2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-14518Evolution CMS 2.0.x allows XSS via a description and new category location in a template. NOTE: the vendor states that t...
CVE-2019-13578CRITICAL9.8A SQL injection vulnerability exists in the Impress GiveWP Give plugin through 2.5.0 for WordPress. Successful exploitat...
CVE-2019-3418MEDIUM5.4All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by cross-site scripting vulnerability (XSS). Due t...
CVE-2019-3417HIGH8.8All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by command injection vulnerability. Due to insuffi...
CVE-2019-15081MEDIUM4.8OpenCart 3.x, when the attacker has login access to the admin panel, allows stored XSS within the Source/HTML editing fe...
CVE-2019-14800The FV Flowplayer Video Player plugin before 7.3.15.727 for WordPress allows guests to obtain the email subscription lis...
CVE-2019-14795The toggle-the-title (aka Toggle The Title) plugin 1.4 for WordPress has XSS via the wp-admin/admin-ajax.php?action=upda...
CVE-2019-14790The limb-gallery (aka Limb Gallery) plugin 1.4.0 for WordPress has XSS via the wp-admin/admin-ajax.php?action=grsGallery...
CVE-2019-14755The profile photo upload feature in Leaf Admin 61.9.0212.10 f allows Unrestricted Upload of a File with a Dangerous Type...
CVE-2019-15062An issue was discovered in Dolibarr 11.0.0-alpha. A user can store an IFRAME element (containing a user/card.php CSRF re...
CVE-2019-14427XSS exists in WEB STUDIO Ultimate Loan Manager 2.0 by adding a branch under the Branches button that sets the notes para...
CVE-2019-9585eQ-3 Homematic CCU2 prior to 2.47.10 and CCU3 prior to 3.47.10 JSON API has Improper Access Control for Interface.***Met...
CVE-2019-9584eQ-3 Homematic AddOn 'CloudMatic' on CCU2 and CCU3 allows uncontrolled admin access, resulting in the ability to obtain ...
CVE-2019-1258An elevation of privilege vulnerability exists in Azure Active Directory Authentication Library On-Behalf-Of flow, in th...
CVE-2019-1229An elevation of privilege vulnerability exists in Dynamics On-Premise v9. An attacker who successfully exploited the vul...
CVE-2019-1228MEDIUM5.5An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker...
CVE-2019-1227MEDIUM5.5An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker...
CVE-2019-1226CRITICAL9.8A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an ...
CVE-2019-1225HIGH7.5An information disclosure vulnerability exists when the Windows RDP server improperly discloses the contents of its memo...
CVE-2019-1224HIGH7.5An information disclosure vulnerability exists when the Windows RDP server improperly discloses the contents of its memo...
CVE-2019-1223HIGH7.5A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system...
CVE-2019-1222CRITICAL9.8A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an ...
CVE-2019-1218A spoofing vulnerability exists in the way Microsoft Outlook iOS software parses specifically crafted email messages. An...
CVE-2019-1213CRITICAL9.8A memory corruption vulnerability exists in the Windows Server DHCP service when an attacker sends specially crafted pac...
CVE-2019-1212CRITICAL9.8A memory corruption vulnerability exists in the Windows Server DHCP service when processing specially crafted packets. A...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now