2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-5980 | HIGH | 8.8 | 1.0% | Jul 5, 2019 | Cross-site request forgery (CSRF) vulnerability in Related YouTube Videos versions prior to 1.9.9 allows remote attacker... |
| CVE-2019-5979 | HIGH | 8.8 | 1.0% | Jul 5, 2019 | Cross-site request forgery (CSRF) vulnerability in Personalized WooCommerce Cart Page 2.4 and earlier allows remote atta... |
| CVE-2019-5974 | — | — | 1.0% | Jul 5, 2019 | Cross-site request forgery (CSRF) vulnerability in Contest Gallery versions prior to 10.4.5 allows remote attackers to h... |
| CVE-2019-5973 | HIGH | 8.8 | 1.1% | Jul 5, 2019 | Cross-site request forgery (CSRF) vulnerability in Online Lesson Booking 0.8.6 and earlier allows remote attackers to hi... |
| CVE-2019-5972 | MEDIUM | 6.1 | 1.6% | Jul 5, 2019 | Cross-site scripting vulnerability in Online Lesson Booking 0.8.6 and earlier allows remote attackers to inject arbitrar... |
| CVE-2019-5971 | — | — | 1.0% | Jul 5, 2019 | Cross-site request forgery (CSRF) vulnerability in Attendance Manager 0.5.6 and earlier allows remote attackers to hijac... |
| CVE-2019-5970 | MEDIUM | 6.1 | 1.6% | Jul 5, 2019 | Cross-site scripting vulnerability in Attendance Manager 0.5.6 and earlier allows remote attackers to inject arbitrary w... |
| CVE-2019-5969 | — | — | 1.1% | Jul 5, 2019 | Open redirect vulnerability in GROWI v3.4.6 and earlier allows remote attackersto redirect users to arbitrary web sites ... |
| CVE-2019-5968 | — | — | 0.7% | Jul 5, 2019 | Cross-site request forgery (CSRF) vulnerability in GROWI v3.4.6 and earlier allows remote attackers to hijack the authen... |
| CVE-2019-5967 | — | — | 1.0% | Jul 5, 2019 | Cross-site scripting vulnerability in Joruri CMS 2017 Release2 and earlier allows remote attackers to inject arbitrary w... |
| CVE-2019-5966 | — | — | 1.0% | Jul 5, 2019 | Joruri Mail 2.1.4 and earlier does not properly manage sessions, which allows remote attackers to impersonate an arbitra... |
| CVE-2019-5965 | — | — | 1.1% | Jul 5, 2019 | Open redirect vulnerability in Joruri Mail 2.1.4 and earlier allows remote attackers to redirect users to arbitrary web ... |
| CVE-2019-5964 | — | — | 0.7% | Jul 5, 2019 | iDoors Reader 2.10.17 and earlier allows an attacker on the same network segment to bypass authentication to access the ... |
| CVE-2019-5963 | HIGH | 8.8 | 1.0% | Jul 5, 2019 | Cross-site request forgery (CSRF) vulnerability in Zoho SalesIQ 1.0.8 and earlier allows remote attackers to hijack the ... |
| CVE-2019-5962 | MEDIUM | 6.1 | 1.6% | Jul 5, 2019 | Cross-site scripting vulnerability in Zoho SalesIQ 1.0.8 and earlier allows remote attackers to inject arbitrary web scr... |
| CVE-2019-5961 | — | — | 0.6% | Jul 5, 2019 | The Android App 'Tootdon for Mastodon' version 3.4.1 and earlier does not verify X.509 certificates from SSL servers, wh... |
| CVE-2019-5960 | — | — | 0.6% | Jul 5, 2019 | Cross-site request forgery (CSRF) vulnerability in WP Open Graph 1.6.1 and earlier allows remote attackers to hijack the... |
| CVE-2019-13314 | — | — | 0.6% | Jul 5, 2019 | virt-bootstrap 1.1.0 allows local users to discover a root password by listing a process, because this password may be p... |
| CVE-2019-13313 | HIGH | 7.8 | 0.4% | Jul 5, 2019 | libosinfo 1.5.0 allows local users to discover credentials by listing a process, because credentials are passed to osinf... |
| CVE-2019-13144 | CRITICAL | 9.8 | 1.8% | Jul 5, 2019 | myTinyTodo 1.3.3 through 1.4.3 allows CSV Injection. This is fixed in 1.5. |
| CVE-2019-13312 | — | — | 1.7% | Jul 5, 2019 | block_cmp() in libavcodec/zmbvenc.c in FFmpeg 4.1.3 has a heap-based buffer over-read. |
| CVE-2019-13311 | MEDIUM | 6.5 | 2.8% | Jul 5, 2019 | ImageMagick 7.0.8-50 Q16 has memory leaks at AcquireMagickMemory because of a wand/mogrify.c error. |
| CVE-2019-13310 | MEDIUM | 6.5 | 2.2% | Jul 5, 2019 | ImageMagick 7.0.8-50 Q16 has memory leaks at AcquireMagickMemory because of an error in MagickWand/mogrify.c. |
| CVE-2019-13309 | MEDIUM | 6.5 | 2.7% | Jul 5, 2019 | ImageMagick 7.0.8-50 Q16 has memory leaks at AcquireMagickMemory because of mishandling the NoSuchImage error in CLIList... |
| CVE-2019-13308 | HIGH | 8.8 | 2.7% | Jul 5, 2019 | ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow in MagickCore/fourier.c in ComplexImage. |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now