2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-16057 | CRITICAL | 9.8 | 87.2% | Sep 16, 2019 | The login_mgr.cgi script in D-Link DNS-320 through 2.05.B10 is vulnerable to remote command injection. |
| CVE-2019-13474 | CRITICAL | 9.8 | 3.0% | Sep 16, 2019 | TELESTAR Bobs Rock Radio, Dabman D10, Dabman i30 Stereo, Imperial i110, Imperial i150, Imperial i200, Imperial i200-cd, ... |
| CVE-2019-16335 | CRITICAL | 9.8 | 4.9% | Sep 15, 2019 | A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikar... |
| CVE-2019-16334 | MEDIUM | 4.8 | 0.7% | Sep 15, 2019 | In Bludit v3.9.2, there is a persistent XSS vulnerability in the Categories -> Add New Category -> Name field. NOTE: thi... |
| CVE-2019-16333 | MEDIUM | 5.4 | 0.7% | Sep 15, 2019 | GetSimple CMS v3.3.15 has Persistent Cross-Site Scripting (XSS) in admin/theme-edit.php. |
| CVE-2019-16332 | MEDIUM | 6.1 | 5.7% | Sep 15, 2019 | In the api-bearer-auth plugin before 20190907 for WordPress, the server parameter is not correctly filtered in the swagg... |
| CVE-2019-14540 | CRITICAL | 9.8 | 10.7% | Sep 15, 2019 | A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikar... |
| CVE-2019-16321 | MEDIUM | 6.1 | 0.8% | Sep 15, 2019 | ScadaBR 1.0CE, and 1.1.x through 1.1.0-RC, has XSS via a request for a nonexistent resource, as demonstrated by the dwr/... |
| CVE-2019-16320 | MEDIUM | 5.3 | 1.1% | Sep 15, 2019 | Cobham Sea Tel v170 224521 through v194 225444 devices allow attackers to obtain potentially sensitive information, such... |
| CVE-2019-16319 | HIGH | 7.5 | 3.8% | Sep 15, 2019 | In Wireshark 3.0.0 to 3.0.3 and 2.6.0 to 2.6.10, the Gryphon dissector could go into an infinite loop. This was addresse... |
| CVE-2019-16318 | HIGH | 8.8 | 1.4% | Sep 14, 2019 | In Pimcore before 5.7.1, an attacker with limited privileges can bypass file-extension restrictions via a 256-character ... |
| CVE-2019-16317 | HIGH | 8.8 | 1.7% | Sep 14, 2019 | In Pimcore before 5.7.1, an attacker with limited privileges can trigger execution of a .phar file via a phar:// URL in ... |
| CVE-2019-16307 | MEDIUM | 6.1 | 1.1% | Sep 14, 2019 | A Reflected Cross-Site Scripting (XSS) vulnerability in the webEx module in webExMeetingLogin.jsp and deleteWebExMeeting... |
| CVE-2019-16314 | CRITICAL | 9.8 | 38.7% | Sep 14, 2019 | Indexhibit 2.1.5 allows a product reinstallation, with resultant remote code execution, via /ndxzstudio/install.php?p=2. |
| CVE-2019-16313 | HIGH | 7.5 | 47.0% | Sep 14, 2019 | ifw8 Router ROM v4.31 allows credential disclosure by reading the action/usermanager.htm HTML source code. |
| CVE-2019-16312 | MEDIUM | 6.1 | 0.8% | Sep 14, 2019 | s-cms V3.0 has XSS in index.php?type=text via the S_id parameter. |
| CVE-2019-16311 | HIGH | 8.8 | 0.6% | Sep 14, 2019 | NIUSHOP V1.11 has CSRF via search_info to index.php. |
| CVE-2019-16310 | MEDIUM | 5.4 | 0.6% | Sep 14, 2019 | NIUSHOP V1.11 has XSS via the index.php?s=/admin URI. |
| CVE-2019-16309 | CRITICAL | 9.8 | 5.0% | Sep 14, 2019 | FlameCMS 3.3.5 has SQL injection in account/login.php via accountName. |
| CVE-2019-16294 | HIGH | 7.8 | 9.8% | Sep 14, 2019 | SciLexer.dll in Scintilla in Notepad++ (x64) before 7.7 allows remote code execution or denial of service via Unicode ch... |
| CVE-2019-16305 | HIGH | 8.8 | 6.7% | Sep 14, 2019 | In MobaXterm 11.1 and 12.1, the protocol handler is vulnerable to command injection. A crafted link can trigger a popup ... |
| CVE-2019-16303 | CRITICAL | 9.8 | 3.7% | Sep 14, 2019 | A class generated by the Generator in JHipster before 6.3.0 and JHipster Kotlin through 1.1.0 produces code that uses an... |
| CVE-2019-5485 | CRITICAL | 10 | 59.8% | Sep 13, 2019 | NPM package gitlabhook version 0.0.17 is vulnerable to a Command Injection vulnerability. Arbitrary commands can be inje... |
| CVE-2019-5484 | HIGH | 7.5 | 2.6% | Sep 13, 2019 | Bower before 1.8.8 has a path traversal vulnerability permitting file write in arbitrary locations via install command, ... |
| CVE-2019-11660 | HIGH | 7.8 | 7.8% | Sep 13, 2019 | Privileges manipulation in Micro Focus Data Protector, versions 10.00, 10.01, 10.02, 10.03, 10.04, 10.10, 10.20, 10.30, ... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now