2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-12472An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 1.18.0 through 1.32.1. It is possible to bypa...
CVE-2019-12471Wikimedia MediaWiki 1.30.0 through 1.32.1 has XSS. Loading user JavaScript from a non-existent account allows anyone to ...
CVE-2019-12466Wikimedia MediaWiki through 1.32.1 allows CSRF.
CVE-2019-12468An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 1.27.0 through 1.32.1. Directly POSTing to Sp...
CVE-2019-12467MediaWiki through 1.32.1 has Incorrect Access Control (issue 1 of 3). A spammer can use Special:ChangeEmail to send out ...
CVE-2019-13396FlightPath 4.x and 5.0-x allows directory traversal and Local File Inclusion through the form_include parameter in an in...
CVE-2019-13240An issue was discovered in GLPI before 9.4.1. After a successful password reset by a user, it is possible to change that...
CVE-2019-13225MEDIUM6.5A NULL Pointer Dereference in match_at() in regexec.c in Oniguruma 6.9.2 allows attackers to potentially cause denial of...
CVE-2019-13224CRITICAL9.8A use-after-free in onig_new_deluxe() in regext.c in Oniguruma 6.9.2 allows attackers to potentially cause information d...
CVE-2019-13071HIGH8.8CSRF in the Agent/Center component of CyberPower PowerPanel Business Edition 3.4.0 allows an attacker to submit POST req...
CVE-2019-12724MEDIUM6.1An issue was discovered in the Teclib News plugin through 1.5.2 for GLPI. It allows a stored XSS attack via the $_POST['...
CVE-2019-10653An issue was discovered in Hsycms V1.1. There is a SQL injection vulnerability via a /news/*.html page.
CVE-2019-12723An issue was discovered in the Teclib Fields plugin through 1.9.2 for GLPI. it allows SQL Injection via container_id and...
CVE-2019-10122eQ-3 HomeMatic CCU2 devices before 2.41.9 and CCU3 devices before 3.43.16 have buffer overflows in the ReGa ise GmbH HTT...
CVE-2019-10121eQ-3 HomeMatic CCU2 devices before 2.41.8 and CCU3 devices before 3.43.15 use session IDs for authentication but lack au...
CVE-2019-10120On eQ-3 HomeMatic CCU2 devices before 2.41.8 and CCU3 devices before 3.43.16, automatic login configuration (aka setAuto...
CVE-2019-10119eQ-3 HomeMatic CCU2 devices before 2.41.8 and CCU3 devices before 3.43.16 use session IDs for authentication but lack au...
CVE-2019-13478CRITICAL9.8The Yoast SEO plugin before 11.6-RC5 for WordPress does not properly restrict unfiltered HTML in term descriptions.
CVE-2019-13475In MobaXterm 11.1, the mobaxterm: URI handler has an argument injection vulnerability that allows remote attackers to ex...
CVE-2019-13472PHPWind 9.1.0 has XSS vulnerabilities in the c and m parameters of the index.php file.
CVE-2019-9150Mailvelope prior to 3.3.0 does not require user interaction to import public keys shown on web page. This functionality ...
CVE-2019-9149MEDIUM6.5Mailvelope prior to 3.3.0 allows private key operations without user interaction via its client-API. By modifying an URL...
CVE-2019-9148MEDIUM4.3Mailvelope prior to 3.3.0 accepts or operates with invalid PGP public keys: Mailvelope allows importing keys that contai...
CVE-2019-9147Mailvelope prior to 3.1.0 is vulnerable to a clickjacking attack against the settings page. As the settings page is inte...
CVE-2019-13470MatrixSSL before 4.2.1 has an out-of-bounds read during ASN.1 handling.

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now