2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-3854 | — | — | — | Jul 11, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2019-13029 | — | — | 2.5% | Jul 11, 2019 | Multiple stored Cross-site scripting (XSS) issues in the admin panel and survey system in REDCap 8 before 8.10.20 and 9 ... |
| CVE-2019-12529 | MEDIUM | 5.9 | 8.1% | Jul 11, 2019 | An issue was discovered in Squid 2.x through 2.7.STABLE9, 3.x through 3.5.28, and 4.x through 4.7. When Squid is configu... |
| CVE-2019-12527 | HIGH | 8.8 | 50.5% | Jul 11, 2019 | An issue was discovered in Squid 4.0.23 through 4.7. When checking Basic Authentication with HttpHeader::getAuth, Squid ... |
| CVE-2019-12525 | CRITICAL | 9.8 | 24.4% | Jul 11, 2019 | An issue was discovered in Squid 3.3.9 through 3.5.28 and 4.x through 4.7. When Squid is configured to use Digest authen... |
| CVE-2019-11062 | CRITICAL | 9.8 | 5.7% | Jul 11, 2019 | The SUNNET WMPro v5.0 and v5.1 for eLearning system has OS Command Injection via "/teach/course/doajaxfileupload.php". T... |
| CVE-2019-10194 | MEDIUM | 5.5 | 0.3% | Jul 11, 2019 | Sensitive passwords used in deployment and configuration of oVirt Metrics, all versions. were found to be insufficiently... |
| CVE-2019-10193 | HIGH | 7.2 | 23.7% | Jul 11, 2019 | A stack-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x ... |
| CVE-2019-10192 | HIGH | 7.2 | 26.0% | Jul 11, 2019 | A heap-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x b... |
| CVE-2019-10135 | HIGH | 7.2 | 1.9% | Jul 11, 2019 | A flaw was found in the yaml.load() function in the osbs-client versions since 0.46 before 0.56.1. Insecure use of the y... |
| CVE-2019-13564 | MEDIUM | 6.1 | 1.6% | Jul 11, 2019 | XSS exists in Ping Identity Agentless Integration Kit before 1.5. |
| CVE-2019-11268 | MEDIUM | 4.3 | 1.0% | Jul 11, 2019 | Cloud Foundry UAA version prior to 73.3.0, contain endpoints that contains improper escaping. An authenticated malicious... |
| CVE-2019-10651 | — | — | 4.3% | Jul 11, 2019 | An issue was discovered in the Core Server in Ivanti Endpoint Manager (EPM) 2017.3 before SU7 and 2018.x before 2018.3 S... |
| CVE-2019-13563 | HIGH | 8.8 | 1.0% | Jul 11, 2019 | D-Link DIR-655 C devices before 3.02B05 BETA03 allow CSRF for the entire management console. |
| CVE-2019-13562 | — | — | 1.8% | Jul 11, 2019 | D-Link DIR-655 C devices before 3.02B05 BETA03 allow XSS, as demonstrated by the /www/ping_response.cgi ping_ipaddr para... |
| CVE-2019-13561 | — | — | 8.4% | Jul 11, 2019 | D-Link DIR-655 C devices before 3.02B05 BETA03 allow remote attackers to execute arbitrary commands via shell metacharac... |
| CVE-2019-13560 | CRITICAL | 9.8 | 3.6% | Jul 11, 2019 | D-Link DIR-655 C devices before 3.02B05 BETA03 allow remote attackers to force a blank password via the apply_sec.cgi se... |
| CVE-2019-13507 | — | — | 2.0% | Jul 11, 2019 | hidea.com AZ Admin 1.0 has news_det.php?cod= SQL Injection. |
| CVE-2019-13506 | — | — | 1.3% | Jul 11, 2019 | @nuxt/devalue before 1.2.3, as used in Nuxt.js before 2.6.2, mishandles object keys, leading to XSS. |
| CVE-2019-12597 | MEDIUM | 6.1 | 2.2% | Jul 11, 2019 | An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via ResourcesAttachments.jsp with the parameter... |
| CVE-2019-12596 | MEDIUM | 6.1 | 2.2% | Jul 11, 2019 | An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via SoftwareListView.do with the parameter swTy... |
| CVE-2019-12595 | MEDIUM | 6.1 | 2.2% | Jul 11, 2019 | An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via the RCSettings.do rdsName parameter. |
| CVE-2019-12540 | — | — | 2.3% | Jul 11, 2019 | An issue was discovered in Zoho ManageEngine ServiceDesk Plus 10.5. There is XSS via the WorkOrder.do search field. |
| CVE-2019-12539 | MEDIUM | 6.1 | 2.5% | Jul 11, 2019 | An issue was discovered in the Purchase component of Zoho ManageEngine ServiceDesk Plus. There is XSS via the SearchN.do... |
| CVE-2019-12537 | MEDIUM | 6.1 | 2.2% | Jul 11, 2019 | An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via the SearchN.do search field. |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now