2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-11615 | — | — | 1.5% | Apr 30, 2019 | /fileman/php/upload.php in doorGets 7.0 has an arbitrary file upload vulnerability. A remote normal registered user can ... |
| CVE-2019-11614 | — | — | 1.5% | Apr 30, 2019 | doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/views/ajax/commentView.php. A remote unauthorized attack... |
| CVE-2019-11613 | — | — | 1.2% | Apr 30, 2019 | doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/views/ajax/contactView.php. A remote normal registered u... |
| CVE-2019-11612 | — | — | 2.7% | Apr 30, 2019 | doorGets 7.0 has an arbitrary file deletion vulnerability in /fileman/php/deletefile.php. A remote unauthenticated attac... |
| CVE-2019-11611 | — | — | 3.9% | Apr 30, 2019 | doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/download.php. A remote unauthenticated... |
| CVE-2019-11610 | — | — | 3.9% | Apr 30, 2019 | doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/downloaddir.php. A remote unauthentica... |
| CVE-2019-11609 | — | — | 4.0% | Apr 30, 2019 | doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/movefile.php. A remote unauthenticated... |
| CVE-2019-11608 | — | — | 4.1% | Apr 30, 2019 | doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/renamefile.php. A remote unauthenticat... |
| CVE-2019-11607 | — | — | 3.9% | Apr 30, 2019 | doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/copydir.php. A remote unauthenticated ... |
| CVE-2019-11606 | — | — | 3.9% | Apr 30, 2019 | doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/copyfile.php. A remote unauthenticated... |
| CVE-2019-9486 | — | — | 2.3% | Apr 30, 2019 | STRATO HiDrive Desktop Client 5.0.1.0 for Windows suffers from a SYSTEM privilege escalation vulnerability through the H... |
| CVE-2019-11193 | MEDIUM | 6.1 | 2.1% | Apr 30, 2019 | The FileManager in InfinitumIT DirectAdmin through v1.561 has XSS via CMD_FILE_MANAGER, CMD_SHOW_USER, and CMD_SHOW_RESE... |
| CVE-2019-10131 | HIGH | 7.1 | 1.3% | Apr 30, 2019 | An off-by-one read vulnerability was discovered in ImageMagick before version 7.0.7-28 in the formatIPTCfromBuffer funct... |
| CVE-2019-9621 | HIGH | 7.5 | 80.9% | Apr 30, 2019 | Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x b... |
| CVE-2019-10272 | — | — | 0.7% | Apr 30, 2019 | An issue was discovered in Weaver e-cology 9.0. There is a CRLF Injection vulnerability via the /workflow/request/ViewRe... |
| CVE-2019-5624 | HIGH | 7.3 | 2.8% | Apr 30, 2019 | Rapid7 Metasploit Framework suffers from an instance of CWE-22, Improper Limitation of a Pathname to a Restricted Direct... |
| CVE-2019-10950 | CRITICAL | 9.8 | 3.6% | Apr 30, 2019 | Fujifilm FCR Capsula X/ Carbon X/ FCR XC-2, model versions CR-IR 357 FCR Carbon X, CR-IR 357 FCR XC-2, FCR-IR 357 FCR Ca... |
| CVE-2019-10948 | — | — | 1.6% | Apr 30, 2019 | Fujifilm FCR Capsula X/ Carbon X/ FCR XC-2, model versions CR-IR 357 FCR Carbon X, CR-IR 357 FCR XC-2, FCR-IR 357 FCR Ca... |
| CVE-2019-3399 | HIGH | 7.5 | 2.1% | Apr 30, 2019 | The BrowseProjects.jspa resource in Jira before version 7.13.2, and from version 8.0.0 before version 8.0.2 allows remot... |
| CVE-2019-6494 | — | — | 1.1% | Apr 30, 2019 | IMFForceDelete.sys in IObit Malware Fighter 6.2 allows a low privileged user to send IOCTL 0x8016E000 along with a user ... |
| CVE-2019-4166 | MEDIUM | 6.1 | 1.5% | Apr 30, 2019 | IBM StoredIQ 7.6 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading... |
| CVE-2019-10318 | HIGH | 8.8 | 1.8% | Apr 30, 2019 | Jenkins Azure AD Plugin 0.3.3 and earlier stored the client secret unencrypted in the global config.xml configuration fi... |
| CVE-2019-10317 | — | — | 1.5% | Apr 30, 2019 | Jenkins SiteMonitor Plugin 0.5 and earlier disabled SSL/TLS and hostname verification globally for the Jenkins master JV... |
| CVE-2019-10316 | HIGH | 8.8 | 1.8% | Apr 30, 2019 | Jenkins Aqua MicroScanner Plugin 1.0.5 and earlier stored credentials unencrypted in its global configuration file on th... |
| CVE-2019-10315 | — | — | 2.1% | Apr 30, 2019 | Jenkins GitHub Authentication Plugin 0.31 and earlier did not use the state parameter of OAuth to prevent CSRF. |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now