2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-8404 | — | — | 8.0% | May 14, 2019 | An issue was discovered in Webiness Inventory 2.3. The ProductModel component allows Arbitrary File Upload via a crafted... |
| CVE-2019-8391 | — | — | 3.3% | May 14, 2019 | qdPM 9.1 suffers from Cross-site Scripting (XSS) via configuration?type=[XSS] parameter. |
| CVE-2019-8390 | — | — | 8.9% | May 14, 2019 | qdPM 9.1 suffers from Cross-site Scripting (XSS) in the search[keywords] parameter. |
| CVE-2019-6516 | — | — | 1.4% | May 14, 2019 | An issue was discovered in WSO2 Dashboard Server 2.0.0. It is possible to force the application to perform requests to t... |
| CVE-2019-6515 | — | — | 1.5% | May 14, 2019 | An issue was discovered in WSO2 API Manager 2.6.0. Uploaded documents for API documentation are available to an unauthen... |
| CVE-2019-6514 | — | — | 0.9% | May 14, 2019 | An issue was discovered in WSO2 Dashboard Server 2.0.0. It is possible to inject a JavaScript payload that will be store... |
| CVE-2019-6512 | — | — | 1.1% | May 14, 2019 | An issue was discovered in WSO2 API Manager 2.6.0. It is possible to force the application to perform requests to the in... |
| CVE-2019-11336 | — | — | 3.2% | May 14, 2019 | Sony Bravia Smart TV devices allow remote attackers to retrieve the static Wi-Fi password (used when the TV is acting as... |
| CVE-2019-12087 | — | — | 0.4% | May 14, 2019 | Samsung S9+, S10, and XCover 4 P(9.0) devices can become temporarily inoperable because of an unprotected intent in the ... |
| CVE-2019-9618 | — | — | 40.8% | May 13, 2019 | The GraceMedia Media Player plugin 1.0 for WordPress allows Local File Inclusion via the "cfg" parameter. |
| CVE-2019-8952 | — | — | 1.4% | May 13, 2019 | A Path Traversal vulnerability located in the webserver affects several Bosch hardware and software products. The vulner... |
| CVE-2019-8951 | — | — | 1.1% | May 13, 2019 | An Open Redirect vulnerability located in the webserver affects several Bosch hardware and software products. The vulner... |
| CVE-2019-10053 | — | — | 1.7% | May 13, 2019 | An issue was discovered in Suricata 4.1.x before 4.1.4. If the input of the function SSHParseBanner is composed only of ... |
| CVE-2019-1862 | HIGH | 7.2 | 5.5% | May 13, 2019 | A vulnerability in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote a... |
| CVE-2019-12083 | HIGH | 8.1 | 2.2% | May 13, 2019 | The Rust Programming Language Standard Library 1.34.x before 1.34.2 contains a stabilized method which, if overridden, c... |
| CVE-2019-11600 | — | — | 80.0% | May 13, 2019 | A SQL injection vulnerability in the activities API in OpenProject before 8.3.2 allows a remote attacker to execute arbi... |
| CVE-2019-7218 | — | — | 1.2% | May 13, 2019 | Citrix ShareFile before 19.23 allows a downgrade from two-factor authentication to one-factor authentication. An attacke... |
| CVE-2019-7217 | — | — | 2.0% | May 13, 2019 | Citrix ShareFile before 19.12 allows User Enumeration. It is possible to enumerate application username based on differe... |
| CVE-2019-1649 | MEDIUM | 6.7 | 0.6% | May 13, 2019 | A vulnerability in the logic that handles access control to one of the hardware components in Cisco's proprietary Secure... |
| CVE-2019-11680 | — | — | 4.2% | May 13, 2019 | KonaKart 8.9.0.0 is vulnerable to Remote Code Execution by uploading a web shell as a product category image. |
| CVE-2019-9727 | — | — | 2.2% | May 13, 2019 | Unauthenticated password hash disclosure in the User.getUserPWD method in eQ-3 AG Homematic CCU3 3.43.15 and earlier all... |
| CVE-2019-9726 | — | — | 15.7% | May 13, 2019 | Directory Traversal / Arbitrary File Read in eQ-3 AG Homematic CCU3 3.43.15 and earlier allows remote attackers to read ... |
| CVE-2019-8342 | — | — | 0.5% | May 13, 2019 | A Local Privilege Escalation in libqcocoa.dylib in Foxit Reader 3.1.0.0111 on macOS has been discovered due to an incorr... |
| CVE-2019-3702 | — | — | 5.3% | May 13, 2019 | A Remote Code Execution issue in the DNS Query Web UI in Lifesize Icon LS_RM3_3.7.0 (2421) allows remote authenticated a... |
| CVE-2019-10050 | HIGH | 7.5 | 1.5% | May 13, 2019 | A buffer over-read issue was discovered in Suricata 4.1.x before 4.1.4. If the input of the decode-mpls.c function Decod... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now