2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-13191 | — | — | 1.4% | Sep 5, 2019 | A SQL injection vulnerability in IntraMaps MapControl 8 allows attackers to execute arbitrary SQL commands via the /Appl... |
| CVE-2019-13188 | — | — | 2.5% | Sep 5, 2019 | In Knowage through 6.1.1, an unauthenticated user can bypass access controls and access the entire application. |
| CVE-2019-13187 | — | — | 1.8% | Sep 5, 2019 | The Rich Text Formatter (Redactor) extension through v1.1.1 for Symphony CMS has an Unauthenticated arbitrary file uploa... |
| CVE-2019-13190 | — | — | 1.4% | Sep 5, 2019 | In Knowage through 6.1.1, the sign up page does not invalidate a valid CAPTCHA token. This allows for CAPTCHA bypass in ... |
| CVE-2019-15938 | — | — | 2.1% | Sep 5, 2019 | Pengutronix barebox through 2019.08.1 has a remote buffer overflow in nfs_readlink_req in fs/nfs.c because a length fiel... |
| CVE-2019-15937 | — | — | 2.1% | Sep 5, 2019 | Pengutronix barebox through 2019.08.1 has a remote buffer overflow in nfs_readlink_reply in net/nfs.c because a length f... |
| CVE-2019-12223 | — | — | 2.4% | Sep 5, 2019 | An issue was discovered in NVR WebViewer on Hanwah Techwin SRN-472s 1.07_190502 devices, and other SRN-x devices before ... |
| CVE-2019-10677 | — | — | 7.3% | Sep 5, 2019 | Multiple Cross-Site Scripting (XSS) issues in the web interface on DASAN Zhone ZNID GPON 2426A EU version S3.1.285 devic... |
| CVE-2019-14470 | — | — | 83.0% | Sep 4, 2019 | cosenary Instagram-PHP-API (aka Instagram PHP API V2), as used in the UserPro plugin through 4.9.32 for WordPress, has X... |
| CVE-2019-14319 | — | — | 1.1% | Sep 4, 2019 | The TikTok (formerly Musical.ly) application 12.2.0 for Android and iOS performs unencrypted transmission of images, vid... |
| CVE-2019-12586 | — | — | 1.4% | Sep 4, 2019 | The EAP peer implementation in Espressif ESP-IDF 2.0.0 through 4.0.0 and ESP8266_NONOS_SDK 2.2.0 through 3.1.0 processes... |
| CVE-2019-15924 | — | — | 0.5% | Sep 4, 2019 | An issue was discovered in the Linux kernel before 5.0.11. fm10k_init_module in drivers/net/ethernet/intel/fm10k/fm10k_m... |
| CVE-2019-15923 | — | — | 0.6% | Sep 4, 2019 | An issue was discovered in the Linux kernel before 5.0.9. There is a NULL pointer dereference for a cd data structure if... |
| CVE-2019-15922 | — | — | 0.5% | Sep 4, 2019 | An issue was discovered in the Linux kernel before 5.0.9. There is a NULL pointer dereference for a pf data structure if... |
| CVE-2019-6646 | — | — | 1.5% | Sep 4, 2019 | On BIG-IP 11.5.2-11.6.4 and Enterprise Manager 3.1.1, REST users with guest privileges may be able to escalate their pri... |
| CVE-2019-13976 | — | — | 1.7% | Sep 4, 2019 | eGain Chat 15.0.3 allows unrestricted file upload. |
| CVE-2019-13975 | — | — | 0.9% | Sep 4, 2019 | eGain Chat 15.0.3 allows HTML Injection. |
| CVE-2019-13518 | — | — | 1.4% | Sep 4, 2019 | An attacker could use a specially crafted project file to overflow the buffer and execute code under the privileges of t... |
| CVE-2019-15814 | — | — | 1.6% | Sep 4, 2019 | Multiple stored XSS vulnerabilities in Sentrifugo 3.2 could allow authenticated users to inject arbitrary web script or ... |
| CVE-2019-13209 | — | — | 1.1% | Sep 4, 2019 | Rancher 2 through 2.2.4 is vulnerable to a Cross-Site Websocket Hijacking attack that allows an exploiter to gain access... |
| CVE-2019-12587 | — | — | 0.8% | Sep 4, 2019 | The EAP peer implementation in Espressif ESP-IDF 2.0.0 through 4.0.0 and ESP8266_NONOS_SDK 2.2.0 through 3.1.0 allows th... |
| CVE-2019-10709 | — | — | 11.5% | Sep 4, 2019 | AsusPTPFilter.sys on Asus Precision TouchPad 11.0.0.25 hardware has a Pool Overflow associated with the \\.\AsusTP devic... |
| CVE-2019-15898 | — | — | 1.6% | Sep 3, 2019 | Nagios Log Server before 2.0.8 allows Reflected XSS via the username on the Login page. |
| CVE-2019-15892 | — | — | 5.7% | Sep 3, 2019 | An issue was discovered in Varnish Cache before 6.0.4 LTS, and 6.1.x and 6.2.x before 6.2.1. An HTTP/1 parsing failure a... |
| CVE-2019-5480 | — | — | 1.6% | Sep 3, 2019 | A path traversal vulnerability in <= v0.9.7 of statichttpserver npm module allows attackers to list files in arbitrary f... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now