2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-11812 | — | — | 0.8% | May 8, 2019 | A persistent XSS issue was discovered in app/View/Helper/CommandHelper.php in MISP before 2.4.107. JavaScript can be inc... |
| CVE-2019-10712 | — | — | 2.8% | May 7, 2019 | The Web-GUI on WAGO Series 750-88x (750-330, 750-352, 750-829, 750-831, 750-852, 750-880, 750-881, 750-882, 750-884, 750... |
| CVE-2019-7746 | — | — | 1.1% | May 7, 2019 | JioFi 4 jmr1140 Amtel_JMR1140_R12.07 devices allow remote attackers to obtain an admin token by making a /cgi-bin/qcmap_... |
| CVE-2019-7745 | — | — | 3.8% | May 7, 2019 | JioFi 4 jmr1140 Amtel_JMR1140_R12.07 devices allow remote attackers to obtain the Wi-Fi password by making a cgi-bin/qcm... |
| CVE-2019-7687 | — | — | 1.6% | May 7, 2019 | cgi-bin/qcmap_web_cgi on JioFi 4 jmr1140 Amtel_JMR1140_R12.07 devices has POST based reflected XSS via the Page paramete... |
| CVE-2019-7564 | — | — | 3.0% | May 7, 2019 | An issue was discovered on Shenzhen Coship WM3300 WiFi Router 5.0.0.55 devices. The password reset functionality of the ... |
| CVE-2019-7541 | — | — | 3.2% | May 7, 2019 | Rukovoditel through 2.4.1 allows XSS via a URL that lacks a module=users%2flogin substring. |
| CVE-2019-7443 | — | — | 2.4% | May 7, 2019 | KDE KAuth before 5.55 allows the passing of parameters with arbitrary types to helpers running as root over DBus via DBu... |
| CVE-2019-7427 | — | — | 2.8% | May 7, 2019 | XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/linkdo... |
| CVE-2019-7426 | — | — | 2.8% | May 7, 2019 | XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/linkdo... |
| CVE-2019-4208 | HIGH | 7.1 | 1.9% | May 7, 2019 | IBM TRIRIGA Application Platform 3.5.3 and 3.6.0 is vulnerable to an XML External Entity Injection (XXE) attack when pro... |
| CVE-2019-4207 | LOW | 3.3 | 0.3% | May 7, 2019 | IBM TRIRIGA Application Platform 3.5.3 and 3.6.0 may disclose sensitive information only available to a local user that ... |
| CVE-2019-10742 | — | — | 6.0% | May 7, 2019 | Axios up to and including 0.18.0 allows attackers to cause a denial of service (application crash) by continuing to acce... |
| CVE-2019-11629 | — | — | 0.7% | May 7, 2019 | Sonatype Nexus Repository Manager 2.x before 2.14.13 allows XSS. |
| CVE-2019-10869 | HIGH | 8.1 | 13.0% | May 7, 2019 | Path Traversal and Unrestricted File Upload exists in the Ninja Forms plugin before 3.0.23 for WordPress (when the Uploa... |
| CVE-2019-9708 | — | — | 1.0% | May 7, 2019 | An issue was discovered in Mahara 17.10 before 17.10.8, 18.04 before 18.04.4, and 18.10 before 18.10.1. A site administr... |
| CVE-2019-11560 | — | — | 1.9% | May 7, 2019 | A buffer overflow vulnerability in the streaming server provided by hisilicon in HI3516 models allows an unauthenticated... |
| CVE-2019-9709 | — | — | 0.6% | May 7, 2019 | An issue was discovered in Mahara 17.10 before 17.10.8, 18.04 before 18.04.4, and 18.10 before 18.10.1. The collection t... |
| CVE-2019-11811 | HIGH | 7 | 0.5% | May 7, 2019 | An issue was discovered in the Linux kernel before 5.0.4. There is a use-after-free upon attempted read access to /proc/... |
| CVE-2019-11810 | HIGH | 7.5 | 5.8% | May 7, 2019 | An issue was discovered in the Linux kernel before 5.0.7. A NULL pointer dereference can occur when megasas_create_frame... |
| CVE-2019-11808 | — | — | 1.3% | May 7, 2019 | Ratpack versions before 1.6.1 generate a session ID using a cryptographically weak PRNG in the JDK's ThreadLocalRandom. ... |
| CVE-2019-11569 | — | — | 2.3% | May 6, 2019 | Veeam ONE Reporter 9.5.0.3201 allows CSRF. |
| CVE-2019-10999 | — | — | 3.7% | May 6, 2019 | The D-Link DCS series of Wi-Fi cameras contains a stack-based buffer overflow in alphapd, the camera's web server. The o... |
| CVE-2019-11807 | — | — | 1.5% | May 6, 2019 | The WooCommerce Checkout Manager plugin before 4.3 for WordPress allows media deletion via the wp-admin/admin-ajax.php?a... |
| CVE-2019-5434 | — | — | 57.0% | May 6, 2019 | An attacker could send a specifically crafted payload to the XML-RPC invocation script and trigger the unserialize() cal... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now