2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-5889HIGH7.5An log-management directory traversal issue was discovered in OverIT Geocall 6.3 before build 2:346977.
CVE-2019-5888MEDIUM6.1Multiple XSS vulnerabilities were discovered in OverIT Geocall 6.3 before build 2:346977.
CVE-2019-10684Application/Admin/Controller/ConfigController.class.php in 74cms v5.0.1 allows remote attackers to execute arbitrary PHP...
CVE-2019-3876MEDIUM6.3A flaw was found in the /oauth/token/request custom endpoint of the OpenShift OAuth server allowing for XSS generation o...
CVE-2019-3836MEDIUM5.9It was discovered in gnutls before version 3.6.7 upstream that there is an uninitialized pointer access in gnutls versio...
CVE-2019-1002101MEDIUM6.4The kubectl cp command allows copying files between containers and the user machine. To copy files from a container, Kub...
CVE-2019-1002100MEDIUM6.5In all Kubernetes versions prior to v1.11.8, v1.12.6, and v1.13.4, users that are authorized to make patch requests to t...
CVE-2019-10678Domoticz before 4.10579 neglects to categorize \n and \r as insecure argument options.
CVE-2019-10675Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2019-10672treeRead in hdf/btree.c in libmysofa before 0.7 does not properly validate multiplications and additions.
CVE-2019-10664Domoticz before 4.10578 allows SQL Injection via the idx parameter in CWebServer::GetFloorplanImage in WebServer.cpp.
CVE-2019-10663Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to conduct SQL injection attacks via the s...
CVE-2019-10662HIGH8.8Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to execute arbitrary code via shell metach...
CVE-2019-10661CRITICAL9.8On Grandstream GXV3611IR_HD before 1.0.3.23 devices, the root account lacks a password.
CVE-2019-10660HIGH8.8Grandstream GXV3611IR_HD before 1.0.3.23 devices allow remote authenticated users to execute arbitrary code via shell me...
CVE-2019-10659HIGH8.8Grandstream GXV3370 before 1.0.1.41 and WP820 before 1.0.3.6 devices allow remote authenticated users to execute arbitra...
CVE-2019-10658HIGH8.8Grandstream GWN7610 before 1.0.8.18 devices allow remote authenticated users to execute arbitrary code via shell metacha...
CVE-2019-10657MEDIUM6.5Grandstream GWN7000 before 1.0.6.32 and GWN7610 before 1.0.8.18 devices allow remote authenticated users to discover pas...
CVE-2019-10656HIGH8.8Grandstream GWN7000 before 1.0.6.32 devices allow remote authenticated users to execute arbitrary code via shell metacha...
CVE-2019-10655CRITICAL9.8Grandstream GAC2500 1.0.3.35, GXP2200 1.0.3.27, GVC3202 1.0.3.51, GXV3275 before 1.0.3.219 Beta, and GXV3240 before 1.0....
CVE-2019-10654The lzo1x_decompress function in liblzo2.so.2 in LZO 2.10, as used in Long Range Zip (aka lrzip) 0.631, allows remote at...
CVE-2019-10652An issue was discovered in flatCore 1.4.7. acp/acp.php allows remote authenticated administrators to upload arbitrary .p...
CVE-2019-10650In ImageMagick 7.0.8-36 Q16, there is a heap-based buffer over-read in the function WriteTIFFImage of coders/tiff.c, whi...
CVE-2019-10649MEDIUM5.5In ImageMagick 7.0.8-36 Q16, there is a memory leak in the function SVGKeyValuePairs of coders/svg.c, which allows an at...
CVE-2019-10648Robocode through 1.9.3.5 allows remote attackers to cause external service interaction (DNS), as demonstrated by a query...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now