2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-17217HIGH8.8An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. There is no CSRF prot...
CVE-2019-17216CRITICAL9.8An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. Password authenticati...
CVE-2019-17215CRITICAL9.8An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. There is no bruteforc...
CVE-2019-17214HIGH7.5The WebARX plugin 1.3.0 for WordPress allows firewall bypass by appending &cc=1 to a URI.
CVE-2019-17213MEDIUM6.1The WebARX plugin 1.3.0 for WordPress has unauthenticated stored XSS via the URI or the X-Forwarded-For HTTP header.
CVE-2019-17206CRITICAL9.8Uncontrolled deserialization of a pickled object in models.py in Frost Ming rediswrapper (aka Redis Wrapper) before 0.3....
CVE-2019-17205MEDIUM6.1TeamPass 2.1.27.36 allows Stored XSS by placing a payload in the username field during a login attempt. When an administ...
CVE-2019-17204MEDIUM5.4TeamPass 2.1.27.36 allows Stored XSS by setting a crafted Knowledge Base label and adding any available item.
CVE-2019-17203MEDIUM5.4TeamPass 2.1.27.36 allows Stored XSS at the Search page by setting a crafted password for an item in any folder.
CVE-2019-17199HIGH7.5www/getfile.php in WPO WebPageTest 19.04 on Windows allows Directory Traversal (for reading arbitrary files) because of ...
CVE-2019-17197CRITICAL9.8OpenEMR through 5.0.2 has SQL Injection in the Lifestyle demographic filter criteria in library/clinical_rules.php that ...
CVE-2019-13145Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2019-17192CRITICAL9.8The WebRTC component in the Signal Private Messenger application through 4.47.7 for Android processes videoconferencing ...
CVE-2019-17191HIGH7.5The Signal Private Messenger application before 4.47.7 for Android allows a caller to force a call to be answered, witho...
CVE-2019-17184CRITICAL9.8Xerox AtlaLink B8045/B8055/B8065/B8075/B8090 C8030/C8035/C8045/C8055/C8070 printers with software before 101.00x.089.226...
CVE-2019-17188HIGH7.2An unrestricted file upload vulnerability was discovered in catalog/productinfo/imageupload in Fecshop FecMall 2.3.4. An...
CVE-2019-16865HIGH7.5An issue was discovered in Pillow before 6.2.0. When reading specially crafted invalid image files, the library can eith...
CVE-2019-17183HIGH7.5Foxit Reader before 9.7 allows an Access Violation and crash if insufficient memory exists.
CVE-2019-17180HIGH7.8Valve Steam Client before 2019-09-12 allows placing or appending partially controlled filesystem content, as demonstrate...
CVE-2019-11656MEDIUM5.4Stored XSS vulnerability in Micro Focus ArcSight Logger, affects versions prior to Logger 6.7.1 HotFix 6.7.1.8262.0. Thi...
CVE-2019-11655HIGH8.8Unrestricted file upload vulnerability in Micro Focus ArcSight Logger, version 6.7.0 and later. This vulnerability could...
CVE-2019-6015HIGH7.5FON2601E-SE, FON2601E-RE, FON2601E-FSW-S, and FON2601E-FSW-B with firmware versions 1.1.7 and earlier contain an issue w...
CVE-2019-17179MEDIUM6.14.1.0, 4.1.1, 4.1.2, 4.1.2.3, 4.1.2.6, 4.1.2.7, 4.2.0, 4.2.1, 4.2.2, 5.0.0, 5.0.0.5, 5.0.0.6, 5.0.1, 5.0.1.1, 5.0.1.2, 5...
CVE-2019-6776HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.5.0...
CVE-2019-6775HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.5.0.207...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now