2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-17319HIGH8.8SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the Emails module by a Regular user.
CVE-2019-17318HIGH8.8SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the pmse_Inbox module by a Regular user.
CVE-2019-17317HIGH7.2SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP object injection in the UpgradeWizard module by an Admin user.
CVE-2019-17316HIGH8.8SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP object injection in the Import module by a Regular user.
CVE-2019-17315HIGH7.2SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP object injection in the Administration module by an Admin user.
CVE-2019-12812CRITICAL9.8MyBuilder viewer before 6.2.2019.814 allow an attacker to execute arbitrary command via specifically crafted configurati...
CVE-2019-12811CRITICAL9.8ActiveX Control in MyBuilder before 6.2.2019.814 allow an attacker to execute arbitrary command via the ShellOpen method...
CVE-2019-3688HIGH7.1The /usr/sbin/pinger binary packaged with squid in SUSE Linux Enterprise Server 15 before and including version 4.8-5.8....
CVE-2019-16263HIGH7.4The Twitter Kit framework through 3.4.2 for iOS does not properly validate the api.twitter.com SSL certificate. Although...
CVE-2019-15751CRITICAL9.8An unrestricted file upload vulnerability in SITOS six Build v6.2.1 allows remote attackers to execute arbitrary code by...
CVE-2019-15750MEDIUM6.1A Cross-Site Scripting (XSS) vulnerability in the blog function in SITOS six Build v6.2.1 allows remote attackers to inj...
CVE-2019-15749MEDIUM6.5SITOS six Build v6.2.1 allows a user to change their password and recovery email address without requiring them to confi...
CVE-2019-15748CRITICAL9.8SITOS six Build v6.2.1 permits unauthorised users to upload and import a SCORM 2004 package by browsing directly to affe...
CVE-2019-15747HIGH8.8SITOS six Build v6.2.1 allows a user with the user role of Seminar Coordinator to escalate their permission to the Syste...
CVE-2019-15746CRITICAL9.8SITOS six Build v6.2.1 allows an attacker to inject arbitrary PHP commands. As a result, an attacker can compromise the ...
CVE-2019-17269CRITICAL9.8Intellian Remote Access 3.18 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the Pi...
CVE-2019-17267CRITICAL9.8A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to net.sf.ehcache.h...
CVE-2019-17266CRITICAL9.8libsoup from versions 2.65.1 until 2.68.1 have a heap-based buffer over-read because soup_ntlm_parse_challenge() in soup...
CVE-2019-17264LOW3.3In libyal liblnk before 20191006, liblnk_location_information_read_data in liblnk_location_information.c has a heap-base...
CVE-2019-17263LOW3.3In libyal libfwsi before 20191006, libfwsi_extension_block_copy_from_byte_stream in libfwsi_extension_block.c has a heap...
CVE-2019-17240CRITICAL9.8bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many...
CVE-2019-17226MEDIUM4.8CMS Made Simple (CMSMS) 2.2.11 allows XSS via the Site Admin > Module Manager > Search Term field.
CVE-2019-17225MEDIUM5.4Subrion 4.2.1 allows XSS via the panel/members/ Username, Full Name, or Email field, aka an "Admin Member JSON Update" i...
CVE-2019-17219HIGH8.8An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. By default, the devic...
CVE-2019-17218CRITICAL9.1An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. By default, the commu...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now