2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-14391 | — | — | 0.4% | Jul 30, 2019 | cPanel before 82.0.2 does not properly enforce Reseller package creation ACLs (SEC-514). |
| CVE-2019-14390 | — | — | 0.6% | Jul 30, 2019 | cPanel before 82.0.2 has stored XSS in the WHM Modify Account interface (SEC-512). |
| CVE-2019-14389 | — | — | 0.4% | Jul 30, 2019 | cPanel before 82.0.2 allows local users to discover the MySQL root password (SEC-510). |
| CVE-2019-14388 | — | — | 1.1% | Jul 30, 2019 | cPanel before 82.0.2 allows unauthenticated file creation because Exim log parsing is mishandled (SEC-507). |
| CVE-2019-14387 | — | — | 0.8% | Jul 30, 2019 | cPanel before 82.0.2 has Self XSS in the cPanel and webmail master templates (SEC-506). |
| CVE-2019-14386 | — | — | 0.6% | Jul 30, 2019 | cPanel before 82.0.2 has stored XSS in the WHM Tomcat Manager interface (SEC-504). |
| CVE-2019-14381 | — | — | 1.4% | Jul 30, 2019 | libopenmpt before 0.4.3 allows a crash due to a NULL pointer dereference when doing a portamento from an OPL instrument ... |
| CVE-2019-14327 | — | — | 0.6% | Jul 30, 2019 | A CSRF vulnerability in Settings form in the Custom Simple Rss plugin 2.0.6 for WordPress allows attackers to change the... |
| CVE-2019-13635 | — | — | 45.4% | Jul 30, 2019 | The WP Fastest Cache plugin through 0.8.9.5 for WordPress allows wpFastestCache.php and inc/cache.php Directory Traversa... |
| CVE-2019-14439 | HIGH | 7.5 | 10.8% | Jul 30, 2019 | A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typ... |
| CVE-2019-3948 | — | — | 26.7% | Jul 29, 2019 | The Amcrest IP2M-841B V2.520.AC00.18.R, Dahua IPC-XXBXX V2.622.0000000.9.R, Dahua IPC HX5X3X and HX4X3X V2.800.0000008.0... |
| CVE-2019-14431 | CRITICAL | 9.8 | 3.6% | Jul 29, 2019 | In MatrixSSL 3.8.3 Open through 4.2.1 Open, the DTLS server mishandles incoming network messages leading to a heap-based... |
| CVE-2019-14418 | HIGH | 8.8 | 4.1% | Jul 29, 2019 | An issue was discovered in Veritas Resiliency Platform (VRP) before 3.4 HF1. When uploading an application bundle, a dir... |
| CVE-2019-14417 | HIGH | 7.2 | 4.0% | Jul 29, 2019 | An issue was discovered in Veritas Resiliency Platform (VRP) before 3.4 HF1. An arbitrary command execution vulnerabilit... |
| CVE-2019-14416 | HIGH | 7.2 | 4.5% | Jul 29, 2019 | An issue was discovered in Veritas Resiliency Platform (VRP) before 3.4 HF1. An arbitrary command execution vulnerabilit... |
| CVE-2019-14415 | MEDIUM | 4.8 | 1.1% | Jul 29, 2019 | An issue was discovered in Veritas Resiliency Platform (VRP) before 3.4 HF1. A persistent cross-site scripting (XSS) vul... |
| CVE-2019-13655 | — | — | 1.4% | Jul 29, 2019 | Imgix through 2019-06-19 allows remote attackers to cause a denial of service (resource consumption) by manipulating a s... |
| CVE-2019-14271 | CRITICAL | 9.8 | 18.8% | Jul 29, 2019 | In Docker 19.03.x before 19.03.1 linked against the GNU C Library (aka glibc), code injection can occur when the nsswitc... |
| CVE-2019-13571 | CRITICAL | 9.8 | 4.0% | Jul 29, 2019 | A SQL injection vulnerability exists in the Vsourz Digital Advanced CF7 DB plugin through 1.6.1 for WordPress. Successfu... |
| CVE-2019-13498 | HIGH | 7.4 | 1.2% | Jul 29, 2019 | One Identity Cloud Access Manager 8.1.3 does not use HTTP Strict Transport Security (HSTS), which may allow man-in-the-m... |
| CVE-2019-13126 | HIGH | 7.5 | 1.7% | Jul 29, 2019 | An integer overflow in NATS Server before 2.0.2 allows a remote attacker to crash the server by sending a crafted reques... |
| CVE-2019-11868 | HIGH | 7.8 | 0.4% | Jul 29, 2019 | See.sys, up to version 4.25, in SoftEther VPN Server versions 4.29 or older, allows a user to call an IOCTL specifying a... |
| CVE-2019-6726 | — | — | 4.3% | Jul 29, 2019 | The WP Fastest Cache plugin through 0.8.9.0 for WordPress allows remote attackers to delete arbitrary files because wp_p... |
| CVE-2019-14267 | HIGH | 7.8 | 7.1% | Jul 29, 2019 | PDFResurrect 0.15 has a buffer overflow via a crafted PDF file because data associated with startxref and %%EOF is misha... |
| CVE-2019-12948 | — | — | 1.7% | Jul 29, 2019 | A vulnerability in the web-based management interface of VVX, Trio, SoundStructure, SoundPoint, and SoundStation phones ... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now