2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-2386 | HIGH | 7.1 | 1.2% | Aug 6, 2019 | After user deletion in MongoDB Server the improper invalidation of authorization sessions allows an authenticated user's... |
| CVE-2019-14473 | — | — | 1.9% | Aug 6, 2019 | eQ-3 Homematic CCU2 and CCU3 use session IDs for authentication but lack authorization checks. Consequently, a valid gue... |
| CVE-2019-13104 | HIGH | 7.8 | 1.1% | Aug 6, 2019 | In Das U-Boot versions 2016.11-rc1 through 2019.07-rc4, an underflow can cause memcpy() to overwrite a very large amount... |
| CVE-2019-13143 | — | — | 3.1% | Aug 6, 2019 | An HTTP parameter pollution issue was discovered on Shenzhen Dragon Brothers Fingerprint Bluetooth Round Padlock FB50 2.... |
| CVE-2019-14347 | HIGH | 8.8 | 9.3% | Aug 6, 2019 | Internal/Views/addUsers.php in Schben Adive 2.0.7 allows remote unprivileged users (editor or developer) to create an ad... |
| CVE-2019-12950 | — | — | 0.8% | Aug 6, 2019 | An issue was discovered in TeamPass 2.1.27.35. From the sources/items.queries.php "Import items" feature, it is possible... |
| CVE-2019-14697 | CRITICAL | 9.8 | 2.5% | Aug 6, 2019 | musl libc through 1.1.23 has an x87 floating-point stack adjustment imbalance, related to the math/i386/ directory. In s... |
| CVE-2019-14696 | — | — | 15.4% | Aug 6, 2019 | Open-School 3.0, and Community Edition 2.3, allows XSS via the osv/index.php?r=students/guardians/create id parameter. |
| CVE-2019-14346 | — | — | 2.7% | Aug 6, 2019 | Internal/Views/config.php in Schben Adive 2.0.7 allows admin/config CSRF to change a user password. |
| CVE-2019-14695 | CRITICAL | 9.8 | 2.7% | Aug 6, 2019 | A SQL injection vulnerability exists in the Sygnoos Popup Builder plugin before 3.45 for WordPress. Successful exploitat... |
| CVE-2019-14692 | HIGH | 8.8 | 1.7% | Aug 6, 2019 | AdPlug 2.3.1 has a heap-based buffer overflow in CmkjPlayer::load() in mkj.cpp. |
| CVE-2019-14691 | HIGH | 8.8 | 1.7% | Aug 6, 2019 | AdPlug 2.3.1 has a heap-based buffer overflow in CdtmLoader::load() in dtm.cpp. |
| CVE-2019-14690 | HIGH | 8.8 | 1.7% | Aug 6, 2019 | AdPlug 2.3.1 has a heap-based buffer overflow in CxadbmfPlayer::__bmf_convert_stream() in bmf.cpp. |
| CVE-2019-14672 | — | — | 0.7% | Aug 5, 2019 | Firefly III 4.7.17.5 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the liability na... |
| CVE-2019-14671 | — | — | 0.5% | Aug 5, 2019 | Firefly III 4.7.17.3 is vulnerable to local file enumeration. An attacker can enumerate local files due to the lack of p... |
| CVE-2019-14670 | — | — | 0.8% | Aug 5, 2019 | Firefly III 4.7.17.3 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the bill name fi... |
| CVE-2019-14669 | — | — | 0.8% | Aug 5, 2019 | Firefly III 4.7.17.3 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the asset accoun... |
| CVE-2019-14668 | — | — | 0.8% | Aug 5, 2019 | Firefly III 4.7.17.3 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the transaction ... |
| CVE-2019-14667 | — | — | 1.3% | Aug 5, 2019 | Firefly III 4.7.17.4 is vulnerable to multiple stored XSS issues due to the lack of filtration of user-supplied data in ... |
| CVE-2019-14664 | MEDIUM | 6.5 | 1.0% | Aug 5, 2019 | In Enigmail below 2.1, an attacker in possession of PGP encrypted emails can wrap them as sub-parts within a crafted mul... |
| CVE-2019-14475 | — | — | 2.0% | Aug 5, 2019 | eQ-3 Homematic CCU2 2.47.15 and prior and CCU3 3.47.15 and prior use session IDs for authentication but lack authorizati... |
| CVE-2019-5502 | — | — | 0.9% | Aug 5, 2019 | SMB in Data ONTAP operating in 7-Mode versions prior to 8.2.5P3 has weak cryptography which when exploited could lead to... |
| CVE-2019-14665 | — | — | 0.8% | Aug 5, 2019 | Brandy 1.20.1 has a heap-based buffer overflow in define_array in variables.c via crafted BASIC source code. |
| CVE-2019-14550 | — | — | 1.1% | Aug 5, 2019 | An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed when a victim clicks on the Edit Dashboard feat... |
| CVE-2019-14549 | — | — | 1.1% | Aug 5, 2019 | An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed inside the title and breadcrumb of a newly form... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now