2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-16745 | HIGH | 8.8 | 1.7% | Sep 30, 2019 | eBrigade before 5.0 has evenement_choice.php chxCal SQL Injection. |
| CVE-2019-16744 | HIGH | 8.8 | 1.7% | Sep 30, 2019 | eBrigade before 5.0 has evenements.php cid SQL Injection. |
| CVE-2019-16743 | HIGH | 8.8 | 1.7% | Sep 30, 2019 | eBrigade before 5.0 has evenement_ical.php evenement SQL Injection. |
| CVE-2019-16414 | MEDIUM | 6.1 | 1.6% | Sep 30, 2019 | A DOM based XSS in GFI Kerio Control v9.3.0 allows embedding of malicious code and manipulating the login page to send b... |
| CVE-2019-14752 | MEDIUM | 6.1 | 0.6% | Sep 30, 2019 | SuiteCRM 7.10.x and 7.11.x before 7.10.20 and 7.11.8 has XSS. |
| CVE-2019-16993 | HIGH | 8.8 | 0.8% | Sep 30, 2019 | In phpBB before 3.1.7-PL1, includes/acp/acp_bbcodes.php has improper verification of a CSRF token on the BBCode page in ... |
| CVE-2019-16676 | CRITICAL | 9.8 | 3.4% | Sep 30, 2019 | Plataformatec Simple Form has Incorrect Access Control in file_method? in lib/simple_form/form_builder.rb, because a use... |
| CVE-2019-16992 | HIGH | 7.5 | 0.9% | Sep 30, 2019 | The Keybase app 2.13.2 for iOS provides potentially insufficient notice that it is employing a user's private key to sig... |
| CVE-2019-16930 | MEDIUM | 5.3 | 1.6% | Sep 28, 2019 | Zcashd in Zcash before 2.0.7-3 allows discovery of the IP address of a full node that owns a shielded address, related t... |
| CVE-2019-16941 | CRITICAL | 9.8 | 5.1% | Sep 28, 2019 | NSA Ghidra through 9.0.4, when experimental mode is enabled, allows arbitrary code execution if the Read XML Files featu... |
| CVE-2019-16935 | MEDIUM | 6.1 | 4.7% | Sep 28, 2019 | The documentation XML-RPC server in Python through 2.7.16, 3.x through 3.6.9, and 3.7.x through 3.7.4 has XSS via the se... |
| CVE-2019-16926 | MEDIUM | 6.1 | 0.8% | Sep 28, 2019 | Flower 0.9.3 has XSS via a crafted worker name. NOTE: The project author stated that he doesn't think this is a valid vu... |
| CVE-2019-16925 | MEDIUM | 6.1 | 0.8% | Sep 28, 2019 | Flower 0.9.3 has XSS via the name parameter in an @app.task call. NOTE: The project author stated that he doesn't think ... |
| CVE-2019-3766 | CRITICAL | 9.8 | 1.9% | Sep 27, 2019 | Dell EMC ECS versions prior to 3.4.0.0 contain an improper restriction of excessive authentication attempts vulnerabilit... |
| CVE-2019-3747 | MEDIUM | 4.8 | 0.8% | Sep 27, 2019 | Dell EMC Integrated Data Protection Appliance versions prior to 2.3 contain a stored cross-site scripting vulnerability.... |
| CVE-2019-3746 | HIGH | 8.8 | 2.1% | Sep 27, 2019 | Dell EMC Integrated Data Protection Appliance versions prior to 2.3 do not limit the number of authentication attempts t... |
| CVE-2019-3736 | HIGH | 7.2 | 0.7% | Sep 27, 2019 | Dell EMC Integrated Data Protection Appliance versions prior to 2.3 contain a password storage vulnerability in the ACM ... |
| CVE-2019-16928 | CRITICAL | 9.8 | 42.5% | Sep 27, 2019 | Exim 4.92 through 4.92.2 allows remote code execution, a different vulnerability than CVE-2019-15846. There is a heap-ba... |
| CVE-2019-11927 | HIGH | 7.8 | 0.9% | Sep 27, 2019 | An integer overflow in WhatsApp media parsing libraries allows a remote attacker to perform an out-of-bounds write on th... |
| CVE-2019-16927 | MEDIUM | 5.5 | 0.9% | Sep 27, 2019 | Xpdf 4.01.01 has an out-of-bounds write in the vertProfile part of the TextPage::findGaps function in TextOutputDev.cc, ... |
| CVE-2019-16688 | MEDIUM | 5.4 | 0.8% | Sep 27, 2019 | Dolibarr 9.0.5 has stored XSS in an Email Template section to mails_templates.php. A user with no privileges can inject ... |
| CVE-2019-16687 | MEDIUM | 5.4 | 0.8% | Sep 27, 2019 | Dolibarr 9.0.5 has stored XSS in a User Profile in a Signature section to card.php. A user with the "Create/modify other... |
| CVE-2019-16686 | MEDIUM | 5.4 | 0.8% | Sep 27, 2019 | Dolibarr 9.0.5 has stored XSS in a User Note section to note.php. A user with no privileges can inject script to attack ... |
| CVE-2019-16685 | MEDIUM | 5.4 | 0.8% | Sep 27, 2019 | Dolibarr 9.0.5 has stored XSS vulnerability via a User Group Description section to card.php. A user with the "Create/mo... |
| CVE-2019-9463 | HIGH | 7.3 | 0.2% | Sep 27, 2019 | In Platform, there is a possible bypass of user interaction requirements due to background app interception. This could ... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now