2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-16745HIGH8.8eBrigade before 5.0 has evenement_choice.php chxCal SQL Injection.
CVE-2019-16744HIGH8.8eBrigade before 5.0 has evenements.php cid SQL Injection.
CVE-2019-16743HIGH8.8eBrigade before 5.0 has evenement_ical.php evenement SQL Injection.
CVE-2019-16414MEDIUM6.1A DOM based XSS in GFI Kerio Control v9.3.0 allows embedding of malicious code and manipulating the login page to send b...
CVE-2019-14752MEDIUM6.1SuiteCRM 7.10.x and 7.11.x before 7.10.20 and 7.11.8 has XSS.
CVE-2019-16993HIGH8.8In phpBB before 3.1.7-PL1, includes/acp/acp_bbcodes.php has improper verification of a CSRF token on the BBCode page in ...
CVE-2019-16676CRITICAL9.8Plataformatec Simple Form has Incorrect Access Control in file_method? in lib/simple_form/form_builder.rb, because a use...
CVE-2019-16992HIGH7.5The Keybase app 2.13.2 for iOS provides potentially insufficient notice that it is employing a user's private key to sig...
CVE-2019-16930MEDIUM5.3Zcashd in Zcash before 2.0.7-3 allows discovery of the IP address of a full node that owns a shielded address, related t...
CVE-2019-16941CRITICAL9.8NSA Ghidra through 9.0.4, when experimental mode is enabled, allows arbitrary code execution if the Read XML Files featu...
CVE-2019-16935MEDIUM6.1The documentation XML-RPC server in Python through 2.7.16, 3.x through 3.6.9, and 3.7.x through 3.7.4 has XSS via the se...
CVE-2019-16926MEDIUM6.1Flower 0.9.3 has XSS via a crafted worker name. NOTE: The project author stated that he doesn't think this is a valid vu...
CVE-2019-16925MEDIUM6.1Flower 0.9.3 has XSS via the name parameter in an @app.task call. NOTE: The project author stated that he doesn't think ...
CVE-2019-3766CRITICAL9.8Dell EMC ECS versions prior to 3.4.0.0 contain an improper restriction of excessive authentication attempts vulnerabilit...
CVE-2019-3747MEDIUM4.8Dell EMC Integrated Data Protection Appliance versions prior to 2.3 contain a stored cross-site scripting vulnerability....
CVE-2019-3746HIGH8.8Dell EMC Integrated Data Protection Appliance versions prior to 2.3 do not limit the number of authentication attempts t...
CVE-2019-3736HIGH7.2Dell EMC Integrated Data Protection Appliance versions prior to 2.3 contain a password storage vulnerability in the ACM ...
CVE-2019-16928CRITICAL9.8Exim 4.92 through 4.92.2 allows remote code execution, a different vulnerability than CVE-2019-15846. There is a heap-ba...
CVE-2019-11927HIGH7.8An integer overflow in WhatsApp media parsing libraries allows a remote attacker to perform an out-of-bounds write on th...
CVE-2019-16927MEDIUM5.5Xpdf 4.01.01 has an out-of-bounds write in the vertProfile part of the TextPage::findGaps function in TextOutputDev.cc, ...
CVE-2019-16688MEDIUM5.4Dolibarr 9.0.5 has stored XSS in an Email Template section to mails_templates.php. A user with no privileges can inject ...
CVE-2019-16687MEDIUM5.4Dolibarr 9.0.5 has stored XSS in a User Profile in a Signature section to card.php. A user with the "Create/modify other...
CVE-2019-16686MEDIUM5.4Dolibarr 9.0.5 has stored XSS in a User Note section to note.php. A user with no privileges can inject script to attack ...
CVE-2019-16685MEDIUM5.4Dolibarr 9.0.5 has stored XSS vulnerability via a User Group Description section to card.php. A user with the "Create/mo...
CVE-2019-9463HIGH7.3In Platform, there is a possible bypass of user interaction requirements due to background app interception. This could ...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now