2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-15304Lierda Grill Temperature Monitor V1.00_50006 has a default password of admin for the admin account, which allows an atta...
CVE-2019-15541rustls-mio/examples/tlsserver.rs in the rustls crate before 0.16.0 for Rust allows attackers to cause a denial of servic...
CVE-2019-15534Raml-Module-Builder 26.4.0 allows SQL Injection in PostgresClient.update.
CVE-2019-15532CyberChef before 8.31.2 allows XSS in core/operations/TextEncodingBruteForce.mjs.
CVE-2019-15506An issue was discovered in Kaseya Virtual System Administrator (VSA) through 9.4.0.37. It has a critical information dis...
CVE-2019-15489laracom (aka Laravel FREE E-Commerce Software) 1.4.11 has search?q= XSS.
CVE-2019-15478Status Board 1.1.81 has reflected XSS via logic.ts.
CVE-2019-15540filters/filter-cso/filter-stream.c in the CSO filter in libMirage 3.2.2 in CDemu does not validate the part size, trigge...
CVE-2019-15538HIGH7.5An issue was discovered in xfs_setattr_nonsize in fs/xfs/xfs_iops.c in the Linux kernel through 5.2.9. XFS partially wed...
CVE-2019-6695CRITICAL9.8Lack of root file system integrity checking in Fortinet FortiManager VM application images of 6.2.0, 6.0.6 and below may...
CVE-2019-5594An Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") in Fortinet FortiNAC 8.3.0 to 8....
CVE-2019-15092The webtoffee "WordPress Users & WooCommerce Customers Import Export" plugin 1.3.0 for WordPress allows CSV injection in...
CVE-2019-12400MEDIUM5.5In version 2.0.3 Apache Santuario XML Security for Java, a caching mechanism was introduced to speed up creating new XML...
CVE-2019-7364DLL preloading vulnerability in versions 2017, 2018, 2019, and 2020 of Autodesk Advanced Steel, Civil 3D, AutoCAD, AutoC...
CVE-2019-7363Use-after-free vulnerability in Autodesk Design Review versions 2011, 2012, 2013, and 2018. An attacker may trick a user...
CVE-2019-7362DLL preloading vulnerability in Autodesk Design Review versions 2011, 2012, 2013, and 2018. An attacker may trick a user...
CVE-2019-6698CRITICAL9.8Use of Hard-coded Credentials vulnerability in FortiRecorder all versions below 2.7.4 may allow an unauthenticated attac...
CVE-2019-5592MEDIUM5.9Multiple padding oracle vulnerabilities (Zombie POODLE, GOLDENDOODLE, OpenSSL 0-length) in the CBC padding implementatio...
CVE-2019-1583Escalation of privilege vulnerability in the Palo Alto Networks Twistlock console 19.07.358 and earlier allows a Twistlo...
CVE-2019-1582Memory corruption in PAN-OS 8.1.9 and earlier, and PAN-OS 9.0.3 and earlier will allow an administrative user to cause a...
CVE-2019-1581CRITICAL9.8A remote code execution vulnerability in the PAN-OS SSH device management interface that can lead to unauthenticated rem...
CVE-2019-1580Memory corruption in PAN-OS 7.1.24 and earlier, PAN-OS 8.0.19 and earlier, PAN-OS 8.1.9 and earlier, and PAN-OS 9.0.3 an...
CVE-2019-15537The proxystatistics module before 3.1.0 for SimpleSAMLphp allows SQL Injection in lib/Auth/Process/DatabaseCommand.php.
CVE-2019-15536The Acclaim block plugin before 2019-06-26 for Moodle allows SQL Injection via delete_records.
CVE-2019-15535Tasking Manager before 3.4.0 allows SQL Injection via custom SQL.

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now