2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-16138 | CRITICAL | 9.8 | 2.5% | Sep 9, 2019 | An issue was discovered in the image crate before 0.21.3 for Rust, affecting the HDR image format decoder. Vec::set_len ... |
| CVE-2019-16137 | HIGH | 7.5 | 1.4% | Sep 9, 2019 | An issue was discovered in the spin crate before 0.5.2 for Rust, when RwLock is used. Because memory ordering is mishand... |
| CVE-2019-16133 | MEDIUM | 6.5 | 1.0% | Sep 9, 2019 | An issue was discovered in eteams OA v4.0.34. Because the session is not strictly checked, the account names and passwor... |
| CVE-2019-16132 | MEDIUM | 6.5 | 6.1% | Sep 9, 2019 | An issue was discovered in OKLite v1.2.25. framework/admin/tpl_control.php allows remote attackers to delete arbitrary f... |
| CVE-2019-16131 | HIGH | 8.8 | 6.5% | Sep 9, 2019 | framework/admin/modulec_control.php in OKLite v1.2.25 has an Arbitrary File Upload Vulnerability because a .php file fro... |
| CVE-2019-16130 | MEDIUM | 6.1 | 0.9% | Sep 9, 2019 | YII2-CMS v1.0 has XSS in protected\core\modules\home\models\Contact.php via a name field to /contact.html. |
| CVE-2019-16126 | MEDIUM | 6.1 | 1.5% | Sep 9, 2019 | Grav through 1.6.15 allows (Stored) Cross-Site Scripting due to JavaScript execution in SVG images. |
| CVE-2019-16125 | CRITICAL | 9.8 | 2.2% | Sep 9, 2019 | In Jobberbase 2.0, the parameter category is not sanitized in public/page_subscribe.php, leading to /subscribe SQL injec... |
| CVE-2019-16124 | CRITICAL | 9.8 | 27.6% | Sep 9, 2019 | In YouPHPTube 7.4, the file install/checkConfiguration.php has no access control, which leads to everyone being able to ... |
| CVE-2019-16123 | HIGH | 7.5 | 16.5% | Sep 9, 2019 | In Kartatopia PilusCart 1.4.1, the parameter filename in the file catalog.php is mishandled, leading to ../ Local File D... |
| CVE-2019-16120 | HIGH | 8.8 | 3.2% | Sep 8, 2019 | CSV injection in the event-tickets (Event Tickets) plugin before 4.10.7.2 for WordPress exists via the "All Post> Ticket... |
| CVE-2019-16119 | CRITICAL | 9.8 | 25.4% | Sep 8, 2019 | SQL injection in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via the admin/control... |
| CVE-2019-16118 | MEDIUM | 6.1 | 5.3% | Sep 8, 2019 | Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admi... |
| CVE-2019-16117 | MEDIUM | 6.1 | 4.6% | Sep 8, 2019 | Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admi... |
| CVE-2019-16115 | HIGH | 7.8 | 1.1% | Sep 8, 2019 | In Xpdf 4.01.01, a stack-based buffer under-read could be triggered in IdentityFunction::transform in Function.cc, used ... |
| CVE-2019-16113 | HIGH | 8.8 | 78.0% | Sep 8, 2019 | Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .j... |
| CVE-2019-16109 | MEDIUM | 5.3 | 1.8% | Sep 8, 2019 | An issue was discovered in Plataformatec Devise before 4.7.1. It confirms accounts upon receiving a request with a blank... |
| CVE-2019-16105 | — | — | 1.7% | Sep 8, 2019 | Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows ..%2f directory traversal via a rest/json/configdb/download/ URI. |
| CVE-2019-16104 | MEDIUM | 6.1 | 0.8% | Sep 8, 2019 | Silver Peak EdgeConnect SD-WAN before 8.1.7.x has reflected XSS via the rest/json/configdb/download/ PATH_INFO. |
| CVE-2019-16103 | — | — | 1.8% | Sep 8, 2019 | Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows privilege escalation (by administrators) from the menu to a root Ba... |
| CVE-2019-16102 | — | — | 1.5% | Sep 8, 2019 | Silver Peak EdgeConnect SD-WAN before 8.1.7.x has an SNMP service with a public value for rocommunity and trapcommunity. |
| CVE-2019-16101 | — | — | 1.5% | Sep 8, 2019 | Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows remote attackers to obtain potentially sensitive stack traces by se... |
| CVE-2019-16100 | — | — | 1.8% | Sep 8, 2019 | Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows remote attackers to trigger a web-interface outage via slow client-... |
| CVE-2019-16099 | — | — | 0.6% | Sep 8, 2019 | Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows CSRF via JSON data to a .swf file. |
| CVE-2019-16097 | MEDIUM | 6.5 | 23.1% | Sep 8, 2019 | core/api/user.go in Harbor 1.7.0 through 1.8.2 allows non-admin users to create admin accounts via the POST /api/users A... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now