2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-15571 | — | — | 1.4% | Aug 26, 2019 | The WEB control panel before 2019-04-30 for ClonOS allows SQL injection in clonos.php. |
| CVE-2019-15570 | — | — | 1.5% | Aug 26, 2019 | BEdita through 4.0.0-RC2 allows SQL injection during a save operation for a relation with parameters. |
| CVE-2019-15569 | — | — | 1.4% | Aug 26, 2019 | HM Courts & Tribunals ccd-data-store-api before 2019-06-10 allows SQL injection, related to SearchQueryFactoryOperation.... |
| CVE-2019-15568 | — | — | 1.4% | Aug 26, 2019 | idseq-web before 2019-07-01 in Infectious Disease Sequencing Platform IDseq allows SQL injection via tax_levels. |
| CVE-2019-15567 | — | — | 1.4% | Aug 26, 2019 | OpenForis Arena before 2019-05-07 allows SQL injection in the sorting feature. |
| CVE-2019-15566 | — | — | 1.6% | Aug 26, 2019 | The Alfresco application before 1.8.7 for Android allows SQL injection in HistorySearchProvider.java. |
| CVE-2019-15565 | — | — | 1.5% | Aug 26, 2019 | The ICOMMKT connector before 1.0.7 for PrestaShop allows SQL injection in icommktconnector.php. |
| CVE-2019-15564 | — | — | 1.4% | Aug 26, 2019 | The Compassion Switzerland addons 10.01.4 for Odoo allow SQL injection in models/partner_compassion.py. |
| CVE-2019-15563 | — | — | 1.9% | Aug 26, 2019 | Observational Health Data Sciences and Informatics (OHDSI) WebAPI before 2.7.2 allows SQL injection in FeatureExtraction... |
| CVE-2019-15554 | — | — | 2.1% | Aug 26, 2019 | An issue was discovered in the smallvec crate before 0.6.10 for Rust. There is memory corruption for certain grow attemp... |
| CVE-2019-15553 | — | — | 1.8% | Aug 26, 2019 | An issue was discovered in the memoffset crate before 0.5.0 for Rust. offset_of and span_of can cause exposure of uninit... |
| CVE-2019-15552 | — | — | 2.5% | Aug 26, 2019 | An issue was discovered in the libflate crate before 0.1.25 for Rust. MultiDecoder::read has a use-after-free, leading t... |
| CVE-2019-15551 | — | — | 1.9% | Aug 26, 2019 | An issue was discovered in the smallvec crate before 0.6.10 for Rust. There is a double free for certain grow attempts w... |
| CVE-2019-15550 | HIGH | 7.5 | 1.4% | Aug 26, 2019 | An issue was discovered in the simd-json crate before 0.1.15 for Rust. There is an out-of-bounds read and an incorrect c... |
| CVE-2019-14307 | HIGH | 8.8 | 3.0% | Aug 26, 2019 | Several Ricoh printers have multiple buffer overflows parsing HTTP parameter settings for SNMP, which allow an attacker ... |
| CVE-2019-14305 | HIGH | 8.8 | 3.0% | Aug 26, 2019 | Several Ricoh printers have multiple buffer overflows parsing HTTP parameter settings for Wi-Fi, mDNS, POP3, SMTP, and n... |
| CVE-2019-14300 | CRITICAL | 9.8 | 3.1% | Aug 26, 2019 | Several Ricoh printers have multiple buffer overflows parsing HTTP cookie headers, which allow an attacker to cause a de... |
| CVE-2019-15501 | — | — | 8.2% | Aug 26, 2019 | Reflected cross site scripting (XSS) in L-Soft LISTSERV before 16.5-2018a exists via the /scripts/wa.exe OK parameter. |
| CVE-2019-15479 | — | — | 0.8% | Aug 26, 2019 | Status Board 1.1.81 has reflected XSS via dashboard.ts. |
| CVE-2019-14308 | CRITICAL | 9.8 | 3.1% | Aug 26, 2019 | Several Ricoh printers have multiple buffer overflows parsing LPD packets, which allow an attacker to cause a denial of ... |
| CVE-2019-15562 | CRITICAL | 9.8 | 1.7% | Aug 26, 2019 | GORM before 1.9.10 allows SQL injection via incomplete parentheses. NOTE: Misusing Gorm by passing untrusted user input ... |
| CVE-2019-15561 | — | — | 1.4% | Aug 26, 2019 | FlashLingo before 2019-06-12 allows SQL injection, related to flashlingo.js and db.js. |
| CVE-2019-15556 | — | — | 1.4% | Aug 26, 2019 | Pvanloon1983 social_network before 2019-07-03 allows SQL injection in includes/form_handlers/register_handler.php. |
| CVE-2019-15524 | — | — | 3.1% | Aug 26, 2019 | CSZ CMS 1.2.3 allows arbitrary file upload, as demonstrated by a .php file to admin/filemanager in the File Management M... |
| CVE-2019-15521 | — | — | 2.5% | Aug 26, 2019 | Spoon Library through 2014-02-06, as used in Fork CMS before 1.4.1 and other products, allows PHP object injection via a... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now