2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-20141MEDIUM6.1An XSS issue was discovered in the Laborator Neon theme 2.0 for WordPress via the data/autosuggest-remote.php q paramete...
CVE-2019-19806MEDIUM5.3_account_forgot_password.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 displays a message indicating whether an em...
CVE-2019-19805MEDIUM5.3_account_forgot_password.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 takes a different amount of time to return ...
CVE-2019-19738MEDIUM6.1log_file_viewer.php in MFScripts YetiShare 3.5.2 through 4.5.3 does not sanitize or encode the output from the lFile par...
CVE-2019-19736MEDIUM6.1MFScripts YetiShare 3.5.2 through 4.5.3 does not set the HttpOnly flag on session cookies, allowing the cookie to be rea...
CVE-2019-19733MEDIUM6.1_get_all_file_server_paths.ajax.php (aka get_all_file_server_paths.ajax.php) in MFScripts YetiShare 3.5.2 through 4.5.3 ...
CVE-2019-4655MEDIUM4.3IBM MQ 9.1.0.0, 9.1.0.1, 9.1.0.2, 9.1.0.3, 9.1.1, 9.1.2, and 9.1.3 is vulnerable to a denial of service attack that woul...
CVE-2019-4623MEDIUM5.4IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbit...
CVE-2019-4343MEDIUM6.5IBM Cognos Analytics 11.0 and 11.1 allows overly permissive cross-origin resource sharing which could allow an attacker ...
CVE-2019-4335MEDIUM5.5IBM Watson Studio Local 1.2.3 stores key files in the user's home directory which could be obtained by another local use...
CVE-2019-20139MEDIUM5.4In Nagios XI 5.6.9, XSS exists via the nocscreenapi.php host, hostgroup, or servicegroup parameter, or the schedulerepor...
CVE-2019-15024MEDIUM6.5In all versions of ClickHouse before 19.14.3, an attacker having write access to ZooKeeper and who is able to run a cust...
CVE-2019-20096MEDIUM5.5In the Linux kernel before 5.1, there is a memory leak in __feat_register_sp() in net/dccp/feat.c, which may cause denia...
CVE-2019-20095MEDIUM5.5mwifiex_tm_cmd in drivers/net/wireless/marvell/mwifiex/cfg80211.c in the Linux kernel before 5.1.6 has some error-handli...
CVE-2019-20093MEDIUM5.5The PoDoFo::PdfVariant::DelayedLoad function in PdfVariant.h in PoDoFo 0.9.6 allows remote attackers to cause a denial o...
CVE-2019-20092MEDIUM5.5An issue was discovered in Bento4 1.5.1.0. There is a NULL pointer dereference in AP4_Descriptor::GetTag in mp42ts when ...
CVE-2019-20091MEDIUM5.5An issue was discovered in Bento4 1.5.1.0. There is a NULL pointer dereference in AP4_Descriptor::GetTag in mp42ts when ...
CVE-2019-20076MEDIUM6.1On Netis DL4323 devices, XSS exists via the form2Ddns.cgi username parameter (DynDns settings of the Dynamic DNS Configu...
CVE-2019-20075MEDIUM6.1On Netis DL4323 devices, pingrtt_v6.html has XSS (Ping6 Diagnostic).
CVE-2019-20073MEDIUM6.1On Netis DL4323 devices, XSS exists via the form2userconfig.cgi username parameter (User Account Configuration).
CVE-2019-20072MEDIUM6.1On Netis DL4323 devices, XSS exists via the form2Ddns.cgi hostname parameter (Dynamic DNS Configuration).
CVE-2019-20071MEDIUM6.5On Netis DL4323 devices, CSRF exists via form2logaction.cgi to delete all logs.
CVE-2019-20070MEDIUM6.1On Netis DL4323 devices, XSS exists via the urlFQDN parameter to form2url.cgi (aka the Keyword field of the URL Blocking...
CVE-2019-20058MEDIUM6.1Bolt 3.7.0, if Symfony Web Profiler is used, allows XSS because unsanitized search?search= input is shown on the _profil...
CVE-2019-20056MEDIUM6.5stb_image.h (aka the stb image loader) 2.23, as used in libsixel and other products, has an assertion failure in stbi__s...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now