2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-12743 | — | — | 1.5% | Jul 29, 2019 | HumHub Social Network Kit Enterprise v1.3.13 allows remote attackers to find the user accounts existing on any Social Ne... |
| CVE-2019-11201 | — | — | 2.2% | Jul 29, 2019 | Dolibarr ERP/CRM 9.0.1 provides a module named website that provides for creation of public websites with a WYSIWYG edit... |
| CVE-2019-11200 | — | — | 2.1% | Jul 29, 2019 | Dolibarr ERP/CRM 9.0.1 provides a web-based functionality that backs up the database content to a dump file. However, th... |
| CVE-2019-11199 | — | — | 1.0% | Jul 29, 2019 | Dolibarr ERP/CRM 9.0.1 was affected by stored XSS within uploaded files. These vulnerabilities allowed the execution of ... |
| CVE-2019-13103 | HIGH | 7.1 | 0.4% | Jul 29, 2019 | A crafted self-referential DOS partition table will cause all Das U-Boot versions through 2019.07-rc4 to infinitely recu... |
| CVE-2019-12613 | — | — | — | Jul 29, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn. Further inves... |
| CVE-2019-1020009 | — | — | 1.4% | Jul 29, 2019 | Fleet before 2.1.2 allows exposure of SMTP credentials. |
| CVE-2019-1020008 | — | — | 0.8% | Jul 29, 2019 | stacktable.js before 1.0.4 allows XSS. |
| CVE-2019-1020007 | — | — | 0.6% | Jul 29, 2019 | Dependency-Track before 3.5.1 allows XSS. |
| CVE-2019-1020006 | — | — | 0.9% | Jul 29, 2019 | invenio-app before 1.1.1 allows host header injection. |
| CVE-2019-1020005 | — | — | 0.7% | Jul 29, 2019 | invenio-communities before 1.0.0a20 allows XSS. |
| CVE-2019-1020004 | — | — | 1.2% | Jul 29, 2019 | Tridactyl before 1.16.0 allows fake key events. |
| CVE-2019-1020003 | — | — | 0.7% | Jul 29, 2019 | invenio-records before 1.2.2 allows XSS. |
| CVE-2019-1020002 | — | — | 1.5% | Jul 29, 2019 | Pterodactyl before 0.7.14 with 2FA allows credential sniffing. |
| CVE-2019-1105 | — | — | 1.8% | Jul 29, 2019 | A spoofing vulnerability exists in the way Microsoft Outlook for Android software parses specifically crafted email mess... |
| CVE-2019-1020019 | — | — | 0.9% | Jul 29, 2019 | invenio-previewer before 1.0.0a12 allows XSS. |
| CVE-2019-1020018 | HIGH | 7.3 | 1.0% | Jul 29, 2019 | Discourse before 2.3.0 and 2.4.x before 2.4.0.beta3 lacks a confirmation screen when logging in via an email link. |
| CVE-2019-1020017 | MEDIUM | 5.3 | 0.9% | Jul 29, 2019 | Discourse before 2.3.0 and 2.4.x before 2.4.0.beta3 lacks a confirmation screen when logging in via a user-api OTP. |
| CVE-2019-1020016 | — | — | 0.8% | Jul 29, 2019 | ASH-AIO before 2.0.0.3 allows an open redirect. |
| CVE-2019-1020015 | — | — | 1.2% | Jul 29, 2019 | graphql-engine (aka Hasura GraphQL Engine) before 1.0.0-beta.3 mishandles the audience check while verifying JWT. |
| CVE-2019-1020014 | MEDIUM | 5.5 | 0.4% | Jul 29, 2019 | docker-credential-helpers before 0.6.3 has a double free in the List functions. |
| CVE-2019-1020013 | — | — | 1.2% | Jul 29, 2019 | parse-server before 3.6.0 allows account enumeration. |
| CVE-2019-1020012 | — | — | 1.4% | Jul 29, 2019 | parse-server before 3.4.1 allows DoS after any POST to a volatile class. |
| CVE-2019-1020011 | HIGH | 7.2 | 1.3% | Jul 29, 2019 | SmokeDetector intentionally does automatic deployments of updated copies of SmokeDetector without server operator author... |
| CVE-2019-1020010 | — | — | 1.3% | Jul 29, 2019 | Misskey before 10.102.4 allows hijacking a user's token. |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now