2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-12149 | — | — | 1.4% | Jun 11, 2019 | SQL injection vulnerability in silverstripe/restfulserver module 1.0.x before 1.0.9, 2.0.x before 2.0.4, and 2.1.x befor... |
| CVE-2019-0197 | MEDIUM | 4.2 | 8.4% | Jun 11, 2019 | A vulnerability was found in Apache HTTP Server 2.4.34 to 2.4.38. When HTTP/2 was enabled for a http: host or H2Upgrade ... |
| CVE-2019-0196 | — | — | 19.3% | Jun 11, 2019 | A vulnerability was found in Apache HTTP Server 2.4.17 to 2.4.38. Using fuzzed network input, the http/2 request handlin... |
| CVE-2019-12154 | — | — | 2.3% | Jun 11, 2019 | XXE in the XML parser library in RealObjects PDFreactor before 10.1.10722 allows attackers to supply malicious XML conte... |
| CVE-2019-12153 | — | — | 1.7% | Jun 11, 2019 | Lack of validation in the HTML parser in RealObjects PDFreactor before 10.1.10722 leads to SSRF, allowing attackers to a... |
| CVE-2019-12146 | — | — | 4.0% | Jun 11, 2019 | A Directory Traversal issue was discovered in SSHServerAPI.dll in Progress ipswitch WS_FTP Server 2018 before 8.6.1. Att... |
| CVE-2019-12145 | — | — | 4.7% | Jun 11, 2019 | A Directory Traversal issue was discovered in SSHServerAPI.dll in Progress ipswitch WS_FTP Server 2018 before 8.6.1. An ... |
| CVE-2019-12144 | — | — | 2.9% | Jun 11, 2019 | An issue was discovered in SSHServerAPI.dll in Progress ipswitch WS_FTP Server 2018 before 8.6.1. Attackers have the abi... |
| CVE-2019-12143 | — | — | 2.0% | Jun 11, 2019 | A Directory Traversal issue was discovered in SSHServerAPI.dll in Progress ipswitch WS_FTP Server 2018 before 8.6.1. An ... |
| CVE-2019-0220 | — | — | 17.9% | Jun 11, 2019 | A vulnerability was found in Apache HTTP Server 2.4.0 to 2.4.38. When the path component of a request URL contains multi... |
| CVE-2019-3413 | MEDIUM | 5.4 | 0.6% | Jun 11, 2019 | All versions up to V20.18.40.R7.B1of ZTE NetNumen DAP product have an XSS vulnerability. Due to the lack of correct vali... |
| CVE-2019-3412 | CRITICAL | 9.8 | 2.9% | Jun 11, 2019 | All versions up to BD_R218V2.4 of ZTE MF920 product are impacted by command execution vulnerability. Due to some interfa... |
| CVE-2019-3411 | HIGH | 7.5 | 1.3% | Jun 11, 2019 | All versions up to BD_R218V2.4 of ZTE MF920 product are impacted by information leak vulnerability. Due to some interfac... |
| CVE-2019-3410 | MEDIUM | 4.6 | 0.5% | Jun 11, 2019 | All versions up to UKBB_WF820+_1.0.0B06 of ZTE WF820+ LTE Outdoor CPE product are impacted by Cross-Site Request Forgery... |
| CVE-2019-3409 | CRITICAL | 9 | 1.9% | Jun 11, 2019 | All versions up to UKBB_WF820+_1.0.0B06 of ZTE WF820+ LTE Outdoor CPE product are impacted by command injection vulnerab... |
| CVE-2019-12766 | MEDIUM | 6.1 | 0.9% | Jun 11, 2019 | An issue was discovered in Joomla! before 3.9.7. The subform fieldtype does not sufficiently filter or validate input of... |
| CVE-2019-12765 | CRITICAL | 9.8 | 10.5% | Jun 11, 2019 | An issue was discovered in Joomla! before 3.9.7. The CSV export of com_actionslogs is vulnerable to CSV injection. |
| CVE-2019-12764 | MEDIUM | 6.5 | 1.1% | Jun 11, 2019 | An issue was discovered in Joomla! before 3.9.7. The update server URL of com_joomlaupdate can be manipulated by non Sup... |
| CVE-2019-11334 | LOW | 3.7 | 1.6% | Jun 11, 2019 | An authentication bypass in website post requests in the Tzumi Electronics Klic Lock application 1.0.9 for mobile device... |
| CVE-2019-12794 | — | — | 0.9% | Jun 11, 2019 | An issue was discovered in MISP 2.4.108. Organization admins could reset credentials for site admins (organization admin... |
| CVE-2019-12749 | HIGH | 7.1 | 0.6% | Jun 11, 2019 | dbus before 1.10.28, 1.12.x before 1.12.16, and 1.13.x before 1.13.12, as used in DBusServer in Canonical Upstart in Ubu... |
| CVE-2019-10339 | HIGH | 8.8 | 1.8% | Jun 11, 2019 | A missing permission check in Jenkins JX Resources Plugin 1.0.36 and earlier in GlobalPluginConfiguration#doValidateClie... |
| CVE-2019-10338 | — | — | 1.0% | Jun 11, 2019 | A cross-site request forgery vulnerability in Jenkins JX Resources Plugin 1.0.36 and earlier in GlobalPluginConfiguratio... |
| CVE-2019-10337 | — | — | 2.0% | Jun 11, 2019 | An XML external entities (XXE) vulnerability in Jenkins Token Macro Plugin 2.7 and earlier allowed attackers able to con... |
| CVE-2019-10336 | — | — | 1.4% | Jun 11, 2019 | A reflected cross site scripting vulnerability in Jenkins ElectricFlow Plugin 1.1.6 and earlier allowed attackers able t... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now