2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-17319 | HIGH | 8.8 | 1.2% | Oct 7, 2019 | SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the Emails module by a Regular user. |
| CVE-2019-17318 | HIGH | 8.8 | 1.2% | Oct 7, 2019 | SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the pmse_Inbox module by a Regular user. |
| CVE-2019-17317 | HIGH | 7.2 | 1.4% | Oct 7, 2019 | SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP object injection in the UpgradeWizard module by an Admin user. |
| CVE-2019-17316 | HIGH | 8.8 | 1.5% | Oct 7, 2019 | SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP object injection in the Import module by a Regular user. |
| CVE-2019-17315 | HIGH | 7.2 | 1.4% | Oct 7, 2019 | SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP object injection in the Administration module by an Admin user. |
| CVE-2019-12812 | CRITICAL | 9.8 | 2.7% | Oct 7, 2019 | MyBuilder viewer before 6.2.2019.814 allow an attacker to execute arbitrary command via specifically crafted configurati... |
| CVE-2019-12811 | CRITICAL | 9.8 | 2.2% | Oct 7, 2019 | ActiveX Control in MyBuilder before 6.2.2019.814 allow an attacker to execute arbitrary command via the ShellOpen method... |
| CVE-2019-3688 | HIGH | 7.1 | 0.3% | Oct 7, 2019 | The /usr/sbin/pinger binary packaged with squid in SUSE Linux Enterprise Server 15 before and including version 4.8-5.8.... |
| CVE-2019-16263 | HIGH | 7.4 | 1.0% | Oct 7, 2019 | The Twitter Kit framework through 3.4.2 for iOS does not properly validate the api.twitter.com SSL certificate. Although... |
| CVE-2019-15751 | CRITICAL | 9.8 | 4.5% | Oct 7, 2019 | An unrestricted file upload vulnerability in SITOS six Build v6.2.1 allows remote attackers to execute arbitrary code by... |
| CVE-2019-15750 | MEDIUM | 6.1 | 1.0% | Oct 7, 2019 | A Cross-Site Scripting (XSS) vulnerability in the blog function in SITOS six Build v6.2.1 allows remote attackers to inj... |
| CVE-2019-15749 | MEDIUM | 6.5 | 1.0% | Oct 7, 2019 | SITOS six Build v6.2.1 allows a user to change their password and recovery email address without requiring them to confi... |
| CVE-2019-15748 | CRITICAL | 9.8 | 1.6% | Oct 7, 2019 | SITOS six Build v6.2.1 permits unauthorised users to upload and import a SCORM 2004 package by browsing directly to affe... |
| CVE-2019-15747 | HIGH | 8.8 | 1.1% | Oct 7, 2019 | SITOS six Build v6.2.1 allows a user with the user role of Seminar Coordinator to escalate their permission to the Syste... |
| CVE-2019-15746 | CRITICAL | 9.8 | 1.9% | Oct 7, 2019 | SITOS six Build v6.2.1 allows an attacker to inject arbitrary PHP commands. As a result, an attacker can compromise the ... |
| CVE-2019-17269 | CRITICAL | 9.8 | 3.1% | Oct 7, 2019 | Intellian Remote Access 3.18 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the Pi... |
| CVE-2019-17267 | CRITICAL | 9.8 | 4.6% | Oct 7, 2019 | A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to net.sf.ehcache.h... |
| CVE-2019-17266 | CRITICAL | 9.8 | 2.8% | Oct 6, 2019 | libsoup from versions 2.65.1 until 2.68.1 have a heap-based buffer over-read because soup_ntlm_parse_challenge() in soup... |
| CVE-2019-17264 | LOW | 3.3 | 0.4% | Oct 6, 2019 | In libyal liblnk before 20191006, liblnk_location_information_read_data in liblnk_location_information.c has a heap-base... |
| CVE-2019-17263 | LOW | 3.3 | 0.5% | Oct 6, 2019 | In libyal libfwsi before 20191006, libfwsi_extension_block_copy_from_byte_stream in libfwsi_extension_block.c has a heap... |
| CVE-2019-17240 | CRITICAL | 9.8 | 39.6% | Oct 6, 2019 | bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many... |
| CVE-2019-17226 | MEDIUM | 4.8 | 0.6% | Oct 6, 2019 | CMS Made Simple (CMSMS) 2.2.11 allows XSS via the Site Admin > Module Manager > Search Term field. |
| CVE-2019-17225 | MEDIUM | 5.4 | 1.9% | Oct 6, 2019 | Subrion 4.2.1 allows XSS via the panel/members/ Username, Full Name, or Email field, aka an "Admin Member JSON Update" i... |
| CVE-2019-17219 | HIGH | 8.8 | 0.6% | Oct 6, 2019 | An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. By default, the devic... |
| CVE-2019-17218 | CRITICAL | 9.1 | 0.7% | Oct 6, 2019 | An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. By default, the commu... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now