2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-12472 | — | — | 1.4% | Jul 10, 2019 | An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 1.18.0 through 1.32.1. It is possible to bypa... |
| CVE-2019-12471 | — | — | 1.3% | Jul 10, 2019 | Wikimedia MediaWiki 1.30.0 through 1.32.1 has XSS. Loading user JavaScript from a non-existent account allows anyone to ... |
| CVE-2019-12466 | — | — | 0.8% | Jul 10, 2019 | Wikimedia MediaWiki through 1.32.1 allows CSRF. |
| CVE-2019-12468 | — | — | 3.4% | Jul 10, 2019 | An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 1.27.0 through 1.32.1. Directly POSTing to Sp... |
| CVE-2019-12467 | — | — | 1.3% | Jul 10, 2019 | MediaWiki through 1.32.1 has Incorrect Access Control (issue 1 of 3). A spammer can use Special:ChangeEmail to send out ... |
| CVE-2019-13396 | — | — | 62.6% | Jul 10, 2019 | FlightPath 4.x and 5.0-x allows directory traversal and Local File Inclusion through the form_include parameter in an in... |
| CVE-2019-13240 | — | — | 1.7% | Jul 10, 2019 | An issue was discovered in GLPI before 9.4.1. After a successful password reset by a user, it is possible to change that... |
| CVE-2019-13225 | MEDIUM | 6.5 | 2.1% | Jul 10, 2019 | A NULL Pointer Dereference in match_at() in regexec.c in Oniguruma 6.9.2 allows attackers to potentially cause denial of... |
| CVE-2019-13224 | CRITICAL | 9.8 | 4.0% | Jul 10, 2019 | A use-after-free in onig_new_deluxe() in regext.c in Oniguruma 6.9.2 allows attackers to potentially cause information d... |
| CVE-2019-13071 | HIGH | 8.8 | 0.7% | Jul 10, 2019 | CSRF in the Agent/Center component of CyberPower PowerPanel Business Edition 3.4.0 allows an attacker to submit POST req... |
| CVE-2019-12724 | MEDIUM | 6.1 | 1.2% | Jul 10, 2019 | An issue was discovered in the Teclib News plugin through 1.5.2 for GLPI. It allows a stored XSS attack via the $_POST['... |
| CVE-2019-10653 | — | — | 1.5% | Jul 10, 2019 | An issue was discovered in Hsycms V1.1. There is a SQL injection vulnerability via a /news/*.html page. |
| CVE-2019-12723 | — | — | 2.0% | Jul 10, 2019 | An issue was discovered in the Teclib Fields plugin through 1.9.2 for GLPI. it allows SQL Injection via container_id and... |
| CVE-2019-10122 | — | — | 4.1% | Jul 10, 2019 | eQ-3 HomeMatic CCU2 devices before 2.41.9 and CCU3 devices before 3.43.16 have buffer overflows in the ReGa ise GmbH HTT... |
| CVE-2019-10121 | — | — | 4.6% | Jul 10, 2019 | eQ-3 HomeMatic CCU2 devices before 2.41.8 and CCU3 devices before 3.43.15 use session IDs for authentication but lack au... |
| CVE-2019-10120 | — | — | 1.3% | Jul 10, 2019 | On eQ-3 HomeMatic CCU2 devices before 2.41.8 and CCU3 devices before 3.43.16, automatic login configuration (aka setAuto... |
| CVE-2019-10119 | — | — | 2.0% | Jul 10, 2019 | eQ-3 HomeMatic CCU2 devices before 2.41.8 and CCU3 devices before 3.43.16 use session IDs for authentication but lack au... |
| CVE-2019-13478 | CRITICAL | 9.8 | 3.3% | Jul 9, 2019 | The Yoast SEO plugin before 11.6-RC5 for WordPress does not properly restrict unfiltered HTML in term descriptions. |
| CVE-2019-13475 | — | — | 4.1% | Jul 9, 2019 | In MobaXterm 11.1, the mobaxterm: URI handler has an argument injection vulnerability that allows remote attackers to ex... |
| CVE-2019-13472 | — | — | 0.8% | Jul 9, 2019 | PHPWind 9.1.0 has XSS vulnerabilities in the c and m parameters of the index.php file. |
| CVE-2019-9150 | — | — | 1.4% | Jul 9, 2019 | Mailvelope prior to 3.3.0 does not require user interaction to import public keys shown on web page. This functionality ... |
| CVE-2019-9149 | MEDIUM | 6.5 | 0.9% | Jul 9, 2019 | Mailvelope prior to 3.3.0 allows private key operations without user interaction via its client-API. By modifying an URL... |
| CVE-2019-9148 | MEDIUM | 4.3 | 1.4% | Jul 9, 2019 | Mailvelope prior to 3.3.0 accepts or operates with invalid PGP public keys: Mailvelope allows importing keys that contai... |
| CVE-2019-9147 | — | — | 1.4% | Jul 9, 2019 | Mailvelope prior to 3.1.0 is vulnerable to a clickjacking attack against the settings page. As the settings page is inte... |
| CVE-2019-13470 | — | — | 1.6% | Jul 9, 2019 | MatrixSSL before 4.2.1 has an out-of-bounds read during ASN.1 handling. |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now