2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-8404An issue was discovered in Webiness Inventory 2.3. The ProductModel component allows Arbitrary File Upload via a crafted...
CVE-2019-8391qdPM 9.1 suffers from Cross-site Scripting (XSS) via configuration?type=[XSS] parameter.
CVE-2019-8390qdPM 9.1 suffers from Cross-site Scripting (XSS) in the search[keywords] parameter.
CVE-2019-6516An issue was discovered in WSO2 Dashboard Server 2.0.0. It is possible to force the application to perform requests to t...
CVE-2019-6515An issue was discovered in WSO2 API Manager 2.6.0. Uploaded documents for API documentation are available to an unauthen...
CVE-2019-6514An issue was discovered in WSO2 Dashboard Server 2.0.0. It is possible to inject a JavaScript payload that will be store...
CVE-2019-6512An issue was discovered in WSO2 API Manager 2.6.0. It is possible to force the application to perform requests to the in...
CVE-2019-11336Sony Bravia Smart TV devices allow remote attackers to retrieve the static Wi-Fi password (used when the TV is acting as...
CVE-2019-12087Samsung S9+, S10, and XCover 4 P(9.0) devices can become temporarily inoperable because of an unprotected intent in the ...
CVE-2019-9618The GraceMedia Media Player plugin 1.0 for WordPress allows Local File Inclusion via the "cfg" parameter.
CVE-2019-8952A Path Traversal vulnerability located in the webserver affects several Bosch hardware and software products. The vulner...
CVE-2019-8951An Open Redirect vulnerability located in the webserver affects several Bosch hardware and software products. The vulner...
CVE-2019-10053An issue was discovered in Suricata 4.1.x before 4.1.4. If the input of the function SSHParseBanner is composed only of ...
CVE-2019-1862HIGH7.2A vulnerability in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote a...
CVE-2019-12083HIGH8.1The Rust Programming Language Standard Library 1.34.x before 1.34.2 contains a stabilized method which, if overridden, c...
CVE-2019-11600A SQL injection vulnerability in the activities API in OpenProject before 8.3.2 allows a remote attacker to execute arbi...
CVE-2019-7218Citrix ShareFile before 19.23 allows a downgrade from two-factor authentication to one-factor authentication. An attacke...
CVE-2019-7217Citrix ShareFile before 19.12 allows User Enumeration. It is possible to enumerate application username based on differe...
CVE-2019-1649MEDIUM6.7A vulnerability in the logic that handles access control to one of the hardware components in Cisco's proprietary Secure...
CVE-2019-11680KonaKart 8.9.0.0 is vulnerable to Remote Code Execution by uploading a web shell as a product category image.
CVE-2019-9727Unauthenticated password hash disclosure in the User.getUserPWD method in eQ-3 AG Homematic CCU3 3.43.15 and earlier all...
CVE-2019-9726Directory Traversal / Arbitrary File Read in eQ-3 AG Homematic CCU3 3.43.15 and earlier allows remote attackers to read ...
CVE-2019-8342A Local Privilege Escalation in libqcocoa.dylib in Foxit Reader 3.1.0.0111 on macOS has been discovered due to an incorr...
CVE-2019-3702A Remote Code Execution issue in the DNS Query Web UI in Lifesize Icon LS_RM3_3.7.0 (2421) allows remote authenticated a...
CVE-2019-10050HIGH7.5A buffer over-read issue was discovered in Suricata 4.1.x before 4.1.4. If the input of the decode-mpls.c function Decod...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now