2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-15120MEDIUM5.4The Kunena extension before 5.1.14 for Joomla! allows XSS via BBCode.
CVE-2019-15119MEDIUM5.5lib/install/install.go in cnlh nps through 0.23.2 uses 0777 permissions for /usr/local/bin/nps and/or /usr/bin/nps, lead...
CVE-2019-15118MEDIUM5.5check_input_term in sound/usb/mixer.c in the Linux kernel through 5.2.9 mishandles recursion, leading to kernel stack ex...
CVE-2019-15117parse_audio_mixer_unit in sound/usb/mixer.c in the Linux kernel through 5.2.9 mishandles a short descriptor, leading to ...
CVE-2019-15091filemgr.php in Artica Integria IMS 5.0.86 allows index.php?sec=wiki&sec2=operation/wiki/wiki&action=upload arbitrary fil...
CVE-2019-14923EyesOfNetwork 5.1 allows Remote Command Execution via shell metacharacters in the module/tool_all/ host field.
CVE-2019-15108MEDIUM4.8An issue was discovered in WSO2 API Manager 2.6.0 before WSO2-CARBON-PATCH-4.4.0-4457. There is XSS via a crafted filena...
CVE-2019-15107CRITICAL9.8An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera...
CVE-2019-15106An issue was discovered in Zoho ManageEngine OpManager in builds before 14310. One can bypass the user password requirem...
CVE-2019-15105An issue was discovered in Zoho ManageEngine Application Manager through 14.2. There is a SQL Injection vulnerability in...
CVE-2019-15104An issue was discovered in Zoho ManageEngine OpManager through 12.4x. There is a SQL Injection vulnerability in jsp/NewT...
CVE-2019-15099HIGH7.5drivers/net/wireless/ath/ath10k/usb.c in the Linux kernel through 5.2.8 has a NULL pointer dereference via an incomplete...
CVE-2019-15098MEDIUM4.6drivers/net/wireless/ath/ath6kl/usb.c in the Linux kernel through 5.2.9 has a NULL pointer dereference via an incomplete...
CVE-2019-15095DWSurvey through 2019-07-22 has reflected XSS via the design/qu-multi-fillblank!answers.action surveyId parameter.
CVE-2019-15090MEDIUM6.7An issue was discovered in drivers/scsi/qedi/qedi_dbg.c in the Linux kernel before 5.1.12. In the qedi_dbg_* family of f...
CVE-2019-15084Realtek Waves MaxxAudio driver 1.6.2.0, as used on Dell laptops, installs with incorrect file permissions. As a result, ...
CVE-2019-9852HIGH7.8LibreOffice has a feature where documents can specify that pre-installed macros can be executed on various script events...
CVE-2019-9851CRITICAL9.8LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitra...
CVE-2019-9850CRITICAL9.8LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitra...
CVE-2019-10081HTTP/2 (2.4.20 through 2.4.39) very early pushes, for example configured with "H2PushResource", could lead to an overwri...
CVE-2019-12792A command injection vulnerability in UploadHandler.php in Vesta Control Panel 0.9.8-24 allows remote attackers to escala...
CVE-2019-12791A directory traversal vulnerability in the v-list-user script in Vesta Control Panel 0.9.8-24 allows remote attackers to...
CVE-2019-3974Nessus 8.5.2 and earlier on Windows platforms were found to contain an issue where certain system files could be overwri...
CVE-2019-13516HIGH8.8In OSIsoft PI Web API and prior, the affected product is vulnerable to a direct attack due to a cross-site request forge...
CVE-2019-13515OSIsoft PI Web API 2018 and prior may allow disclosure of sensitive information.

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now