2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-13950index.php?c=admin&a=index in SyGuestBook A5 Version 1.2 has stored XSS via a reply to a comment.
CVE-2019-13949SyGuestBook A5 Version 1.2 has no CSRF protection mechanism, as demonstrated by CSRF for an index.php?c=Administrator&a=...
CVE-2019-13948SyGuestBook A5 Version 1.2 allows stored XSS because the isValidData function in include/functions.php does not properly...
CVE-2019-13509In Docker CE and EE before 18.09.8 (as well as Docker EE before 17.06.2-ee-23 and 18.x before 18.03.1-ee-10), Docker Eng...
CVE-2019-1010104TechyTalk Quick Chat WordPress Plugin All up to the latest is affected by: SQL Injection. The impact is: Access to the d...
CVE-2019-9230An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versio...
CVE-2019-13915b3log Wide before 1.6.0 allows three types of attacks to access arbitrary files. First, the attacker can write code in t...
CVE-2019-13607The Opera Mini application through 16.0.14 for iOS has a UXSS vulnerability that can be triggered by performing navigati...
CVE-2019-13575CRITICAL9.8A SQL injection vulnerability exists in WPEverest Everest Forms plugin for WordPress through 1.4.9. Successful exploitat...
CVE-2019-1010073Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-10238. Reason: This issue was MERGED into CVE-20...
CVE-2019-1010069MEDIUM5.5moinejf abcm2ps 8.13.20 is affected by: Incorrect Access Control. The impact is: Allows attackers to cause a denial of s...
CVE-2019-1010066Lawrence Livermore National Laboratory msr-safe v1.1.0 is affected by: Incorrect Access Control. The impact is: An attac...
CVE-2019-1010096DomainMOD v4.10.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: There is a CSRF vulnerability that c...
CVE-2019-1010095DomainMOD v4.10.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: There is a CSRF vulnerability that c...
CVE-2019-1010094domainmod v4.10.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: There is a CSRF vulnerability that c...
CVE-2019-1010054Dolibarr 7.0.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: allow malitious html to change user pas...
CVE-2019-13647Firefly III before 4.7.17.3 is vulnerable to stored XSS due to lack of filtration of user-supplied data in image file co...
CVE-2019-13646Firefly III before 4.7.17.3 is vulnerable to reflected XSS due to lack of filtration of user-supplied data in a search q...
CVE-2019-13645Firefly III before 4.7.17.3 is vulnerable to stored XSS due to lack of filtration of user-supplied data in image file na...
CVE-2019-13644MEDIUM5.4Firefly III before 4.7.17.1 is vulnerable to stored XSS due to lack of filtration of user-supplied data in a budget name...
CVE-2019-13643Stored XSS in EspoCRM before 5.6.4 allows remote attackers to execute malicious JavaScript and inject arbitrary source c...
CVE-2019-5222There is an information disclosure vulnerability on Secure Input of certain Huawei smartphones in Versions earlier than ...
CVE-2019-13640In qBittorrent before 4.1.7, the function Application::runExternalProgram() located in app/application.cpp allows comman...
CVE-2019-8932Redbrick Shift through 3.4.3 allows an attacker to extract authentication tokens of services (such as Gmail, Outlook, et...
CVE-2019-8931Redbrick Shift through 3.4.3 allows an attacker to extract emails of services (such as Gmail, Outlook, etc.) used in the...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now