2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-14548 | — | — | 1.1% | Aug 5, 2019 | An issue was discovered in EspoCRM before 5.6.9. Stored XSS in the body of an Article was executed when a victim opens a... |
| CVE-2019-14547 | — | — | 1.1% | Aug 5, 2019 | An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed when a attacker sends an attachment to admin wi... |
| CVE-2019-14546 | — | — | 1.1% | Aug 5, 2019 | An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed on the Preference page as well as while sending... |
| CVE-2019-10994 | — | — | 0.9% | Aug 5, 2019 | Processing a specially crafted project file in LAquis SCADA 4.3.1.71 may trigger an out-of-bounds read, which may allow ... |
| CVE-2019-10980 | HIGH | 7.8 | 1.0% | Aug 5, 2019 | A type confusion vulnerability may be exploited when LAquis SCADA 4.3.1.71 processes a specially crafted project file. T... |
| CVE-2019-12264 | HIGH | 7.1 | 8.3% | Aug 5, 2019 | Wind River VxWorks 6.6, 6.7, 6.8, 6.9.3, 6.9.4, and Vx7 has Incorrect Access Control in IPv4 assignment by the ipdhcpc D... |
| CVE-2019-11198 | — | — | 1.1% | Aug 5, 2019 | Multiple cross-site scripting (XSS) vulnerabilities in Sitecore CMS 9.0.1 and earlier allow remote attackers to inject a... |
| CVE-2019-3800 | MEDIUM | 6.3 | 2.1% | Aug 5, 2019 | CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when th... |
| CVE-2019-3717 | MEDIUM | 6.8 | 0.4% | Aug 5, 2019 | Select Dell Client Commercial and Consumer platforms contain an Improper Access Vulnerability. An unauthenticated attack... |
| CVE-2019-11270 | HIGH | 7.5 | 1.1% | Aug 5, 2019 | Cloud Foundry UAA versions prior to v73.4.0 contain a vulnerability where a malicious client possessing the 'clients.wri... |
| CVE-2019-14348 | — | — | 21.1% | Aug 5, 2019 | The BearDev JoomSport plugin 3.3 for WordPress allows SQL injection to steal, modify, or delete database information via... |
| CVE-2019-4473 | HIGH | 7.8 | 0.4% | Aug 5, 2019 | Multiple binaries in IBM SDK, Java Technology Edition 7, 7R, and 8 on the AIX platform use insecure absolute RPATHs, whi... |
| CVE-2019-4284 | MEDIUM | 4.4 | 0.4% | Aug 5, 2019 | IBM Cloud Private 2.1.0 , 3.1.0, 3.1.1, and 3.1.2 could allow a local privileged user to obtain sensitive OIDC token tha... |
| CVE-2019-4261 | MEDIUM | 6.5 | 2.6% | Aug 5, 2019 | IBM WebSphere MQ V7.1, 7.5, IBM MQ V8, IBM MQ V9.0LTS, IBM MQ V9.1 LTS, and IBM MQ V9.1 CD are vulnerable to a denial of... |
| CVE-2019-14663 | — | — | 0.8% | Aug 5, 2019 | Brandy 1.20.1 has a stack-based buffer overflow in fileio_openin in fileio.c via crafted BASIC source code. |
| CVE-2019-14662 | — | — | 0.8% | Aug 5, 2019 | Brandy 1.20.1 has a stack-based buffer overflow in fileio_openout in fileio.c via crafted BASIC source code. |
| CVE-2019-14525 | — | — | 1.5% | Aug 5, 2019 | In Octopus Deploy 2019.4.0 through 2019.6.x before 2019.6.6, and 2019.7.x before 2019.7.6, an authenticated system admin... |
| CVE-2019-14521 | — | — | 2.4% | Aug 5, 2019 | The api/admin/logoupload Logo File upload feature in EMCA Energy Logserver 6.1.2 allows attackers to send any kind of fi... |
| CVE-2019-14655 | — | — | — | Aug 5, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2019-14654 | — | — | 2.3% | Aug 5, 2019 | In Joomla! 3.9.7 and 3.9.8, inadequate filtering allows users authorised to create custom fields to manipulate the filte... |
| CVE-2019-14653 | — | — | 0.8% | Aug 3, 2019 | pandao Editor.md 1.5.0 allows XSS via an attribute of an ABBR or SUP element. |
| CVE-2019-14551 | — | — | 1.1% | Aug 3, 2019 | Das Q before 2019-08-02 allows web sites to execute arbitrary code on client machines, as demonstrated by a cross-origin... |
| CVE-2019-7951 | — | — | 1.2% | Aug 2, 2019 | An information leakage vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prio... |
| CVE-2019-7950 | — | — | 2.2% | Aug 2, 2019 | An access control bypass vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 pr... |
| CVE-2019-7947 | — | — | 0.4% | Aug 2, 2019 | A cross-site request forgery vulnerability exists in the GiftCardAccount removal feature for Magento Open Source prior t... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now