2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-16679MEDIUM4.9Gila CMS before 1.11.1 allows admin/fm/?f=../ directory traversal, leading to Local File Inclusion.
CVE-2019-16678MEDIUM6.5admin/urlrule/add.html in YzmCMS 5.3 allows CSRF with a resultant denial of service by adding a superseding route.
CVE-2019-16677MEDIUM6.5An issue was discovered in idreamsoft iCMS V7.0. admincp.php?app=members&do=del allows CSRF.
CVE-2019-16669MEDIUM5.3The Reset Password feature in Pagekit 1.0.17 gives a different response depending on whether the e-mail address of a val...
CVE-2019-16665MEDIUM6.1An issue was discovered in ThinkSAAS 2.91. There is XSS via the content to the index.php?app=group&ac=comment&ts=do&js=1...
CVE-2019-16664MEDIUM4.8An issue was discovered in ThinkSAAS 2.91. There is XSS via the index.php?app=group&ac=create&ts=do groupname parameter.
CVE-2019-16661MEDIUM5.4Ogma CMS 0.5 has XSS via creation of a new blog.
CVE-2019-16660HIGH8.8joyplus-cms 1.6.0 has admin_ajax.php?action=savexml&tab=vodplay CSRF.
CVE-2019-16659HIGH8.8TuziCMS 2.0.6 has index.php/manage/link/do_add CSRF.
CVE-2019-16658HIGH8.8TuziCMS 2.0.6 has index.php/manage/notice/do_add CSRF.
CVE-2019-16657MEDIUM6.1TuziCMS 2.0.6 has XSS via the PATH_INFO to a group URI, as demonstrated by index.php/article/group/id/2/.
CVE-2019-16656CRITICAL9.8joyplus-cms 1.6.0 allows remote attackers to execute arbitrary PHP code via /install by placing the code in the name of ...
CVE-2019-16655HIGH7.5joyplus-cms 1.6.0 allows reinstallation if the install/ URI remains available.
CVE-2019-16650CRITICAL10On Supermicro X10 and X11 products, a client's access privileges may be transferred to a different client that later has...
CVE-2019-16649CRITICAL10On Supermicro H11, H12, M11, X9, X10, and X11 products, a combination of encryption and authentication problems in the v...
CVE-2019-6650CRITICAL9.1F5 BIG-IP ASM 15.0.0, 14.1.0-14.1.0.6, 14.0.0-14.0.0.5, 13.0.0-13.1.1.5, 12.1.0-12.1.4.1, 11.6.0-11.6.4, and 11.5.1-11.5...
CVE-2019-6649CRITICAL9.1F5 BIG-IP 15.0.0, 14.1.0-14.1.0.6, 14.0.0-14.0.0.5, 13.0.0-13.1.1.5, 12.1.0-12.1.4.1, 11.6.0-11.6.4, and 11.5.1-11.5.9 a...
CVE-2019-6145MEDIUM6.7Forcepoint VPN Client for Windows versions lower than 6.6.1 have an unquoted search path vulnerability. This enables loc...
CVE-2019-15138HIGH7.5The html-pdf package 2.2.0 for Node.js has an arbitrary file read vulnerability via an HTML file that uses XMLHttpReques...
CVE-2019-16645HIGH8.6An issue was discovered in Embedthis GoAhead 2.5.0. Certain pages (such as goform/login and config/log_off_page.htm) cre...
CVE-2019-14816HIGH7.8There is heap-based buffer overflow in kernel, all versions up to, excluding 5.3, in the marvell wifi chip driver in Lin...
CVE-2019-14814HIGH7.8There is heap-based buffer overflow in Linux kernel, all versions up to, excluding 5.3, in the marvell wifi chip driver ...
CVE-2019-11327MEDIUM4.9An issue was discovered on Topcon Positioning Net-G5 GNSS Receiver devices with firmware 5.2.2. The web interface of the...
CVE-2019-11326HIGH8.8An issue was discovered on Topcon Positioning Net-G5 GNSS Receiver devices with firmware 5.2.2. The web interface of the...
CVE-2019-11280HIGH8.8Pivotal Apps Manager, included in Pivotal Application Service versions 2.3.x prior to 2.3.18, 2.4.x prior to 2.4.14, 2.5...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now