2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-14548An issue was discovered in EspoCRM before 5.6.9. Stored XSS in the body of an Article was executed when a victim opens a...
CVE-2019-14547An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed when a attacker sends an attachment to admin wi...
CVE-2019-14546An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed on the Preference page as well as while sending...
CVE-2019-10994Processing a specially crafted project file in LAquis SCADA 4.3.1.71 may trigger an out-of-bounds read, which may allow ...
CVE-2019-10980HIGH7.8A type confusion vulnerability may be exploited when LAquis SCADA 4.3.1.71 processes a specially crafted project file. T...
CVE-2019-12264HIGH7.1Wind River VxWorks 6.6, 6.7, 6.8, 6.9.3, 6.9.4, and Vx7 has Incorrect Access Control in IPv4 assignment by the ipdhcpc D...
CVE-2019-11198Multiple cross-site scripting (XSS) vulnerabilities in Sitecore CMS 9.0.1 and earlier allow remote attackers to inject a...
CVE-2019-3800MEDIUM6.3CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when th...
CVE-2019-3717MEDIUM6.8Select Dell Client Commercial and Consumer platforms contain an Improper Access Vulnerability. An unauthenticated attack...
CVE-2019-11270HIGH7.5Cloud Foundry UAA versions prior to v73.4.0 contain a vulnerability where a malicious client possessing the 'clients.wri...
CVE-2019-14348The BearDev JoomSport plugin 3.3 for WordPress allows SQL injection to steal, modify, or delete database information via...
CVE-2019-4473HIGH7.8Multiple binaries in IBM SDK, Java Technology Edition 7, 7R, and 8 on the AIX platform use insecure absolute RPATHs, whi...
CVE-2019-4284MEDIUM4.4IBM Cloud Private 2.1.0 , 3.1.0, 3.1.1, and 3.1.2 could allow a local privileged user to obtain sensitive OIDC token tha...
CVE-2019-4261MEDIUM6.5IBM WebSphere MQ V7.1, 7.5, IBM MQ V8, IBM MQ V9.0LTS, IBM MQ V9.1 LTS, and IBM MQ V9.1 CD are vulnerable to a denial of...
CVE-2019-14663Brandy 1.20.1 has a stack-based buffer overflow in fileio_openin in fileio.c via crafted BASIC source code.
CVE-2019-14662Brandy 1.20.1 has a stack-based buffer overflow in fileio_openout in fileio.c via crafted BASIC source code.
CVE-2019-14525In Octopus Deploy 2019.4.0 through 2019.6.x before 2019.6.6, and 2019.7.x before 2019.7.6, an authenticated system admin...
CVE-2019-14521The api/admin/logoupload Logo File upload feature in EMCA Energy Logserver 6.1.2 allows attackers to send any kind of fi...
CVE-2019-14655Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2019-14654In Joomla! 3.9.7 and 3.9.8, inadequate filtering allows users authorised to create custom fields to manipulate the filte...
CVE-2019-14653pandao Editor.md 1.5.0 allows XSS via an attribute of an ABBR or SUP element.
CVE-2019-14551Das Q before 2019-08-02 allows web sites to execute arbitrary code on client machines, as demonstrated by a cross-origin...
CVE-2019-7951An information leakage vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prio...
CVE-2019-7950An access control bypass vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 pr...
CVE-2019-7947A cross-site request forgery vulnerability exists in the GiftCardAccount removal feature for Magento Open Source prior t...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now