2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-5927Directory traversal vulnerability in 'an' App for iOS Version 3.2.0 and earlier allows remote attackers to read arbitrar...
CVE-2019-5926Cross-site scripting vulnerability in KinagaCMS versions prior to 6.5 allows remote authenticated attackers to inject ar...
CVE-2019-5420CRITICAL9.8A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess th...
CVE-2019-5419HIGH7.5There is a possible denial of service vulnerability in Action View (Rails) <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 where...
CVE-2019-5418HIGH7.5There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe...
CVE-2019-3877MEDIUM5.8A vulnerability was found in mod_auth_mellon before v0.14.2. An open redirect in the logout URL allows requests with bac...
CVE-2019-3847MEDIUM4.8A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Users with the "login as other users...
CVE-2019-3840MEDIUM5.8A NULL pointer dereference flaw was discovered in libvirt before version 5.0.0 in the way it gets interface information ...
CVE-2019-3828MEDIUM4.2Ansible fetch module before versions 2.5.15, 2.6.14, 2.7.8 has a path traversal vulnerability which allows copying and o...
CVE-2019-3821HIGH7.5A flaw was found in the way civetweb frontend was handling requests for ceph RGW server with SSL enabled. An unauthentic...
CVE-2019-3817HIGH7.5A use-after-free flaw has been discovered in libcomps before version 0.1.10 in the way ObjMRTrees are merged. An attacke...
CVE-2019-3814HIGH7.7It was discovered that Dovecot before versions 2.2.36.1 and 2.3.4.1 incorrectly handled client certificates. A remote at...
CVE-2019-9917ZNC before 1.7.3-rc1 allows an existing remote user to cause a Denial of Service (crash) via invalid encoding.
CVE-2019-10125CRITICAL9.8An issue was discovered in aio_poll() in fs/aio.c in the Linux kernel through 5.0.4. A file may be released by aio_poll_...
CVE-2019-10124Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2019-10118Snipe-IT before 4.6.14 has XSS, as demonstrated by log_meta values and the user's last name in the API.
CVE-2019-7167Zcash, before the Sapling network upgrade (2018-10-28), had a counterfeiting vulnerability. A key-generation process, du...
CVE-2019-1571The Expedition Migration tool 1.1.8 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML ...
CVE-2019-6569CRITICAL9.1The monitor barrier of the affected products insufficiently blocks data from being forwarded over the mirror port into t...
CVE-2019-1572PAN-OS 9.0.0 may allow an unauthenticated remote user to access php files.
CVE-2019-1570The Expedition Migration tool 1.1.8 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML ...
CVE-2019-1569The Expedition Migration tool 1.1.8 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML ...
CVE-2019-10107CMS Made Simple 2.2.10 has XSS via the myaccount.php "Email Address" field, which is reachable via the "My Preferences -...
CVE-2019-10106CMS Made Simple 2.2.10 has XSS via the 'moduleinterface.php' Name field, which is reachable via an "Add Category" action...
CVE-2019-10105CMS Made Simple 2.2.10 has a Self-XSS vulnerability via the Layout Design Manager "Name" field, which is reachable via a...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now