2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-10647 | — | — | 6.6% | Mar 30, 2019 | ZZZCMS zzzphp v1.6.3 allows remote attackers to execute arbitrary PHP code via a .php URL in the plugins/ueditor/php/con... |
| CVE-2019-10646 | — | — | 0.9% | Mar 30, 2019 | Wolf CMS v0.8.3.1 is affected by cross site scripting (XSS) in the module Add Snippet (/?/admin/snippet/add). This allow... |
| CVE-2019-10644 | — | — | 0.7% | Mar 30, 2019 | An issue was discovered in HYBBS 2.2. /?admin/user.html has a CSRF vulnerability that can add an administrator account. |
| CVE-2019-9922 | HIGH | 7.5 | 10.6% | Mar 29, 2019 | An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. Directory Traversal allows read access t... |
| CVE-2019-9921 | MEDIUM | 6.5 | 1.1% | Mar 29, 2019 | An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. It is possible to read information that ... |
| CVE-2019-9920 | HIGH | 8.8 | 1.3% | Mar 29, 2019 | An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. It is possible to perform an action with... |
| CVE-2019-9919 | MEDIUM | 5.4 | 0.7% | Mar 29, 2019 | An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. It is possible to craft messages in a wa... |
| CVE-2019-9918 | CRITICAL | 9.1 | 1.3% | Mar 29, 2019 | An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. Input does not get validated and queries... |
| CVE-2019-9695 | — | — | 0.6% | Mar 29, 2019 | Norton Core prior to v278 may be susceptible to an arbitrary code execution issue, which is a type of vulnerability that... |
| CVE-2019-9605 | — | — | 0.6% | Mar 29, 2019 | PHP Scripts Mall Online Lottery PHP Readymade Script 1.7.0 has Reflected Cross-site Scripting (XSS) via the err value in... |
| CVE-2019-9604 | — | — | 0.6% | Mar 29, 2019 | PHP Scripts Mall Online Lottery PHP Readymade Script 1.7.0 has Cross-Site Request Forgery (CSRF) for Edit Profile action... |
| CVE-2019-6481 | — | — | 2.1% | Mar 29, 2019 | Abine Blur 7.8.2431 allows remote attackers to conduct "Second-Factor Auth Bypass" attacks by using the "Perform a right... |
| CVE-2019-10477 | — | — | 1.8% | Mar 29, 2019 | The FusionInventory plugin before 1.4 for GLPI 9.3.x and before 1.1 for GLPI 9.4.x mishandles sendXML actions. |
| CVE-2019-10276 | — | — | 1.8% | Mar 29, 2019 | Western Bridge Cobub Razor 0.8.0 has a file upload vulnerability via the web/assets/swf/uploadify.php URI, as demonstrat... |
| CVE-2019-10269 | CRITICAL | 9.8 | 2.9% | Mar 29, 2019 | BWA (aka Burrow-Wheeler Aligner) before 2019-01-23 has a stack-based buffer overflow in the bns_restore function in bnts... |
| CVE-2019-10262 | — | — | 1.5% | Mar 28, 2019 | A SQL Injection issue was discovered in BlueCMS 1.6. The variable $ad_id is spliced directly in uploads/admin/ad.php in ... |
| CVE-2019-0225 | HIGH | 7.5 | 10.3% | Mar 28, 2019 | A specially crafted url could be used to access files under the ROOT directory of the application on Apache JSPWiki 2.9.... |
| CVE-2019-0222 | HIGH | 7.5 | 12.4% | Mar 28, 2019 | In Apache ActiveMQ 5.0.0 - 5.15.8, unmarshalling corrupt MQTT frame can lead to broker Out of Memory exception making it... |
| CVE-2019-0212 | — | — | 3.9% | Mar 28, 2019 | In all previously released Apache HBase 2.x versions (2.0.0-2.0.4, 2.1.0-2.1.3), authorization was incorrectly applied t... |
| CVE-2019-6608 | — | — | 1.0% | Mar 28, 2019 | On BIG-IP 11.5.1-11.6.3, 12.1.0-12.1.3, 13.0.0-13.1.1.1, and 14.0.0-14.0.0.2, under certain conditions, the snmpd daemon... |
| CVE-2019-6607 | — | — | 0.7% | Mar 28, 2019 | On BIG-IP ASM 11.5.1-11.5.8, 11.6.1-11.6.3, 12.1.0-12.1.3, 13.0.0-13.1.1.3, and 14.0.0-14.0.0.2, there is a stored cross... |
| CVE-2019-6606 | — | — | 1.3% | Mar 28, 2019 | On BIG-IP 11.5.1-11.6.3.4, 12.1.0-12.1.3.7, 13.0.0-13.1.1.3, and 14.0.0-14.0.0.2, when processing certain SNMP requests ... |
| CVE-2019-6605 | — | — | 1.7% | Mar 28, 2019 | On BIG-IP 11.5.1-11.5.8, 11.6.1-11.6.3, and 12.0.x, an undisclosed sequence of packets received by an SSL virtual server... |
| CVE-2019-6604 | — | — | 1.0% | Mar 28, 2019 | On BIG-IP 11.5.1-11.5.8, 11.6.1-11.6.3, 12.1.0-12.1.3.6, 13.0.0-13.1.1.1, and 14.0.0-14.0.0.2, under certain conditions,... |
| CVE-2019-6603 | — | — | 1.8% | Mar 28, 2019 | In BIG-IP 11.5.1-11.5.8, 11.6.1-11.6.3, 12.1.0-12.1.3, and 13.0.0-13.0.1, malformed TCP packets sent to a self IP addres... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now