2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-15304 | — | — | 3.4% | Aug 26, 2019 | Lierda Grill Temperature Monitor V1.00_50006 has a default password of admin for the admin account, which allows an atta... |
| CVE-2019-15541 | — | — | 2.2% | Aug 26, 2019 | rustls-mio/examples/tlsserver.rs in the rustls crate before 0.16.0 for Rust allows attackers to cause a denial of servic... |
| CVE-2019-15534 | — | — | 1.4% | Aug 26, 2019 | Raml-Module-Builder 26.4.0 allows SQL Injection in PostgresClient.update. |
| CVE-2019-15532 | — | — | 1.3% | Aug 26, 2019 | CyberChef before 8.31.2 allows XSS in core/operations/TextEncodingBruteForce.mjs. |
| CVE-2019-15506 | — | — | 1.8% | Aug 26, 2019 | An issue was discovered in Kaseya Virtual System Administrator (VSA) through 9.4.0.37. It has a critical information dis... |
| CVE-2019-15489 | — | — | 0.9% | Aug 26, 2019 | laracom (aka Laravel FREE E-Commerce Software) 1.4.11 has search?q= XSS. |
| CVE-2019-15478 | — | — | 0.8% | Aug 26, 2019 | Status Board 1.1.81 has reflected XSS via logic.ts. |
| CVE-2019-15540 | — | — | 0.6% | Aug 25, 2019 | filters/filter-cso/filter-stream.c in the CSO filter in libMirage 3.2.2 in CDemu does not validate the part size, trigge... |
| CVE-2019-15538 | HIGH | 7.5 | 3.9% | Aug 25, 2019 | An issue was discovered in xfs_setattr_nonsize in fs/xfs/xfs_iops.c in the Linux kernel through 5.2.9. XFS partially wed... |
| CVE-2019-6695 | CRITICAL | 9.8 | 0.8% | Aug 23, 2019 | Lack of root file system integrity checking in Fortinet FortiManager VM application images of 6.2.0, 6.0.6 and below may... |
| CVE-2019-5594 | — | — | 0.7% | Aug 23, 2019 | An Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") in Fortinet FortiNAC 8.3.0 to 8.... |
| CVE-2019-15092 | — | — | 5.1% | Aug 23, 2019 | The webtoffee "WordPress Users & WooCommerce Customers Import Export" plugin 1.3.0 for WordPress allows CSV injection in... |
| CVE-2019-12400 | MEDIUM | 5.5 | 0.8% | Aug 23, 2019 | In version 2.0.3 Apache Santuario XML Security for Java, a caching mechanism was introduced to speed up creating new XML... |
| CVE-2019-7364 | — | — | 1.9% | Aug 23, 2019 | DLL preloading vulnerability in versions 2017, 2018, 2019, and 2020 of Autodesk Advanced Steel, Civil 3D, AutoCAD, AutoC... |
| CVE-2019-7363 | — | — | 1.3% | Aug 23, 2019 | Use-after-free vulnerability in Autodesk Design Review versions 2011, 2012, 2013, and 2018. An attacker may trick a user... |
| CVE-2019-7362 | — | — | 1.2% | Aug 23, 2019 | DLL preloading vulnerability in Autodesk Design Review versions 2011, 2012, 2013, and 2018. An attacker may trick a user... |
| CVE-2019-6698 | CRITICAL | 9.8 | 1.5% | Aug 23, 2019 | Use of Hard-coded Credentials vulnerability in FortiRecorder all versions below 2.7.4 may allow an unauthenticated attac... |
| CVE-2019-5592 | MEDIUM | 5.9 | 0.7% | Aug 23, 2019 | Multiple padding oracle vulnerabilities (Zombie POODLE, GOLDENDOODLE, OpenSSL 0-length) in the CBC padding implementatio... |
| CVE-2019-1583 | — | — | 1.2% | Aug 23, 2019 | Escalation of privilege vulnerability in the Palo Alto Networks Twistlock console 19.07.358 and earlier allows a Twistlo... |
| CVE-2019-1582 | — | — | 1.0% | Aug 23, 2019 | Memory corruption in PAN-OS 8.1.9 and earlier, and PAN-OS 9.0.3 and earlier will allow an administrative user to cause a... |
| CVE-2019-1581 | CRITICAL | 9.8 | 3.2% | Aug 23, 2019 | A remote code execution vulnerability in the PAN-OS SSH device management interface that can lead to unauthenticated rem... |
| CVE-2019-1580 | — | — | 3.2% | Aug 23, 2019 | Memory corruption in PAN-OS 7.1.24 and earlier, PAN-OS 8.0.19 and earlier, PAN-OS 8.1.9 and earlier, and PAN-OS 9.0.3 an... |
| CVE-2019-15537 | — | — | 1.6% | Aug 23, 2019 | The proxystatistics module before 3.1.0 for SimpleSAMLphp allows SQL Injection in lib/Auth/Process/DatabaseCommand.php. |
| CVE-2019-15536 | — | — | 1.4% | Aug 23, 2019 | The Acclaim block plugin before 2019-06-26 for Moodle allows SQL Injection via delete_records. |
| CVE-2019-15535 | — | — | 1.5% | Aug 23, 2019 | Tasking Manager before 3.4.0 allows SQL Injection via custom SQL. |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now