2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-15571The WEB control panel before 2019-04-30 for ClonOS allows SQL injection in clonos.php.
CVE-2019-15570BEdita through 4.0.0-RC2 allows SQL injection during a save operation for a relation with parameters.
CVE-2019-15569HM Courts & Tribunals ccd-data-store-api before 2019-06-10 allows SQL injection, related to SearchQueryFactoryOperation....
CVE-2019-15568idseq-web before 2019-07-01 in Infectious Disease Sequencing Platform IDseq allows SQL injection via tax_levels.
CVE-2019-15567OpenForis Arena before 2019-05-07 allows SQL injection in the sorting feature.
CVE-2019-15566The Alfresco application before 1.8.7 for Android allows SQL injection in HistorySearchProvider.java.
CVE-2019-15565The ICOMMKT connector before 1.0.7 for PrestaShop allows SQL injection in icommktconnector.php.
CVE-2019-15564The Compassion Switzerland addons 10.01.4 for Odoo allow SQL injection in models/partner_compassion.py.
CVE-2019-15563Observational Health Data Sciences and Informatics (OHDSI) WebAPI before 2.7.2 allows SQL injection in FeatureExtraction...
CVE-2019-15554An issue was discovered in the smallvec crate before 0.6.10 for Rust. There is memory corruption for certain grow attemp...
CVE-2019-15553An issue was discovered in the memoffset crate before 0.5.0 for Rust. offset_of and span_of can cause exposure of uninit...
CVE-2019-15552An issue was discovered in the libflate crate before 0.1.25 for Rust. MultiDecoder::read has a use-after-free, leading t...
CVE-2019-15551An issue was discovered in the smallvec crate before 0.6.10 for Rust. There is a double free for certain grow attempts w...
CVE-2019-15550HIGH7.5An issue was discovered in the simd-json crate before 0.1.15 for Rust. There is an out-of-bounds read and an incorrect c...
CVE-2019-14307HIGH8.8Several Ricoh printers have multiple buffer overflows parsing HTTP parameter settings for SNMP, which allow an attacker ...
CVE-2019-14305HIGH8.8Several Ricoh printers have multiple buffer overflows parsing HTTP parameter settings for Wi-Fi, mDNS, POP3, SMTP, and n...
CVE-2019-14300CRITICAL9.8Several Ricoh printers have multiple buffer overflows parsing HTTP cookie headers, which allow an attacker to cause a de...
CVE-2019-15501Reflected cross site scripting (XSS) in L-Soft LISTSERV before 16.5-2018a exists via the /scripts/wa.exe OK parameter.
CVE-2019-15479Status Board 1.1.81 has reflected XSS via dashboard.ts.
CVE-2019-14308CRITICAL9.8Several Ricoh printers have multiple buffer overflows parsing LPD packets, which allow an attacker to cause a denial of ...
CVE-2019-15562CRITICAL9.8GORM before 1.9.10 allows SQL injection via incomplete parentheses. NOTE: Misusing Gorm by passing untrusted user input ...
CVE-2019-15561FlashLingo before 2019-06-12 allows SQL injection, related to flashlingo.js and db.js.
CVE-2019-15556Pvanloon1983 social_network before 2019-07-03 allows SQL injection in includes/form_handlers/register_handler.php.
CVE-2019-15524CSZ CMS 1.2.3 allows arbitrary file upload, as demonstrated by a .php file to admin/filemanager in the File Management M...
CVE-2019-15521Spoon Library through 2014-02-06, as used in Fork CMS before 1.4.1 and other products, allows PHP object injection via a...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now