2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-12743HumHub Social Network Kit Enterprise v1.3.13 allows remote attackers to find the user accounts existing on any Social Ne...
CVE-2019-11201Dolibarr ERP/CRM 9.0.1 provides a module named website that provides for creation of public websites with a WYSIWYG edit...
CVE-2019-11200Dolibarr ERP/CRM 9.0.1 provides a web-based functionality that backs up the database content to a dump file. However, th...
CVE-2019-11199Dolibarr ERP/CRM 9.0.1 was affected by stored XSS within uploaded files. These vulnerabilities allowed the execution of ...
CVE-2019-13103HIGH7.1A crafted self-referential DOS partition table will cause all Das U-Boot versions through 2019.07-rc4 to infinitely recu...
CVE-2019-12613Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn. Further inves...
CVE-2019-1020009Fleet before 2.1.2 allows exposure of SMTP credentials.
CVE-2019-1020008stacktable.js before 1.0.4 allows XSS.
CVE-2019-1020007Dependency-Track before 3.5.1 allows XSS.
CVE-2019-1020006invenio-app before 1.1.1 allows host header injection.
CVE-2019-1020005invenio-communities before 1.0.0a20 allows XSS.
CVE-2019-1020004Tridactyl before 1.16.0 allows fake key events.
CVE-2019-1020003invenio-records before 1.2.2 allows XSS.
CVE-2019-1020002Pterodactyl before 0.7.14 with 2FA allows credential sniffing.
CVE-2019-1105A spoofing vulnerability exists in the way Microsoft Outlook for Android software parses specifically crafted email mess...
CVE-2019-1020019invenio-previewer before 1.0.0a12 allows XSS.
CVE-2019-1020018HIGH7.3Discourse before 2.3.0 and 2.4.x before 2.4.0.beta3 lacks a confirmation screen when logging in via an email link.
CVE-2019-1020017MEDIUM5.3Discourse before 2.3.0 and 2.4.x before 2.4.0.beta3 lacks a confirmation screen when logging in via a user-api OTP.
CVE-2019-1020016ASH-AIO before 2.0.0.3 allows an open redirect.
CVE-2019-1020015graphql-engine (aka Hasura GraphQL Engine) before 1.0.0-beta.3 mishandles the audience check while verifying JWT.
CVE-2019-1020014MEDIUM5.5docker-credential-helpers before 0.6.3 has a double free in the List functions.
CVE-2019-1020013parse-server before 3.6.0 allows account enumeration.
CVE-2019-1020012parse-server before 3.4.1 allows DoS after any POST to a volatile class.
CVE-2019-1020011HIGH7.2SmokeDetector intentionally does automatic deployments of updated copies of SmokeDetector without server operator author...
CVE-2019-1020010Misskey before 10.102.4 allows hijacking a user's token.

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now