2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-13380 | — | — | 0.8% | Jul 9, 2019 | KEYNTO Team Password Manager 1.5.0 allows XSS because data saved from websites is mishandled in the online vault. |
| CVE-2019-13277 | — | — | 1.5% | Jul 9, 2019 | TRENDnet TEW-827DRU with firmware up to and including 2.04B03 allows an unauthenticated attacker to execute setup wizard... |
| CVE-2019-11512 | — | — | 1.5% | Jul 9, 2019 | Contao 4.x allows SQL Injection. Fixed in Contao 4.4.39 and Contao 4.7.5. |
| CVE-2019-13338 | — | — | 1.8% | Jul 9, 2019 | In WESEEK GROWI before 3.5.0, a remote attacker can obtain the password hash of the creator of a page by leveraging wiki... |
| CVE-2019-13337 | — | — | 1.4% | Jul 9, 2019 | In WESEEK GROWI before 3.5.0, the site-wide basic authentication can be bypassed by adding a URL parameter access_token ... |
| CVE-2019-5044 | — | — | — | Jul 9, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2019-13464 | — | — | 1.5% | Jul 9, 2019 | An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) 3.0.2. Use of X.Filename instead of X_Filename can bypa... |
| CVE-2019-13280 | — | — | 2.1% | Jul 9, 2019 | TRENDnet TEW-827DRU with firmware up to and including 2.04B03 contains a stack-based buffer overflow while returning an ... |
| CVE-2019-13070 | — | — | 0.8% | Jul 9, 2019 | A stored XSS vulnerability in the Agent/Center component of CyberPower PowerPanel Business Edition 3.4.0 allows a privil... |
| CVE-2019-11991 | — | — | 4.7% | Jul 9, 2019 | HPE has identified a vulnerability in HPE 3PAR Service Processor (SP) version 4.1 through 4.4. HPE 3PAR Service Processo... |
| CVE-2019-8920 | — | — | 0.8% | Jul 9, 2019 | iart.php in XAMPP 1.7.0 has XSS, a related issue to CVE-2008-3569. |
| CVE-2019-3950 | — | — | 1.7% | Jul 9, 2019 | Arlo Basestation firmware 1.12.0.1_27940 and prior contain a hardcoded username and password combination that allows roo... |
| CVE-2019-3949 | — | — | 1.2% | Jul 9, 2019 | Arlo Basestation firmware 1.12.0.1_27940 and prior firmware contain a networking misconfiguration that allows access to ... |
| CVE-2019-13461 | — | — | 1.7% | Jul 9, 2019 | In PrestaShop before 1.7.6.0 RC2, the id_address_delivery and id_address_invoice parameters are affected by an Insecure ... |
| CVE-2019-13146 | — | — | 1.4% | Jul 9, 2019 | The field_test gem 0.3.0 for Ruby has unvalidated input. A method call that is expected to return a value from a certain... |
| CVE-2019-13142 | — | — | 0.3% | Jul 9, 2019 | The RzSurroundVADStreamingService (RzSurroundVADStreamingService.exe) in Razer Surround 1.1.63.0 runs as the SYSTEM user... |
| CVE-2019-13454 | MEDIUM | 6.5 | 4.4% | Jul 9, 2019 | ImageMagick 7.0.1-0 to 7.0.8-54 Q16 allows Division by Zero in RemoveDuplicateLayers in MagickCore/layer.c. |
| CVE-2019-13397 | — | — | 1.1% | Jul 9, 2019 | Unauthenticated Stored XSS in osTicket 1.10.1 allows a remote attacker to gain admin privileges by injecting arbitrary w... |
| CVE-2019-11020 | HIGH | 7.5 | 1.5% | Jul 9, 2019 | Lack of authentication in file-viewing components in DDRT Dashcom Live 2019-05-09 allows anyone to remotely access all c... |
| CVE-2019-12782 | — | — | 1.1% | Jul 9, 2019 | An authorization bypass vulnerability in pinboard updates in ThoughtSpot 4.4.1 through 5.1.1 (before 5.1.2) allows a low... |
| CVE-2019-11019 | HIGH | 7.5 | 1.5% | Jul 9, 2019 | Lack of authentication in case-exporting components in DDRT Dashcom Live through 2019-05-08 allows anyone to remotely ac... |
| CVE-2019-12748 | MEDIUM | 6.1 | 0.7% | Jul 9, 2019 | TYPO3 8.3.0 through 8.7.26 and 9.0.0 through 9.5.7 allows XSS. |
| CVE-2019-12747 | HIGH | 8.8 | 1.5% | Jul 9, 2019 | TYPO3 8.x through 8.7.26 and 9.x through 9.5.7 allows Deserialization of Untrusted Data. |
| CVE-2019-11890 | — | — | 4.4% | Jul 9, 2019 | Sony Bravia Smart TV devices allow remote attackers to cause a denial of service (device hang or reboot) via a SYN flood... |
| CVE-2019-11889 | — | — | 3.5% | Jul 9, 2019 | Sony BRAVIA Smart TV devices allow remote attackers to cause a denial of service (device hang) via a crafted web page ov... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now