2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-5521CRITICAL9.6VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), Workstation (15.x before 15.0.3 and 14.x...
CVE-2019-4565HIGH7.5IBM Security Key Lifecycle Manager 3.0 and 3.0.1 does not require that users should have strong passwords by default, wh...
CVE-2019-4505MEDIUM5.3IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Network Deployment could allow a remote attacker to obtain sensi...
CVE-2019-16644CRITICAL9.8App\Home\Controller\ZhuantiController.class.php in TuziCMS 2.0.6 has SQL injection via the index.php/Zhuanti/group?id= s...
CVE-2019-16643MEDIUM5.4An issue was discovered in ZrLog 2.1.1. There is a Stored XSS vulnerability in the article_edit area.
CVE-2019-16534MEDIUM6.1On DrayTek Vigor2925 devices with firmware 3.8.4.3, XSS exists via a crafted WAN name on the General Setup screen. NOTE:...
CVE-2019-16533MEDIUM6.1On DrayTek Vigor2925 devices with firmware 3.8.4.3, Incorrect Access Control exists in loginset.htm, and can be used to ...
CVE-2019-16642CRITICAL9.8App\Mobile\Controller\ZhuantiController.class.php in TuziCMS 2.0.6 has SQL injection via the index.php/Mobile/Zhuanti/gr...
CVE-2019-15089HIGH8.8An issue was discovered in PRiSE adAS 1.7.0. Forms have no CSRF protection, letting an attacker execute actions as the a...
CVE-2019-15088CRITICAL9.8An issue was discovered in PRiSE adAS 1.7.0. Password hashes are compared using the equality operator. Thus, under speci...
CVE-2019-15087HIGH7.2An issue was discovered in PRiSE adAS 1.7.0. An authenticated user can change the function used to hash passwords to any...
CVE-2019-15086MEDIUM6.1An issue was discovered in PRiSE adAS 1.7.0. The newentityID parameter is not properly escaped, leading to a reflected X...
CVE-2019-15085HIGH7.5An issue was discovered in PRiSE adAS 1.7.0. The current database password is embedded in the change password form.
CVE-2019-14916MEDIUM6.5An issue was discovered in PRiSE adAS 1.7.0. A file's format is not properly checked, leading to an unrestricted file up...
CVE-2019-14915MEDIUM6.1An issue was discovered in PRiSE adAS 1.7.0. Certificate data are not properly escaped. This leads to XSS when submittin...
CVE-2019-14914CRITICAL9.1An issue was discovered in PRiSE adAS 1.7.0. The path is not properly escaped in the medatadata_del method, leading to a...
CVE-2019-14913MEDIUM5.4An issue was discovered in PRiSE adAS 1.7.0. Log data are not properly escaped, leading to persistent XSS in the adminis...
CVE-2019-14912MEDIUM6.1An issue was discovered in PRiSE adAS 1.7.0. The OPENSSO module does not properly check the goto parameter, leading to a...
CVE-2019-14911MEDIUM6.1An issue was discovered in PRiSE adAS 1.7.0. The OPENSSO module does not properly escape output on error, leading to ref...
CVE-2019-16531HIGH8.8LayerBB before 1.1.4 has multiple CSRF issues, as demonstrated by changing the System Settings via admin/general.php.
CVE-2019-9720MEDIUM6.5A stack-based buffer overflow in the subtitle decoder in Libav 12.3 allows attackers to corrupt the stack via a crafted ...
CVE-2019-9719HIGH8.8A stack-based buffer overflow in the subtitle decoder in Libav 12.3 allows attackers to corrupt the stack via a crafted ...
CVE-2019-9717MEDIUM6.5In Libav 12.3, a denial of service in the subtitle decoder allows attackers to hog the CPU via a crafted video file in M...
CVE-2019-9619Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2019-16525MEDIUM6.1An XSS issue was discovered in the checklist plugin before 1.1.9 for WordPress. The fill parameter is not correctly filt...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now