2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-12935 | HIGH | 7.4 | 2.7% | Jun 23, 2019 | Shopware before 5.5.8 has XSS via the Query String to the backend/Login or backend/Login/load/ URI. |
| CVE-2019-12933 | — | — | — | Jun 22, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-11877. Reason: This candidate is a duplicate of ... |
| CVE-2019-10028 | — | — | 1.1% | Jun 21, 2019 | Denial of Service (DOS) in Dial Reference Source Code Used before June 18th, 2019. |
| CVE-2019-11392 | — | — | 1.6% | Jun 21, 2019 | BlogEngine.NET 3.3.7 and earlier allows XXE via an apml file to syndication.axd. |
| CVE-2019-10720 | HIGH | 8.8 | 7.1% | Jun 21, 2019 | BlogEngine.NET 3.3.7.0 and earlier allows Directory Traversal and Remote Code Execution via the theme cookie to the File... |
| CVE-2019-10719 | — | — | 7.6% | Jun 21, 2019 | BlogEngine.NET 3.3.7.0 and earlier allows Directory Traversal and Remote Code Execution because file creation is mishand... |
| CVE-2019-10718 | — | — | 2.7% | Jun 21, 2019 | BlogEngine.NET 3.3.7.0 and earlier allows XML External Entity Blind Injection, related to pingback.axd and BlogEngine.Co... |
| CVE-2019-12572 | — | — | 0.9% | Jun 21, 2019 | A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client 1.0.2 (build 02363) for Windows could... |
| CVE-2019-11011 | — | — | 2.6% | Jun 21, 2019 | Akamai CloudTest before 58.30 allows remote code execution. |
| CVE-2019-10270 | HIGH | 8.8 | 1.2% | Jun 21, 2019 | An arbitrary password reset issue was discovered in the Ultimate Member plugin 2.39 for WordPress. It is possible (due t... |
| CVE-2019-10072 | — | — | 73.0% | Jun 21, 2019 | The fix for CVE-2019-0199 was incomplete and did not address HTTP/2 connection window exhaustion on write in Apache Tomc... |
| CVE-2019-12836 | — | — | 1.0% | Jun 21, 2019 | The Bobronix JEditor editor before 3.0.6 for Jira allows an attacker to add a URL/Link (to an existing issue) that can c... |
| CVE-2019-1904 | HIGH | 8.8 | 1.0% | Jun 21, 2019 | A vulnerability in the web-based UI (web UI) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to... |
| CVE-2019-3735 | HIGH | 7.8 | 0.3% | Jun 20, 2019 | Dell SupportAssist for Business PCs version 2.0 and Dell SupportAssist for Home PCs version 2.2, 2.2.1, 2.2.2, 2.2.3, 3.... |
| CVE-2019-12920 | — | — | 2.3% | Jun 20, 2019 | On Shenzhen Cylan Clever Dog Smart Camera DOG-2W and DOG-2W-V4 devices, an attacker on the network can login remotely to... |
| CVE-2019-12919 | — | — | 0.4% | Jun 20, 2019 | On Shenzhen Cylan Clever Dog Smart Camera DOG-2W and DOG-2W-V4 devices, an attacker on the local network has unauthentic... |
| CVE-2019-8459 | — | — | 1.2% | Jun 20, 2019 | Check Point Endpoint Security Client for Windows, with the VPN blade, before version E80.83, starts a process without us... |
| CVE-2019-8458 | MEDIUM | 4.4 | 1.0% | Jun 20, 2019 | Check Point Endpoint Security Client for Windows, with Anti-Malware blade installed, before version E81.00, tries to loa... |
| CVE-2019-12745 | — | — | 2.6% | Jun 20, 2019 | out/out.UsrMgr.php in SeedDMS before 5.1.11 allows Stored Cross-Site Scripting (XSS) via the name field. |
| CVE-2019-12744 | — | — | 11.7% | Jun 20, 2019 | SeedDMS before 5.1.11 allows Remote Command Execution (RCE) because of unvalidated file upload of PHP scripts, a differe... |
| CVE-2019-12905 | MEDIUM | 6.1 | 3.6% | Jun 20, 2019 | FileRun 2019.05.21 allows XSS via the filename to the ?module=fileman§ion=do&page=up URI. This issue has been fixed ... |
| CVE-2019-6964 | — | — | 1.8% | Jun 20, 2019 | A heap-based buffer over-read in Service_SetParamStringValue in cosa_x_cisco_com_ddns_dml.c of the RDK RDKB-20181217-1 C... |
| CVE-2019-6963 | — | — | 2.4% | Jun 20, 2019 | A heap-based buffer overflow in cosa_dhcpv4_dml.c in the RDK RDKB-20181217-1 CcspPandM module may allow attackers with l... |
| CVE-2019-6962 | — | — | 1.6% | Jun 20, 2019 | A shell injection issue in cosa_wifi_apis.c in the RDK RDKB-20181217-1 CcspWifiAgent module allows attackers with login ... |
| CVE-2019-6961 | — | — | 0.9% | Jun 20, 2019 | Incorrect access control in actionHandlerUtility.php in the RDK RDKB-20181217-1 WebUI module allows a logged in user to ... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now