2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-12346In the miniOrange SAML SP Single Sign On plugin before 4.8.73 for WordPress, the SAML Login Endpoint is vulnerable to XS...
CVE-2019-7231MEDIUM5.7The ABB IDAL FTP server is vulnerable to a buffer overflow when a long string is sent by an authenticated attacker. This...
CVE-2019-9958CSRF within the admin panel in Quadbase EspressReport ES (ERES) v7.0 update 7 allows remote attackers to escalate privil...
CVE-2019-9957Stored XSS within Quadbase EspressReport ES (ERES) v7.0 update 7 allows remote attackers to execute malicious JavaScript...
CVE-2019-12880BCN Quark Quarking Password Manager 3.1.84 suffers from a clickjacking vulnerability caused by allowing * within web_acc...
CVE-2019-10271MEDIUM4.3An issue was discovered in the Ultimate Member plugin 2.39 for WordPress. It allows unauthorized profile and cover pictu...
CVE-2019-9085Hoteldruid before v2.3.1 allows remote authenticated users to cause a denial of service (invoice-creation outage) via th...
CVE-2019-7229HIGH8.3The ABB CP635 HMI uses two different transmission methods to upgrade its firmware and its software components: "Utilizat...
CVE-2019-7232HIGH8.8The ABB IDAL HTTP server is vulnerable to a buffer overflow when a long Host header is sent in a web request. The Host h...
CVE-2019-7230HIGH8.8The ABB IDAL FTP server mishandles format strings in a username during the authentication process. Attempting to authent...
CVE-2019-12940LiveZilla Server before 8.0.1.1 is vulnerable to Denial Of Service (memory consumption) in knowledgebase.php via a large...
CVE-2019-12939LiveZilla Server before 8.0.1.1 is vulnerable to SQL Injection in server.php via the p_ext_rse parameter.
CVE-2019-12870An issue was discovered in PHOENIX CONTACT PC Worx through 1.86, PC Worx Express through 1.86, and Config+ through 1.86....
CVE-2019-12869An issue was discovered in PHOENIX CONTACT PC Worx through 1.86, PC Worx Express through 1.86, and Config+ through 1.86....
CVE-2019-12384MEDIUM5.9FasterXML jackson-databind 2.x before 2.9.9.1 might allow attackers to have a variety of impacts by leveraging failure t...
CVE-2019-12323The HC.Server service in Hosting Controller HC10 10.14 allows an Invalid Pointer Write DoS.
CVE-2019-12292Citrix AppDNA before 7 1906.1.0.472 has Incorrect Access Control.
CVE-2019-11648An information leakage exists in Micro Focus NetIQ Self Service Password Reset Software all versions prior to version 4....
CVE-2019-11647A potential XSS exists in Self Service Password Reset, in Micro Focus NetIQ Software all versions prior to version 4.4. ...
CVE-2019-12871An issue was discovered in PHOENIX CONTACT PC Worx through 1.86, PC Worx Express through 1.86, and Config+ through 1.86....
CVE-2019-12938The Roundcube component of Analogic Poste.io 2.1.6 uses .htaccess to protect the logs/ folder, which is effective with t...
CVE-2019-12929The QMP guest_exec command in QEMU 4.0.0 and earlier is prone to OS command injection, which allows the attacker to achi...
CVE-2019-12928The QMP migrate command in QEMU version 4.0.0 and earlier is vulnerable to OS command injection, which allows the remote...
CVE-2019-12937apps/gsudo.c in gsudo in ToaruOS through 1.10.9 has a buffer overflow allowing local privilege escalation to the root us...
CVE-2019-12936HIGH7.1BlueStacks App Player 2, 3, and 4 before 4.90 allows DNS Rebinding for attacks on exposed IPC functions.

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now