2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-12206njs through 0.3.1, used in NGINX, has a heap-based buffer overflow in nxt_utf8_encode in nxt_utf8.c.
CVE-2019-11809An issue was discovered in Joomla! before 3.9.6. The debug views of com_users do not properly escape user supplied data,...
CVE-2019-12198In GoHttp through 2017-07-25, there is a stack-based buffer over-read via a long User-Agent header.
CVE-2019-12185eLabFTW 1.8.5 is vulnerable to arbitrary file uploads via the /app/controllers/EntityController.php component. This may ...
CVE-2019-12184There is XSS in browser/components/MarkdownPreview.js in BoostIO Boostnote 0.11.15 via a label named flowchart, sequence...
CVE-2019-12173MacDown 0.7.1 (870) allows remote code execution via a file:\\\ URI, with a .app pathname, in the HREF attribute of an A...
CVE-2019-12172Typora 0.9.9.21.1 (1913) allows arbitrary code execution via a modified file: URL syntax in the HREF attribute of an ARE...
CVE-2019-12170ATutor through 2.2.4 is vulnerable to arbitrary file uploads via the mods/_core/backups/upload.php (aka backup) componen...
CVE-2019-12168Four-Faith Wireless Mobile Router F3x24 v1.0 devices allow remote code execution via the Command Shell (aka Administrati...
CVE-2019-12163MEDIUM5.3GAT-Ship Web Module through 1.30 allows remote attackers to obtain potentially sensitive information via {} in a ws/gats...
CVE-2019-11644In the F-Secure installer in F-Secure SAFE for Windows before 17.6, F-Secure Internet Security before 17.6, F-Secure Ant...
CVE-2019-8339An issue was discovered in Falco through 0.14.0. A missing indicator for insufficient resources allows local users to by...
CVE-2019-12161WPO WebPageTest 19.04 allows SSRF because ValidateURL in www/runtest.php does not consider octal encoding of IP addresse...
CVE-2019-12160GoHTTP through 2017-07-25 has a sendHeader use-after-free.
CVE-2019-12159GoHTTP through 2017-07-25 has a stack-based buffer over-read in the scan function (when called from getRequestType) via ...
CVE-2019-12158GoHTTP through 2017-07-25 has a GetExtension heap-based buffer overflow via a long extension.
CVE-2019-7353An Incorrect Access Control issue was discovered in GitLab Community and Enterprise Edition 11.7.x before 11.7.4. GitLab...
CVE-2019-12086HIGH7.5A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9. When Default Typing is enabled...
CVE-2019-11887SimplyBook.me through 2019-05-11 does not properly restrict File Upload which could allow remote code execution.
CVE-2019-11057HIGH8.8SQL injection vulnerability in Vtiger CRM before 7.1.0 hotfix3 allows authenticated users to execute arbitrary SQL comma...
CVE-2019-6797An information disclosure issue was discovered in GitLab Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11....
CVE-2019-6790An Incorrect Access Control (issue 2 of 3) issue was discovered in GitLab Community and Enterprise Edition 8.14 and late...
CVE-2019-6787An Incorrect Access Control issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before...
CVE-2019-6781HIGH7.5An Improper Input Validation issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x befor...
CVE-2019-5958Untrusted search path vulnerability in Electronic reception and examination of application for radio licenses Offline 1....

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now