2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-10973 | — | — | 2.4% | Jul 8, 2019 | Quest KACE, all versions prior to version 8.0.x, 8.1.x, and 9.0.x, allows unintentional access to the appliance leveragi... |
| CVE-2019-13414 | MEDIUM | 6.1 | 1.1% | Jul 8, 2019 | The Rencontre plugin before 3.1.3 for WordPress allows XSS via inc/rencontre_widget.php. |
| CVE-2019-13413 | CRITICAL | 9.8 | 2.2% | Jul 8, 2019 | The Rencontre plugin before 3.1.3 for WordPress allows SQL Injection via inc/rencontre_widget.php. |
| CVE-2019-13354 | — | — | 3.3% | Jul 8, 2019 | The strong_password gem 0.0.7 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a... |
| CVE-2019-12174 | — | — | 0.4% | Jul 8, 2019 | hide.me before 2.4.4 on macOS suffers from a privilege escalation vulnerability in the connectWithExecutablePath:configF... |
| CVE-2019-12171 | — | — | 0.9% | Jul 8, 2019 | Dropbox.exe (and QtWebEngineProcess.exe in the Web Helper) in the Dropbox desktop application 71.4.108.0 store cleartext... |
| CVE-2019-13404 | — | — | 1.3% | Jul 8, 2019 | The MSI installer for Python through 2.7.16 on Windows defaults to the C:\Python27 directory, which makes it easier for ... |
| CVE-2019-13402 | — | — | 1.5% | Jul 8, 2019 | /usr/sbin/default.sh and /usr/apache/htdocs/cgi-bin/admin/hardfactorydefault.cgi on Dynacolor FCM-MB40 v1.2.0.0 devices ... |
| CVE-2019-13401 | — | — | 0.6% | Jul 8, 2019 | Dynacolor FCM-MB40 v1.2.0.0 devices have CSRF in all scripts under cgi-bin/. |
| CVE-2019-13400 | — | — | 1.6% | Jul 8, 2019 | Dynacolor FCM-MB40 v1.2.0.0 use /etc/appWeb/appweb.pass to store administrative web-interface credentials in cleartext. ... |
| CVE-2019-13399 | — | — | 1.1% | Jul 8, 2019 | Dynacolor FCM-MB40 v1.2.0.0 devices have a hard-coded SSL/TLS key that is used during an administrator's SSL conversatio... |
| CVE-2019-13398 | — | — | 4.1% | Jul 8, 2019 | Dynacolor FCM-MB40 v1.2.0.0 devices allow remote attackers to execute arbitrary commands via a crafted parameter to a CG... |
| CVE-2019-13391 | — | — | 2.8% | Jul 7, 2019 | In ImageMagick 7.0.8-50 Q16, ComplexImages in MagickCore/fourier.c has a heap-based buffer over-read because of incorrec... |
| CVE-2019-13390 | — | — | 1.7% | Jul 7, 2019 | In FFmpeg 4.1.3, there is a division by zero at adx_write_trailer in libavformat/rawenc.c. |
| CVE-2019-13379 | — | — | 3.0% | Jul 7, 2019 | On AVTECH Room Alert 3E devices before 2.2.5, an attacker with access to the device's web interface may escalate privile... |
| CVE-2019-13183 | — | — | 0.8% | Jul 7, 2019 | Flarum before 0.1.0-beta.9 allows CSRF against all POST endpoints, as demonstrated by changing admin settings. |
| CVE-2019-13375 | — | — | 28.2% | Jul 6, 2019 | A SQL Injection was discovered in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 in PayAction.class.php wi... |
| CVE-2019-13374 | — | — | 2.4% | Jul 6, 2019 | A cross-site scripting (XSS) vulnerability in resource view in PayAction.class.php in D-Link Central WiFi Manager CWM(10... |
| CVE-2019-13373 | — | — | 68.0% | Jul 6, 2019 | An issue was discovered in the D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6. Input does not get validate... |
| CVE-2019-13372 | CRITICAL | 9.8 | 80.7% | Jul 6, 2019 | /web/Lib/Action/IndexAction.class.php in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 allows remote atta... |
| CVE-2019-13370 | HIGH | 8.8 | 0.6% | Jul 6, 2019 | index.php/admin/permissions in Ignited CMS through 2017-02-19 allows CSRF to add an administrator. |
| CVE-2019-13362 | — | — | 1.0% | Jul 6, 2019 | Codedoc v3.2 has a stack-based buffer overflow in add_variable in codedoc.c, related to codedoc_strlcpy. |
| CVE-2019-1933 | MEDIUM | 5.8 | 1.2% | Jul 6, 2019 | A vulnerability in the email message scanning of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could a... |
| CVE-2019-1932 | MEDIUM | 6.7 | 0.3% | Jul 6, 2019 | A vulnerability in Cisco Advanced Malware Protection (AMP) for Endpoints for Windows could allow an authenticated, local... |
| CVE-2019-1931 | MEDIUM | 6.1 | 1.1% | Jul 6, 2019 | Multiple vulnerabilities in the RSS dashboard in the web-based management interface of Cisco Firepower Management Center... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now