2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-1930MEDIUM6.1Multiple vulnerabilities in the RSS dashboard in the web-based management interface of Cisco Firepower Management Center...
CVE-2019-1922MEDIUM5.3A vulnerability in Cisco SIP IP Phone Software for Cisco IP Phone 7800 Series and 8800 Series could allow an unauthentic...
CVE-2019-1921MEDIUM5.8A vulnerability in the attachment scanning of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allo...
CVE-2019-1911MEDIUM5.3A vulnerability in the CLI of Cisco Unified Communications Domain Manager (Cisco Unified CDM) Software could allow an au...
CVE-2019-1909MEDIUM6.8A vulnerability in the implementation of Border Gateway Protocol (BGP) functionality in Cisco IOS XR Software could allo...
CVE-2019-1894HIGH7.2A vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker wi...
CVE-2019-1893HIGH7.8A vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to ...
CVE-2019-1892HIGH7.5A vulnerability in the Secure Sockets Layer (SSL) input packet processor of Cisco Small Business 200, 300, and 500 Serie...
CVE-2019-1891HIGH7.5A vulnerability in the web interface of Cisco Small Business 200, 300, and 500 Series Managed Switches could allow an un...
CVE-2019-1887HIGH8.6A vulnerability in the Session Initiation Protocol (SIP) protocol implementation of Cisco Unified Communications Manager...
CVE-2019-10639The Linux kernel 4.x (starting from 4.1) and 5.x before 5.0.8 allows Information Exposure (partial kernel address disclo...
CVE-2019-10638In the Linux kernel before 5.1.7, a device can be tracked by an attacker using the IP ID values the kernel produces for ...
CVE-2019-13358HIGH7.5lib/DocumentToText.php in OpenCats before 0.9.4-3 has XXE that allows remote users to read files on the underlying opera...
CVE-2019-13352WolfVision Cynap before 1.30j uses a static, hard-coded cryptographic secret for generating support PINs for the 'forgot...
CVE-2019-13351posix/JackSocket.cpp in libjack in JACK2 1.9.1 through 1.9.12 (as distributed with alsa-plugins 1.1.7 and later) has a "...
CVE-2019-12971BKS EBK Ethernet-Buskoppler Pro before 3.01 allows Unrestricted Upload of a File with a Dangerous Type.
CVE-2019-13345The cachemgr.cgi web module of Squid through 4.7 has XSS via the user_name or auth parameter.
CVE-2019-13344An authentication bypass vulnerability in the CRUDLab WP Like Button plugin through 1.6.0 for WordPress allows unauthent...
CVE-2019-13341In MiniCMS V1.10, stored XSS was found in mc-admin/conf.php (comment box), which can be used to get a user's cookie.
CVE-2019-13340In MiniCMS V1.10, stored XSS was found in mc-admin/post-edit.php via the content box. An attacker can use it to get a us...
CVE-2019-13339In MiniCMS V1.10, stored XSS was found in mc-admin/page-edit.php (content box), which can be used to get a user's cookie...
CVE-2019-5984HIGH8.8Cross-site request forgery (CSRF) vulnerability in Custom CSS Pro 1.0.3 and earlier allows remote attackers to hijack th...
CVE-2019-5983HIGH8.8Cross-site request forgery (CSRF) vulnerability in HTML5 Maps 1.6.5.6 and earlier allows remote attackers to hijack the ...
CVE-2019-5982Improper download file verification vulnerability in VAIO Update 7.3.0.03150 and earlier allows remote attackers to cond...
CVE-2019-5981Improper authorization vulnerability in VAIO Update 7.3.0.03150 and earlier allows an attackers to execute arbitrary exe...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now