2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-11592 | — | — | 0.8% | Apr 29, 2019 | WeBid 1.2.2 has reflected XSS via the id parameter to admin/deletenews.php, admin/editbannersuser.php, admin/editfaqscat... |
| CVE-2019-11591 | HIGH | 8.8 | 1.1% | Apr 29, 2019 | The WebDorado Contact Form plugin before 1.13.5 for WordPress allows CSRF via the wp-admin/admin-ajax.php action paramet... |
| CVE-2019-11590 | — | — | 1.2% | Apr 29, 2019 | The 10Web Form Maker plugin before 1.13.5 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, wi... |
| CVE-2019-11579 | MEDIUM | 5.3 | 1.4% | Apr 28, 2019 | dhcp.c in dhcpcd before 7.2.1 contains a 1-byte read overflow with DHO_OPTSOVERLOADED. |
| CVE-2019-11578 | MEDIUM | 5.9 | 2.0% | Apr 28, 2019 | auth.c in dhcpcd before 7.2.1 allowed attackers to infer secrets by performing latency attacks. |
| CVE-2019-11577 | — | — | 53.1% | Apr 28, 2019 | dhcpcd before 7.2.1 contains a buffer overflow in dhcp6_findna in dhcp6.c when reading NA/TA addresses. |
| CVE-2019-11576 | — | — | 1.7% | Apr 28, 2019 | Gitea before 1.8.0 allows 1FA for user accounts that have completed 2FA enrollment. If a user's credentials are known, t... |
| CVE-2019-11568 | — | — | 1.4% | Apr 27, 2019 | An issue was discovered in AikCms v2.0. There is a File upload vulnerability, as demonstrated by an admin/page/system/na... |
| CVE-2019-11567 | — | — | 1.3% | Apr 27, 2019 | An issue was discovered in AikCms v2.0. There is a SQL Injection vulnerability via $_GET['del'], as demonstrated by an a... |
| CVE-2019-11565 | — | — | 2.8% | Apr 27, 2019 | Server Side Request Forgery (SSRF) exists in the Print My Blog plugin before 1.6.7 for WordPress via the site parameter. |
| CVE-2019-11557 | HIGH | 8.8 | 1.1% | Apr 26, 2019 | The WebDorado Contact Form Builder plugin before 1.0.69 for WordPress allows CSRF via the wp-admin/admin-ajax.php action... |
| CVE-2019-11555 | — | — | 3.3% | Apr 26, 2019 | The EAP-pwd implementation in hostapd (EAP server) before 2.8 and wpa_supplicant (EAP peer) before 2.8 does not validate... |
| CVE-2019-7476 | HIGH | 8.1 | 1.4% | Apr 26, 2019 | A vulnerability in SonicWall Global Management System (GMS), allow a remote user to gain access to the appliance using e... |
| CVE-2019-3844 | HIGH | 7.8 | 0.9% | Apr 26, 2019 | It was discovered that a systemd service that uses DynamicUser property can get new privileges through the execution of ... |
| CVE-2019-3843 | HIGH | 7.8 | 0.9% | Apr 26, 2019 | It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allo... |
| CVE-2019-11533 | — | — | 1.2% | Apr 26, 2019 | Cross-site scripting (XSS) vulnerability in ProjectSend before r1070 allows remote attackers to inject arbitrary web scr... |
| CVE-2019-11492 | — | — | 1.1% | Apr 26, 2019 | ProjectSend before r1070 writes user passwords to the server logs. |
| CVE-2019-6689 | — | — | 0.8% | Apr 26, 2019 | An issue was discovered in Dillon Kane Tidal Workload Automation Agent 3.2.0.5 (formerly known as Cisco Workload Automat... |
| CVE-2019-3707 | HIGH | 8.6 | 3.3% | Apr 26, 2019 | Dell EMC iDRAC9 versions prior to 3.30.30.30 contain an authentication bypass vulnerability. A remote attacker may poten... |
| CVE-2019-3706 | HIGH | 8.6 | 3.3% | Apr 26, 2019 | Dell EMC iDRAC9 versions prior to 3.24.24.24, 3.21.26.22, 3.22.22.22 and 3.21.25.22 contain an authentication bypass vul... |
| CVE-2019-3705 | CRITICAL | 9.8 | 4.2% | Apr 26, 2019 | Dell EMC iDRAC6 versions prior to 2.92, iDRAC7/iDRAC8 versions prior to 2.61.60.60, and iDRAC9 versions prior to 3.20.21... |
| CVE-2019-2725 | CRITICAL | 9.8 | 100.0% | Apr 26, 2019 | Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte... |
| CVE-2019-11220 | — | — | 1.2% | Apr 26, 2019 | An authentication flaw in Shenzhen Yunni Technology iLnkP2P allows remote attackers to actively intercept user-to-device... |
| CVE-2019-11219 | — | — | 1.8% | Apr 26, 2019 | The algorithm used to generate device IDs (UIDs) for devices that utilize Shenzhen Yunni Technology iLnkP2P suffers from... |
| CVE-2019-9813 | — | — | 7.4% | Apr 26, 2019 | Incorrect handling of __proto__ mutations may lead to type confusion in IonMonkey JIT code and can be leveraged for arbi... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now