2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-7588MEDIUM6.7A vulnerability in the exacqVision Enterprise System Manager (ESM) v5.12.2 application whereby unauthorized privilege es...
CVE-2019-12872dotCMS before 5.1.6 is vulnerable to a SQL injection that can be exploited by an attacker of the role Publisher via view...
CVE-2019-7159OX App Suite 7.10.1 and earlier allows Information Exposure.
CVE-2019-6965An XSS issue was discovered in i-doit Open 1.12 via the src/tools/php/qr/qr.php url parameter.
CVE-2019-12823MEDIUM6.1Craft CMS before 3.1.31 does not properly filter XML feeds and thus allowing XSS.
CVE-2019-10998An issue was discovered on Phoenix Contact AXC F 2152 (No.2404267) before 2019.0 LTS and AXC F 2152 STARTERKIT (No.10465...
CVE-2019-12868app/Model/Server.php in MISP 2.4.109 allows remote command execution by a super administrator because the PHP file_exist...
CVE-2019-12865In radare2 through 3.5.1, cmd_mount in libr/core/cmd_mount.c has a double free for the ms command.
CVE-2019-5017MEDIUM5.3An exploitable information disclosure vulnerability exists in the KCodes NetUSB.ko kernel module that enables the ReadyS...
CVE-2019-5016CRITICAL9.1An exploitable arbitrary memory read vulnerability exists in the KCodes NetUSB.ko kernel module which enables the ReadyS...
CVE-2019-8323HIGH7.5An issue was discovered in RubyGems 2.6 and later through 3.0.2. Gem::GemcutterUtilities#with_response may output the AP...
CVE-2019-8322HIGH7.5An issue was discovered in RubyGems 2.6 and later through 3.0.2. The gem owner command outputs the contents of the API r...
CVE-2019-8321HIGH7.5An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::UserInteraction#verbose calls say without es...
CVE-2019-7158OX App Suite 7.10.0 and earlier has Incorrect Access Control.
CVE-2019-8325HIGH7.5An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::CommandManager#run calls alert_error without...
CVE-2019-8324HIGH8.8An issue was discovered in RubyGems 2.6 and later through 3.0.2. A crafted gem with a multi-line name is not handled cor...
CVE-2019-7579An issue was discovered on Linksys WRT1900ACS 1.0.3.187766 devices. An ability exists for an unauthenticated user to bro...
CVE-2019-7315Genie Access WIP3BVAF WISH IP 3MP IR Auto Focus Bullet Camera devices through 3.x are vulnerable to directory traversal ...
CVE-2019-11410app/backup/index.php in the Backup Module in FusionPBX 4.4.3 suffers from a command injection vulnerability due to a lac...
CVE-2019-11409HIGH8.8app/operator_panel/exec.php in the Operator Panel module in FusionPBX 4.4.3 suffers from a command injection vulnerabili...
CVE-2019-12801out/out.GroupMgr.php in SeedDMS 5.1.11 has Stored XSS by making a new group with a JavaScript payload as the "GROUP" Nam...
CVE-2019-12476An authentication bypass vulnerability in the password reset functionality in Zoho ManageEngine ADSelfService Plus befor...
CVE-2019-12248MEDIUM4.3An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.7, Community Edition 6.0.x through 6.0.19...
CVE-2019-11408XSS in app/operator_panel/index_inc.php in the Operator Panel module in FusionPBX 4.4.3 allows remote unauthenticated at...
CVE-2019-11407app/operator_panel/index_inc.php in the Operator Panel module in FusionPBX 4.4.3 suffers from an information disclosure ...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now