2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-16057CRITICAL9.8The login_mgr.cgi script in D-Link DNS-320 through 2.05.B10 is vulnerable to remote command injection.
CVE-2019-13474CRITICAL9.8TELESTAR Bobs Rock Radio, Dabman D10, Dabman i30 Stereo, Imperial i110, Imperial i150, Imperial i200, Imperial i200-cd, ...
CVE-2019-16335CRITICAL9.8A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikar...
CVE-2019-16334MEDIUM4.8In Bludit v3.9.2, there is a persistent XSS vulnerability in the Categories -> Add New Category -> Name field. NOTE: thi...
CVE-2019-16333MEDIUM5.4GetSimple CMS v3.3.15 has Persistent Cross-Site Scripting (XSS) in admin/theme-edit.php.
CVE-2019-16332MEDIUM6.1In the api-bearer-auth plugin before 20190907 for WordPress, the server parameter is not correctly filtered in the swagg...
CVE-2019-14540CRITICAL9.8A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikar...
CVE-2019-16321MEDIUM6.1ScadaBR 1.0CE, and 1.1.x through 1.1.0-RC, has XSS via a request for a nonexistent resource, as demonstrated by the dwr/...
CVE-2019-16320MEDIUM5.3Cobham Sea Tel v170 224521 through v194 225444 devices allow attackers to obtain potentially sensitive information, such...
CVE-2019-16319HIGH7.5In Wireshark 3.0.0 to 3.0.3 and 2.6.0 to 2.6.10, the Gryphon dissector could go into an infinite loop. This was addresse...
CVE-2019-16318HIGH8.8In Pimcore before 5.7.1, an attacker with limited privileges can bypass file-extension restrictions via a 256-character ...
CVE-2019-16317HIGH8.8In Pimcore before 5.7.1, an attacker with limited privileges can trigger execution of a .phar file via a phar:// URL in ...
CVE-2019-16307MEDIUM6.1A Reflected Cross-Site Scripting (XSS) vulnerability in the webEx module in webExMeetingLogin.jsp and deleteWebExMeeting...
CVE-2019-16314CRITICAL9.8Indexhibit 2.1.5 allows a product reinstallation, with resultant remote code execution, via /ndxzstudio/install.php?p=2.
CVE-2019-16313HIGH7.5ifw8 Router ROM v4.31 allows credential disclosure by reading the action/usermanager.htm HTML source code.
CVE-2019-16312MEDIUM6.1s-cms V3.0 has XSS in index.php?type=text via the S_id parameter.
CVE-2019-16311HIGH8.8NIUSHOP V1.11 has CSRF via search_info to index.php.
CVE-2019-16310MEDIUM5.4NIUSHOP V1.11 has XSS via the index.php?s=/admin URI.
CVE-2019-16309CRITICAL9.8FlameCMS 3.3.5 has SQL injection in account/login.php via accountName.
CVE-2019-16294HIGH7.8SciLexer.dll in Scintilla in Notepad++ (x64) before 7.7 allows remote code execution or denial of service via Unicode ch...
CVE-2019-16305HIGH8.8In MobaXterm 11.1 and 12.1, the protocol handler is vulnerable to command injection. A crafted link can trigger a popup ...
CVE-2019-16303CRITICAL9.8A class generated by the Generator in JHipster before 6.3.0 and JHipster Kotlin through 1.1.0 produces code that uses an...
CVE-2019-5485CRITICAL10NPM package gitlabhook version 0.0.17 is vulnerable to a Command Injection vulnerability. Arbitrary commands can be inje...
CVE-2019-5484HIGH7.5Bower before 1.8.8 has a path traversal vulnerability permitting file write in arbitrary locations via install command, ...
CVE-2019-11660HIGH7.8Privileges manipulation in Micro Focus Data Protector, versions 10.00, 10.01, 10.02, 10.03, 10.04, 10.10, 10.20, 10.30, ...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now