2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-16138CRITICAL9.8An issue was discovered in the image crate before 0.21.3 for Rust, affecting the HDR image format decoder. Vec::set_len ...
CVE-2019-16137HIGH7.5An issue was discovered in the spin crate before 0.5.2 for Rust, when RwLock is used. Because memory ordering is mishand...
CVE-2019-16133MEDIUM6.5An issue was discovered in eteams OA v4.0.34. Because the session is not strictly checked, the account names and passwor...
CVE-2019-16132MEDIUM6.5An issue was discovered in OKLite v1.2.25. framework/admin/tpl_control.php allows remote attackers to delete arbitrary f...
CVE-2019-16131HIGH8.8framework/admin/modulec_control.php in OKLite v1.2.25 has an Arbitrary File Upload Vulnerability because a .php file fro...
CVE-2019-16130MEDIUM6.1YII2-CMS v1.0 has XSS in protected\core\modules\home\models\Contact.php via a name field to /contact.html.
CVE-2019-16126MEDIUM6.1Grav through 1.6.15 allows (Stored) Cross-Site Scripting due to JavaScript execution in SVG images.
CVE-2019-16125CRITICAL9.8In Jobberbase 2.0, the parameter category is not sanitized in public/page_subscribe.php, leading to /subscribe SQL injec...
CVE-2019-16124CRITICAL9.8In YouPHPTube 7.4, the file install/checkConfiguration.php has no access control, which leads to everyone being able to ...
CVE-2019-16123HIGH7.5In Kartatopia PilusCart 1.4.1, the parameter filename in the file catalog.php is mishandled, leading to ../ Local File D...
CVE-2019-16120HIGH8.8CSV injection in the event-tickets (Event Tickets) plugin before 4.10.7.2 for WordPress exists via the "All Post> Ticket...
CVE-2019-16119CRITICAL9.8SQL injection in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via the admin/control...
CVE-2019-16118MEDIUM6.1Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admi...
CVE-2019-16117MEDIUM6.1Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admi...
CVE-2019-16115HIGH7.8In Xpdf 4.01.01, a stack-based buffer under-read could be triggered in IdentityFunction::transform in Function.cc, used ...
CVE-2019-16113HIGH8.8Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .j...
CVE-2019-16109MEDIUM5.3An issue was discovered in Plataformatec Devise before 4.7.1. It confirms accounts upon receiving a request with a blank...
CVE-2019-16105Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows ..%2f directory traversal via a rest/json/configdb/download/ URI.
CVE-2019-16104MEDIUM6.1Silver Peak EdgeConnect SD-WAN before 8.1.7.x has reflected XSS via the rest/json/configdb/download/ PATH_INFO.
CVE-2019-16103Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows privilege escalation (by administrators) from the menu to a root Ba...
CVE-2019-16102Silver Peak EdgeConnect SD-WAN before 8.1.7.x has an SNMP service with a public value for rocommunity and trapcommunity.
CVE-2019-16101Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows remote attackers to obtain potentially sensitive stack traces by se...
CVE-2019-16100Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows remote attackers to trigger a web-interface outage via slow client-...
CVE-2019-16099Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows CSRF via JSON data to a .swf file.
CVE-2019-16097MEDIUM6.5core/api/user.go in Harbor 1.7.0 through 1.8.2 allows non-admin users to create admin accounts via the POST /api/users A...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now