2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-11278HIGH8.8CF UAA versions prior to 74.1.0, allow external input to be directly queried against. A remote malicious user with 'clie...
CVE-2019-12562MEDIUM6.1Stored Cross-Site Scripting in DotNetNuke (DNN) Version before 9.4.0 allows remote attackers to store and embed the mali...
CVE-2019-16667HIGH8.8diag_command.php in pfSense 2.4.4-p3 allows CSRF via the txtCommand or txtRecallBuffer field, as demonstrated by executi...
CVE-2019-16915CRITICAL9.8An issue was discovered in pfSense through 2.4.4-p3. widgets/widgets/picture.widget.php uses the widgetkey parameter dir...
CVE-2019-16914MEDIUM6.1An XSS issue was discovered in pfSense through 2.4.4-p3. In services_captiveportal_mac.php, the username and delmac para...
CVE-2019-6175HIGH7.5A denial of service vulnerability was reported in Lenovo System Update versions prior to 5.07.0088 that could allow conf...
CVE-2019-6161HIGH7.5An internal product security audit discovered a session handling vulnerability in the web interface of ThinkAgile CP-SB ...
CVE-2019-16895Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-16894. Reason: This candidate is a reservation d...
CVE-2019-16894CRITICAL9.8download.php in inoERP 4.15 allows SQL injection through insecure deserialization.
CVE-2019-16869HIGH7.5Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a "Transfer-Encoding : chunked...
CVE-2019-16755CRITICAL9.8BMC Remedy ITSM Suite is prone to unspecified vulnerabilities in both DWP and SmartIT components, which can permit remot...
CVE-2019-16532MEDIUM6.1An HTTP Host header injection vulnerability exists in YzmCMS V5.3. A malicious user can poison a web cache or trigger re...
CVE-2019-16524MEDIUM4.8The easy-fancybox plugin before 1.8.18 for WordPress (aka Easy FancyBox) is susceptible to Stored XSS in the Settings Me...
CVE-2019-16409MEDIUM5.3In the Versioned Files module through 2.0.3 for SilverStripe 3.x, unpublished versions of files are publicly exposed to ...
CVE-2019-13523MEDIUM5.3In Honeywell Performance IP Cameras and Performance NVRs, the integrated web server of the affected devices could allow ...
CVE-2019-12091HIGH7.8The Netskope client service, v57 before 57.2.0.219 and v60 before 60.2.0.214, running with NT\SYSTEM privilege, accepts ...
CVE-2019-10882HIGH7.8The Netskope client service, v57 before 57.2.0.219 and v60 before 60.2.0.214, running with NT\SYSTEM privilege, accepts ...
CVE-2019-10097HIGH7.2In Apache HTTP Server 2.4.32-2.4.39, when mod_remoteip was configured to use a trusted intermediary proxy server using t...
CVE-2019-10092MEDIUM6.1In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page...
CVE-2019-10082CRITICAL9.1In Apache HTTP Server 2.4.18-2.4.39, using fuzzed network input, the http/2 session handling could be made to read memor...
CVE-2019-0203HIGH7.5In Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0, Subversion's svnserve server process may exit ...
CVE-2019-4378MEDIUM6.5IBM MQ 7.5.0.0 - 7.5.0.9, 7.1.0.0 - 7.1.0.9, 8.0.0.0 - 8.0.0.12, 9.0.0.0 - 9.0.0.6, 9.1.0.0 - 9.1.0.2, and 9.1.0 - 9.1.2...
CVE-2019-4262MEDIUM5.3IBM QRadar SIEM 7.2 and 7.3 is vulnerable to Server Side Request Forgery (SSRF). This may allow an unauthenticated attac...
CVE-2019-16910MEDIUM5.3Arm Mbed TLS before 2.19.0 and Arm Mbed Crypto before 2.0.0, when deterministic ECDSA is enabled, use an RNG with insuff...
CVE-2019-16904MEDIUM5.4TeamPass 2.1.27.36 allows Stored XSS by setting a crafted password for an item in a common available folder or sharing t...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now