2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-5889 | HIGH | 7.5 | 2.2% | Apr 1, 2019 | An log-management directory traversal issue was discovered in OverIT Geocall 6.3 before build 2:346977. |
| CVE-2019-5888 | MEDIUM | 6.1 | 0.9% | Apr 1, 2019 | Multiple XSS vulnerabilities were discovered in OverIT Geocall 6.3 before build 2:346977. |
| CVE-2019-10684 | — | — | 2.4% | Apr 1, 2019 | Application/Admin/Controller/ConfigController.class.php in 74cms v5.0.1 allows remote attackers to execute arbitrary PHP... |
| CVE-2019-3876 | MEDIUM | 6.3 | 0.7% | Apr 1, 2019 | A flaw was found in the /oauth/token/request custom endpoint of the OpenShift OAuth server allowing for XSS generation o... |
| CVE-2019-3836 | MEDIUM | 5.9 | 3.4% | Apr 1, 2019 | It was discovered in gnutls before version 3.6.7 upstream that there is an uninitialized pointer access in gnutls versio... |
| CVE-2019-1002101 | MEDIUM | 6.4 | 13.2% | Apr 1, 2019 | The kubectl cp command allows copying files between containers and the user machine. To copy files from a container, Kub... |
| CVE-2019-1002100 | MEDIUM | 6.5 | 10.5% | Apr 1, 2019 | In all Kubernetes versions prior to v1.11.8, v1.12.6, and v1.13.4, users that are authorized to make patch requests to t... |
| CVE-2019-10678 | — | — | 17.3% | Mar 31, 2019 | Domoticz before 4.10579 neglects to categorize \n and \r as insecure argument options. |
| CVE-2019-10675 | — | — | — | Mar 31, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2019-10672 | — | — | 2.4% | Mar 31, 2019 | treeRead in hdf/btree.c in libmysofa before 0.7 does not properly validate multiplications and additions. |
| CVE-2019-10664 | — | — | 7.5% | Mar 31, 2019 | Domoticz before 4.10578 allows SQL Injection via the idx parameter in CWebServer::GetFloorplanImage in WebServer.cpp. |
| CVE-2019-10663 | — | — | 28.1% | Mar 30, 2019 | Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to conduct SQL injection attacks via the s... |
| CVE-2019-10662 | HIGH | 8.8 | 43.8% | Mar 30, 2019 | Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to execute arbitrary code via shell metach... |
| CVE-2019-10661 | CRITICAL | 9.8 | 1.8% | Mar 30, 2019 | On Grandstream GXV3611IR_HD before 1.0.3.23 devices, the root account lacks a password. |
| CVE-2019-10660 | HIGH | 8.8 | 2.7% | Mar 30, 2019 | Grandstream GXV3611IR_HD before 1.0.3.23 devices allow remote authenticated users to execute arbitrary code via shell me... |
| CVE-2019-10659 | HIGH | 8.8 | 2.7% | Mar 30, 2019 | Grandstream GXV3370 before 1.0.1.41 and WP820 before 1.0.3.6 devices allow remote authenticated users to execute arbitra... |
| CVE-2019-10658 | HIGH | 8.8 | 2.7% | Mar 30, 2019 | Grandstream GWN7610 before 1.0.8.18 devices allow remote authenticated users to execute arbitrary code via shell metacha... |
| CVE-2019-10657 | MEDIUM | 6.5 | 1.5% | Mar 30, 2019 | Grandstream GWN7000 before 1.0.6.32 and GWN7610 before 1.0.8.18 devices allow remote authenticated users to discover pas... |
| CVE-2019-10656 | HIGH | 8.8 | 4.0% | Mar 30, 2019 | Grandstream GWN7000 before 1.0.6.32 devices allow remote authenticated users to execute arbitrary code via shell metacha... |
| CVE-2019-10655 | CRITICAL | 9.8 | 15.4% | Mar 30, 2019 | Grandstream GAC2500 1.0.3.35, GXP2200 1.0.3.27, GVC3202 1.0.3.51, GXV3275 before 1.0.3.219 Beta, and GXV3240 before 1.0.... |
| CVE-2019-10654 | — | — | 1.2% | Mar 30, 2019 | The lzo1x_decompress function in liblzo2.so.2 in LZO 2.10, as used in Long Range Zip (aka lrzip) 0.631, allows remote at... |
| CVE-2019-10652 | — | — | 7.1% | Mar 30, 2019 | An issue was discovered in flatCore 1.4.7. acp/acp.php allows remote authenticated administrators to upload arbitrary .p... |
| CVE-2019-10650 | — | — | 4.1% | Mar 30, 2019 | In ImageMagick 7.0.8-36 Q16, there is a heap-based buffer over-read in the function WriteTIFFImage of coders/tiff.c, whi... |
| CVE-2019-10649 | MEDIUM | 5.5 | 1.7% | Mar 30, 2019 | In ImageMagick 7.0.8-36 Q16, there is a memory leak in the function SVGKeyValuePairs of coders/svg.c, which allows an at... |
| CVE-2019-10648 | — | — | 2.2% | Mar 30, 2019 | Robocode through 1.9.3.5 allows remote attackers to cause external service interaction (DNS), as demonstrated by a query... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now