2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-9883Multi modules of MailSherlock MSR35 and MSR45 lead to a CSRF vulnerability. It allows attacker to elevate privilege of s...
CVE-2019-9882Multi modules of MailSherlock MSR35 and MSR45 lead to a CSRF vulnerability. It allows attacker to add malicious email so...
CVE-2019-6739HIGH8.8This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Malwarebytes Antimal...
CVE-2019-6738HIGH8.8This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Bitdefender SafePay ...
CVE-2019-6737HIGH8.8This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Bitdefender SafePay ...
CVE-2019-6736HIGH8.8This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Bitdefender SafePay ...
CVE-2019-12593IceWarp Mail Server through 10.4.4 is prone to a local file inclusion vulnerability via webmail/calendar/minimizer/index...
CVE-2019-12308An issue was discovered in Django 1.11 before 1.11.21, 2.1 before 2.1.9, and 2.2 before 2.2.2. The clickable Current URL...
CVE-2019-11646Remote unauthorized command execution and unauthorized disclosure of information in Micro Focus Service Manager, version...
CVE-2019-3802MEDIUM5.3This affects Spring Data JPA in versions up to and including 2.1.6, 2.0.14 and 1.11.20. ExampleMatcher using ExampleMatc...
CVE-2019-3397Atlassian Bitbucket Data Center licensed instances starting with version 5.13.0 before 5.13.6 (the fixed version for 5.1...
CVE-2019-11580CRITICAL9.8Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attac...
CVE-2019-12591MEDIUM6.8NETGEAR Insight Cloud with firmware before Insight 5.6 allows remote authenticated users to achieve command injection.
CVE-2019-12582Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-12583. Reason: This candidate is a reservation d...
CVE-2019-12589In Firejail before 0.9.60, seccomp filters are writable inside the jail, leading to a lack of intended seccomp restricti...
CVE-2019-12585Apcupsd 0.3.91_5, as used in pfSense through 2.4.4-RELEASE-p3 and other products, has an Arbitrary Command Execution iss...
CVE-2019-12584Apcupsd 0.3.91_5, as used in pfSense through 2.4.4-RELEASE-p3 and other products, has an XSS issue in apcupsd_status.php...
CVE-2019-12569A vulnerability in Viber before 10.7.0 for Desktop (Windows) could allow an attacker to execute arbitrary commands on a ...
CVE-2019-12566The WP Statistics plugin through 12.6.5 for Wordpress has stored XSS in includes/class-wp-statistics-pages.php. This is ...
CVE-2019-12564In DouCo DouPHP v1.5 Release 20190516, remote attackers can view the database backup file via a brute-force guessing app...
CVE-2019-12530Incorrect access control was discovered in the stdonato Dashboard plugin through 0.9.7 for GLPI, affecting df.php, issue...
CVE-2019-12515There is an out-of-bounds read vulnerability in the function FlateStream::getChar() located at Stream.cc in Xpdf 4.01.01...
CVE-2019-9653NUUO Network Video Recorder Firmware 1.7.x through 3.3.x allows unauthenticated attackers to execute arbitrary commands ...
CVE-2019-9106The WebApp v04.68 in the supervisor on SAET Impianti Speciali TEBE Small 05.01 build 1137 devices allows remote attacker...
CVE-2019-9105The WebApp v04.68 in the supervisor on SAET Impianti Speciali TEBE Small 05.01 build 1137 devices allows remote attacker...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now