2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-11380The master-password feature in the ES File Explorer File Manager application 4.2.0.1.3 for Android can be bypassed via a...
CVE-2019-15944MEDIUM5.3In Counter-Strike: Global Offensive before 8/29/2019, community game servers can display unsafe HTML in a disconnection ...
CVE-2019-15848JetBrains TeamCity 2019.1 and 2019.1.1 allows cross-site scripting (XSS), potentially making it possible to send an arbi...
CVE-2019-14339The ContentProvider in the Canon PRINT jp.co.canon.bsd.ad.pixmaprint 2.5.5 application for Android does not properly res...
CVE-2019-10753In all versions prior to version 3.9.6 for eclipse-wtp, all versions prior to version 9.4.4 for eclipse-cdt, and all ver...
CVE-2019-15955An issue was discovered in Total.js CMS 12.0.0. A low privilege user can perform a simple transformation of a cookie to ...
CVE-2019-15954CRITICAL9.9An issue was discovered in Total.js CMS 12.0.0. An authenticated user with the widgets privilege can gain achieve Remote...
CVE-2019-15953An issue was discovered in Total.js CMS 12.0.0. An authenticated user with limited privileges can get access to a resour...
CVE-2019-15952An issue was discovered in Total.js CMS 12.0.0. An authenticated user with the Pages privilege can conduct a path traver...
CVE-2019-14278In Knowage through 6.1.1, an unauthenticated user can enumerated valid usernames via the ChangePwdServlet page.
CVE-2019-13349In Knowage through 6.1.1, an authenticated user that accesses the users page will obtain all user password hashes.
CVE-2019-13191A SQL injection vulnerability in IntraMaps MapControl 8 allows attackers to execute arbitrary SQL commands via the /Appl...
CVE-2019-13188In Knowage through 6.1.1, an unauthenticated user can bypass access controls and access the entire application.
CVE-2019-13187The Rich Text Formatter (Redactor) extension through v1.1.1 for Symphony CMS has an Unauthenticated arbitrary file uploa...
CVE-2019-5070MEDIUM6.5An exploitable SQL injection vulnerability exists in the unauthenticated portion of eFront LMS, versions v5.2.12 and ear...
CVE-2019-5069HIGH8.8A code execution vulnerability exists in Epignosis eFront LMS v5.2.12. A specially crafted web request can cause unsafe ...
CVE-2019-5065MEDIUM5.3An exploitable information disclosure vulnerability exists in the packet-parsing functionality of Blynk-Library v0.6.1. ...
CVE-2019-15949HIGH8.8Nagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to the server as the nagios ...
CVE-2019-15947HIGH7.5In Bitcoin Core 0.18.0, bitcoin-qt stores wallet.dat data unencrypted in memory. Upon a crash, it may dump a core file. ...
CVE-2019-15946MEDIUM6.4OpenSC before 0.20.0-rc1 has an out-of-bounds access of an ASN.1 Octet string in asn1_decode_entry in libopensc/asn1.c.
CVE-2019-15945MEDIUM6.4OpenSC before 0.20.0-rc1 has an out-of-bounds access of an ASN.1 Bitstring in decode_bit_string in libopensc/asn1.c.
CVE-2019-13361MEDIUM6.5Smanos W100 1.0.0 devices have Insecure Permissions, exploitable by an attacker on the same Wi-Fi network.
CVE-2019-13190In Knowage through 6.1.1, the sign up page does not invalidate a valid CAPTCHA token. This allows for CAPTCHA bypass in ...
CVE-2019-15942HIGH8.8FFmpeg through 4.2 has a "Conditional jump or move depends on uninitialised value" issue in h2645_parse because alloc_rb...
CVE-2019-15939MEDIUM5.9An issue was discovered in OpenCV 4.1.0. There is a divide-by-zero error in cv::HOGDescriptor::getDescriptorSize in modu...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now