2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-13950 | — | — | 0.7% | Jul 18, 2019 | index.php?c=admin&a=index in SyGuestBook A5 Version 1.2 has stored XSS via a reply to a comment. |
| CVE-2019-13949 | — | — | 0.7% | Jul 18, 2019 | SyGuestBook A5 Version 1.2 has no CSRF protection mechanism, as demonstrated by CSRF for an index.php?c=Administrator&a=... |
| CVE-2019-13948 | — | — | 0.7% | Jul 18, 2019 | SyGuestBook A5 Version 1.2 allows stored XSS because the isValidData function in include/functions.php does not properly... |
| CVE-2019-13509 | — | — | 3.7% | Jul 18, 2019 | In Docker CE and EE before 18.09.8 (as well as Docker EE before 17.06.2-ee-23 and 18.x before 18.03.1-ee-10), Docker Eng... |
| CVE-2019-1010104 | — | — | 1.8% | Jul 18, 2019 | TechyTalk Quick Chat WordPress Plugin All up to the latest is affected by: SQL Injection. The impact is: Access to the d... |
| CVE-2019-9230 | — | — | 1.0% | Jul 18, 2019 | An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versio... |
| CVE-2019-13915 | — | — | 2.6% | Jul 18, 2019 | b3log Wide before 1.6.0 allows three types of attacks to access arbitrary files. First, the attacker can write code in t... |
| CVE-2019-13607 | — | — | 0.8% | Jul 18, 2019 | The Opera Mini application through 16.0.14 for iOS has a UXSS vulnerability that can be triggered by performing navigati... |
| CVE-2019-13575 | CRITICAL | 9.8 | 2.6% | Jul 18, 2019 | A SQL injection vulnerability exists in WPEverest Everest Forms plugin for WordPress through 1.4.9. Successful exploitat... |
| CVE-2019-1010073 | — | — | — | Jul 18, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-10238. Reason: This issue was MERGED into CVE-20... |
| CVE-2019-1010069 | MEDIUM | 5.5 | 0.9% | Jul 18, 2019 | moinejf abcm2ps 8.13.20 is affected by: Incorrect Access Control. The impact is: Allows attackers to cause a denial of s... |
| CVE-2019-1010066 | — | — | 1.3% | Jul 18, 2019 | Lawrence Livermore National Laboratory msr-safe v1.1.0 is affected by: Incorrect Access Control. The impact is: An attac... |
| CVE-2019-1010096 | — | — | 0.7% | Jul 18, 2019 | DomainMOD v4.10.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: There is a CSRF vulnerability that c... |
| CVE-2019-1010095 | — | — | 0.7% | Jul 18, 2019 | DomainMOD v4.10.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: There is a CSRF vulnerability that c... |
| CVE-2019-1010094 | — | — | 0.7% | Jul 18, 2019 | domainmod v4.10.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: There is a CSRF vulnerability that c... |
| CVE-2019-1010054 | — | — | 2.2% | Jul 18, 2019 | Dolibarr 7.0.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: allow malitious html to change user pas... |
| CVE-2019-13647 | — | — | 0.8% | Jul 18, 2019 | Firefly III before 4.7.17.3 is vulnerable to stored XSS due to lack of filtration of user-supplied data in image file co... |
| CVE-2019-13646 | — | — | 0.8% | Jul 18, 2019 | Firefly III before 4.7.17.3 is vulnerable to reflected XSS due to lack of filtration of user-supplied data in a search q... |
| CVE-2019-13645 | — | — | 0.8% | Jul 18, 2019 | Firefly III before 4.7.17.3 is vulnerable to stored XSS due to lack of filtration of user-supplied data in image file na... |
| CVE-2019-13644 | MEDIUM | 5.4 | 0.8% | Jul 18, 2019 | Firefly III before 4.7.17.1 is vulnerable to stored XSS due to lack of filtration of user-supplied data in a budget name... |
| CVE-2019-13643 | — | — | 1.1% | Jul 18, 2019 | Stored XSS in EspoCRM before 5.6.4 allows remote attackers to execute malicious JavaScript and inject arbitrary source c... |
| CVE-2019-5222 | — | — | 0.6% | Jul 17, 2019 | There is an information disclosure vulnerability on Secure Input of certain Huawei smartphones in Versions earlier than ... |
| CVE-2019-13640 | — | — | 7.9% | Jul 17, 2019 | In qBittorrent before 4.1.7, the function Application::runExternalProgram() located in app/application.cpp allows comman... |
| CVE-2019-8932 | — | — | 1.2% | Jul 17, 2019 | Redbrick Shift through 3.4.3 allows an attacker to extract authentication tokens of services (such as Gmail, Outlook, et... |
| CVE-2019-8931 | — | — | 1.1% | Jul 17, 2019 | Redbrick Shift through 3.4.3 allows an attacker to extract emails of services (such as Gmail, Outlook, etc.) used in the... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now