2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-11741MEDIUM6.1A compromised sandboxed content process can perform a Universal Cross-site Scripting (UXSS) attack on content from any s...
CVE-2019-11740HIGH8.8Mozilla developers and community members reported memory safety bugs present in Firefox 68, Firefox ESR 68, and Firefox ...
CVE-2019-11739MEDIUM6.5Encrypted S/MIME parts in a crafted multipart/alternative message can leak plaintext when included in a a HTML reply/for...
CVE-2019-11738MEDIUM6.3If a Content Security Policy (CSP) directive is defined that uses a hash-based source that takes the empty string as inp...
CVE-2019-11737MEDIUM5.3If a wildcard ('*') is specified for the host in Content Security Policy (CSP) directives, any port or path restriction ...
CVE-2019-11736HIGH7The Mozilla Maintenance Service does not guard against files being hardlinked to another file in the updates directory, ...
CVE-2019-11735HIGH8.8Mozilla developers and community members reported memory safety bugs present in Firefox 68 and Firefox ESR 68. Some of t...
CVE-2019-11734CRITICAL9.8Mozilla developers and community members reported memory safety bugs present in Firefox 68. Some of these bugs showed ev...
CVE-2019-11733CRITICAL9.8When a master password is set, it is required to be entered again before stored passwords can be accessed in the 'Saved ...
CVE-2019-16923MEDIUM6.1kkcms 1.3 has jx.php?url= XSS.
CVE-2019-11722Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2019-9853HIGH7.8LibreOffice documents can contain macros. The execution of those macros is controlled by the document security settings,...
CVE-2019-8075HIGH7.5Adobe Flash Player version 32.0.0.192 and earlier versions have a Same Origin Policy Bypass vulnerability. Successful ex...
CVE-2019-8074CRITICAL9.8ColdFusion 2018- update 4 and earlier and ColdFusion 2016- update 11 and earlier have a Path Traversal vulnerability. Su...
CVE-2019-8073CRITICAL9.8ColdFusion 2018- update 4 and earlier and ColdFusion 2016- update 11 and earlier have a Command Injection via Vulnerable...
CVE-2019-8072HIGH7.5ColdFusion 2018- update 4 and earlier and ColdFusion 2016- update 11 and earlier have a Security bypass vulnerability. S...
CVE-2019-16922MEDIUM5.3SuiteCRM 7.10.x before 7.10.20 and 7.11.x before 7.11.8 allows unintended public exposure of files.
CVE-2019-4141MEDIUM6.5IBM MQ 7.1.0.0 - 7.1.0.9, 7.5.0.0 - 7.5.0.9, 8.0.0.0 - 8.0.0.11, 9.0.0.0 - 9.0.0.6, 9.1.0.0 - 9.1.0.2, and 9.1.1 - 9.1.2...
CVE-2019-16921HIGH7.5In the Linux kernel before 4.17, hns_roce_alloc_ucontext in drivers/infiniband/hw/hns/hns_roce_main.c does not initializ...
CVE-2019-13376MEDIUM6.5phpBB version 3.2.7 allows the stealing of an Administration Control Panel session id by leveraging CSRF in the Remote A...
CVE-2019-16920CRITICAL9.8Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The i...
CVE-2019-16902HIGH7.5In the ARforms plugin 3.7.1 for WordPress, arf_delete_file in arformcontroller.php allows unauthenticated deletion of an...
CVE-2019-11279HIGH8.8CF UAA versions prior to 74.1.0 can request scopes for a client that shouldn't be allowed by submitting an array of requ...
CVE-2019-15891MEDIUM5.3An issue was discovered in CKFinder through 2.6.2.1 and 3.x through 3.5.0. The documentation has misleading information ...
CVE-2019-15862HIGH7.5An issue was discovered in CKFinder through 2.6.2.1. Improper checks of file names allows remote attackers to upload fil...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now