2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-1930 | MEDIUM | 6.1 | 1.1% | Jul 6, 2019 | Multiple vulnerabilities in the RSS dashboard in the web-based management interface of Cisco Firepower Management Center... |
| CVE-2019-1922 | MEDIUM | 5.3 | 1.3% | Jul 6, 2019 | A vulnerability in Cisco SIP IP Phone Software for Cisco IP Phone 7800 Series and 8800 Series could allow an unauthentic... |
| CVE-2019-1921 | MEDIUM | 5.8 | 1.4% | Jul 6, 2019 | A vulnerability in the attachment scanning of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allo... |
| CVE-2019-1911 | MEDIUM | 5.3 | 0.3% | Jul 6, 2019 | A vulnerability in the CLI of Cisco Unified Communications Domain Manager (Cisco Unified CDM) Software could allow an au... |
| CVE-2019-1909 | MEDIUM | 6.8 | 1.5% | Jul 6, 2019 | A vulnerability in the implementation of Border Gateway Protocol (BGP) functionality in Cisco IOS XR Software could allo... |
| CVE-2019-1894 | HIGH | 7.2 | 3.5% | Jul 6, 2019 | A vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker wi... |
| CVE-2019-1893 | HIGH | 7.8 | 0.6% | Jul 6, 2019 | A vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to ... |
| CVE-2019-1892 | HIGH | 7.5 | 1.8% | Jul 6, 2019 | A vulnerability in the Secure Sockets Layer (SSL) input packet processor of Cisco Small Business 200, 300, and 500 Serie... |
| CVE-2019-1891 | HIGH | 7.5 | 1.8% | Jul 6, 2019 | A vulnerability in the web interface of Cisco Small Business 200, 300, and 500 Series Managed Switches could allow an un... |
| CVE-2019-1887 | HIGH | 8.6 | 1.8% | Jul 6, 2019 | A vulnerability in the Session Initiation Protocol (SIP) protocol implementation of Cisco Unified Communications Manager... |
| CVE-2019-10639 | — | — | 3.3% | Jul 5, 2019 | The Linux kernel 4.x (starting from 4.1) and 5.x before 5.0.8 allows Information Exposure (partial kernel address disclo... |
| CVE-2019-10638 | — | — | 2.6% | Jul 5, 2019 | In the Linux kernel before 5.1.7, a device can be tracked by an attacker using the IP ID values the kernel produces for ... |
| CVE-2019-13358 | HIGH | 7.5 | 23.8% | Jul 5, 2019 | lib/DocumentToText.php in OpenCats before 0.9.4-3 has XXE that allows remote users to read files on the underlying opera... |
| CVE-2019-13352 | — | — | 2.9% | Jul 5, 2019 | WolfVision Cynap before 1.30j uses a static, hard-coded cryptographic secret for generating support PINs for the 'forgot... |
| CVE-2019-13351 | — | — | 1.7% | Jul 5, 2019 | posix/JackSocket.cpp in libjack in JACK2 1.9.1 through 1.9.12 (as distributed with alsa-plugins 1.1.7 and later) has a "... |
| CVE-2019-12971 | — | — | 2.2% | Jul 5, 2019 | BKS EBK Ethernet-Buskoppler Pro before 3.01 allows Unrestricted Upload of a File with a Dangerous Type. |
| CVE-2019-13345 | — | — | 74.5% | Jul 5, 2019 | The cachemgr.cgi web module of Squid through 4.7 has XSS via the user_name or auth parameter. |
| CVE-2019-13344 | — | — | 45.1% | Jul 5, 2019 | An authentication bypass vulnerability in the CRUDLab WP Like Button plugin through 1.6.0 for WordPress allows unauthent... |
| CVE-2019-13341 | — | — | 0.6% | Jul 5, 2019 | In MiniCMS V1.10, stored XSS was found in mc-admin/conf.php (comment box), which can be used to get a user's cookie. |
| CVE-2019-13340 | — | — | 0.6% | Jul 5, 2019 | In MiniCMS V1.10, stored XSS was found in mc-admin/post-edit.php via the content box. An attacker can use it to get a us... |
| CVE-2019-13339 | — | — | 0.6% | Jul 5, 2019 | In MiniCMS V1.10, stored XSS was found in mc-admin/page-edit.php (content box), which can be used to get a user's cookie... |
| CVE-2019-5984 | HIGH | 8.8 | 1.0% | Jul 5, 2019 | Cross-site request forgery (CSRF) vulnerability in Custom CSS Pro 1.0.3 and earlier allows remote attackers to hijack th... |
| CVE-2019-5983 | HIGH | 8.8 | 1.0% | Jul 5, 2019 | Cross-site request forgery (CSRF) vulnerability in HTML5 Maps 1.6.5.6 and earlier allows remote attackers to hijack the ... |
| CVE-2019-5982 | — | — | 0.4% | Jul 5, 2019 | Improper download file verification vulnerability in VAIO Update 7.3.0.03150 and earlier allows remote attackers to cond... |
| CVE-2019-5981 | — | — | 0.9% | Jul 5, 2019 | Improper authorization vulnerability in VAIO Update 7.3.0.03150 and earlier allows an attackers to execute arbitrary exe... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now