2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-11523Anviz Global M3 Outdoor RFID Access Control executes any command received from any source. No authentication/encryption ...
CVE-2019-6452HIGH8.8Kyocera Command Center RX TASKalfa4501i and TASKalfa5052ci allows remote attackers to abuse the Test button in the machi...
CVE-2019-6451HIGH7.5On SOYAL AR-727H and AR-829Ev5 devices, all CGI programs allow unauthenticated POST access.
CVE-2019-5525VMware Workstation (15.x before 15.1.0) contains a use-after-free vulnerability in the Advanced Linux Sound Architecture...
CVE-2019-5522VMware Tools for Windows update addresses an out of bounds read vulnerability in vm3dmp driver which is installed with v...
CVE-2019-3790MEDIUM6.1The Pivotal Ops Manager, 2.2.x versions prior to 2.2.23, 2.3.x versions prior to 2.3.16, 2.4.x versions prior to 2.4.11,...
CVE-2019-3723CRITICAL9.1Dell EMC OpenManage Server Administrator (OMSA) versions prior to 9.1.0.3 and prior to 9.2.0.4 contain a web parameter t...
CVE-2019-3722HIGH7.5Dell EMC OpenManage Server Administrator (OMSA) versions prior to 9.1.0.3 and prior to 9.2.0.4 contain an XML external e...
CVE-2019-3579MEDIUM5.3MyBB 1.8.19 allows remote attackers to obtain sensitive information because it discloses the username upon receiving a p...
CVE-2019-3578MEDIUM6.1MyBB 1.8.19 has XSS in the resetpassword function.
CVE-2019-12761A code injection issue was discovered in PyXDG before 0.26 via crafted Python code in a Category element of a Menu XML d...
CVE-2019-12760LOW3.3A deserialization vulnerability exists in the way parso through 0.4.0 handles grammar parsing from the cache. Cache load...
CVE-2019-6989TP-Link TL-WR940N is vulnerable to a stack-based buffer overflow, caused by improper bounds checking by the ipAddrDispos...
CVE-2019-9929Northern.tech CFEngine Enterprise 3.12.1 has Insecure Permissions.
CVE-2019-7215Progress Sitefinity 10.1.6536 does not invalidate session cookies upon logouts. It instead tries to overwrite the cookie...
CVE-2019-12291HashiCorp Consul 1.4.0 through 1.5.0 has Incorrect Access Control. Keys not matching a specific ACL rule used for prefix...
CVE-2019-12135An unspecified vulnerability in the application server in PaperCut MF and NG versions 18.3.8 and earlier and versions 19...
CVE-2019-7554An issue was discovered in PHP Scripts Mall API Based Travel Booking 3.4.7. There is Reflected XSS via the flight-result...
CVE-2019-7553MEDIUM5.4PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has Stored XSS in the Profile Update page via the My Name ...
CVE-2019-7552MEDIUM5.4An issue was discovered in PHP Scripts Mall Investment MLM Software 2.0.2. Stored XSS was found in the the My Profile Se...
CVE-2019-7311An issue was discovered on Linksys WRT1900ACS 1.0.3.187766 devices. A lack of encryption in how the user login cookie (a...
CVE-2019-7220X-Cart V5 is vulnerable to XSS via the CategoryFilter2 parameter.
CVE-2019-12303In Rancher 2 through 2.2.3, Project owners can inject additional fluentd configuration to read files or execute arbitrar...
CVE-2019-12274In Rancher 1 and 2 through 2.2.3, unprivileged users (if allowed to deploy nodes) can gain admin access to the Rancher m...
CVE-2019-8320A Directory Traversal issue was discovered in RubyGems 2.7.6 and later through 3.0.2. Before making new directories or t...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now