2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-16403HIGH8.8In Webkul Bagisto before 0.1.5, the functionalities for customers to change their own values (such as address, review, o...
CVE-2019-16216MEDIUM5.4Zulip server before 2.0.5 incompletely validated the MIME types of uploaded files. A user who is logged into the server ...
CVE-2019-16215MEDIUM6.5The Markdown parser in Zulip server before 2.0.5 used a regular expression vulnerable to exponential backtracking. A use...
CVE-2019-16396HIGH7.8GnuCOBOL 2.2 has a use-after-free in the end_scope_of_program_name() function in cobc/parser.y via crafted COBOL source ...
CVE-2019-16395HIGH7.8GnuCOBOL 2.2 has a stack-based buffer overflow in the cb_name() function in cobc/tree.c via crafted COBOL source code.
CVE-2019-16394MEDIUM5.3SPIP before 3.1.11 and 3.2 before 3.2.5 provides different error messages from the password-reminder page depending on w...
CVE-2019-16393MEDIUM6.1SPIP before 3.1.11 and 3.2 before 3.2.5 mishandles redirect URLs in ecrire/inc/headers.php with a %0D, %0A, or %20 chara...
CVE-2019-16392MEDIUM6.1SPIP before 3.1.11 and 3.2 before 3.2.5 allows prive/formulaires/login.php XSS via error messages.
CVE-2019-16391MEDIUM6.5SPIP before 3.1.11 and 3.2 before 3.2.5 allows authenticated visitors to modify any published content and execute other ...
CVE-2019-16199CRITICAL9.8eQ-3 Homematic CCU2 before 2.47.18 and CCU3 before 3.47.18 allow Remote Code Execution by unauthenticated attackers with...
CVE-2019-6840CRITICAL9.8A Format String: CWE-134 vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 - U.m...
CVE-2019-6839HIGH8.8A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists in U.motion Server (MEG6501-0001 - U.mot...
CVE-2019-6838MEDIUM6.5A CWE-863: Incorrect Authorization vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-...
CVE-2019-6837CRITICAL9.1A Server-Side Request Forgery (SSRF): CWE-918 vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX serve...
CVE-2019-6836HIGH7.5A CWE-863: Incorrect Authorization vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-...
CVE-2019-6835MEDIUM5.4A Cross-Site Scripting (XSS) CWE-79 vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501...
CVE-2019-6833MEDIUM6.5A CWE-754 – Improper Check for Unusual or Exceptional Conditions vulnerability exists in Magelis HMI Panels (all version...
CVE-2019-6832HIGH8.3A CWE-287: Authentication vulnerability exists in spaceLYnk (all versions before 2.4.0) and Wiser for KNX (all versions ...
CVE-2019-6831HIGH8.6A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in BMXNOR0200H Ethernet / Serial RT...
CVE-2019-6830MEDIUM5.9A CWE-248: Uncaught Exception vulnerability exists IN Modicon M580 all versions prior to V2.80, which could cause a poss...
CVE-2019-6829HIGH7.5A CWE-248: Uncaught Exception vulnerability exists in Modicon M580 (firmware version prior to V2.90) and Modicon M340 (f...
CVE-2019-6828HIGH7.5A CWE-248: Uncaught Exception vulnerability exists Modicon M580 (firmware version prior to V2.90), Modicon M340 (firmwar...
CVE-2019-6826HIGH7.8A CWE-426: Untrusted Search Path vulnerability exists in SoMachine HVAC v2.4.1 and earlier versions, which could cause a...
CVE-2019-6813HIGH7.5A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in BMXNOR0200H Ethernet / Serial RT...
CVE-2019-6811HIGH7.5An Improper Check for Unusual or Exceptional Conditions (CWE-754) vulnerability exists in Modicon Quantum 140 NOE771x1 v...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now