2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-11812A persistent XSS issue was discovered in app/View/Helper/CommandHelper.php in MISP before 2.4.107. JavaScript can be inc...
CVE-2019-10712The Web-GUI on WAGO Series 750-88x (750-330, 750-352, 750-829, 750-831, 750-852, 750-880, 750-881, 750-882, 750-884, 750...
CVE-2019-7746JioFi 4 jmr1140 Amtel_JMR1140_R12.07 devices allow remote attackers to obtain an admin token by making a /cgi-bin/qcmap_...
CVE-2019-7745JioFi 4 jmr1140 Amtel_JMR1140_R12.07 devices allow remote attackers to obtain the Wi-Fi password by making a cgi-bin/qcm...
CVE-2019-7687cgi-bin/qcmap_web_cgi on JioFi 4 jmr1140 Amtel_JMR1140_R12.07 devices has POST based reflected XSS via the Page paramete...
CVE-2019-7564An issue was discovered on Shenzhen Coship WM3300 WiFi Router 5.0.0.55 devices. The password reset functionality of the ...
CVE-2019-7541Rukovoditel through 2.4.1 allows XSS via a URL that lacks a module=users%2flogin substring.
CVE-2019-7443KDE KAuth before 5.55 allows the passing of parameters with arbitrary types to helpers running as root over DBus via DBu...
CVE-2019-7427XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/linkdo...
CVE-2019-7426XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/linkdo...
CVE-2019-4208HIGH7.1IBM TRIRIGA Application Platform 3.5.3 and 3.6.0 is vulnerable to an XML External Entity Injection (XXE) attack when pro...
CVE-2019-4207LOW3.3IBM TRIRIGA Application Platform 3.5.3 and 3.6.0 may disclose sensitive information only available to a local user that ...
CVE-2019-10742Axios up to and including 0.18.0 allows attackers to cause a denial of service (application crash) by continuing to acce...
CVE-2019-11629Sonatype Nexus Repository Manager 2.x before 2.14.13 allows XSS.
CVE-2019-10869HIGH8.1Path Traversal and Unrestricted File Upload exists in the Ninja Forms plugin before 3.0.23 for WordPress (when the Uploa...
CVE-2019-9708An issue was discovered in Mahara 17.10 before 17.10.8, 18.04 before 18.04.4, and 18.10 before 18.10.1. A site administr...
CVE-2019-11560A buffer overflow vulnerability in the streaming server provided by hisilicon in HI3516 models allows an unauthenticated...
CVE-2019-9709An issue was discovered in Mahara 17.10 before 17.10.8, 18.04 before 18.04.4, and 18.10 before 18.10.1. The collection t...
CVE-2019-11811HIGH7An issue was discovered in the Linux kernel before 5.0.4. There is a use-after-free upon attempted read access to /proc/...
CVE-2019-11810HIGH7.5An issue was discovered in the Linux kernel before 5.0.7. A NULL pointer dereference can occur when megasas_create_frame...
CVE-2019-11808Ratpack versions before 1.6.1 generate a session ID using a cryptographically weak PRNG in the JDK's ThreadLocalRandom. ...
CVE-2019-11569Veeam ONE Reporter 9.5.0.3201 allows CSRF.
CVE-2019-10999The D-Link DCS series of Wi-Fi cameras contains a stack-based buffer overflow in alphapd, the camera's web server. The o...
CVE-2019-11807The WooCommerce Checkout Manager plugin before 4.3 for WordPress allows media deletion via the wp-admin/admin-ajax.php?a...
CVE-2019-5434An attacker could send a specifically crafted payload to the XML-RPC invocation script and trigger the unserialize() cal...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now