2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-3481Mitigates a XML External Entity Parsing issue in ArcSight Logger versions prior to 6.7.
CVE-2019-3480Mitigates a stored/reflected XSS issue in ArcSight Logger versions prior to 6.7.
CVE-2019-3479Mitigates a potential remote code execution issue in ArcSight Logger versions prior to 6.7.
CVE-2019-3476Remote arbitrary code execution in Micro Focus Data Protector, version 10.03 this vulnerability could allow remote arbit...
CVE-2019-10016GForge Advanced Server 6.4.4 allows XSS via the commonsearch.php words parameter, as demonstrated by a snippet/search/?w...
CVE-2019-10027PHPCMS 9.6.x through 9.6.3 has XSS via the mailbox (aka E-mail) field on the personal information screen.
CVE-2019-10026An issue was discovered in Xpdf 4.01.01. There is an FPE in the function PostScriptFunction::exec in Function.cc for the...
CVE-2019-10025An issue was discovered in Xpdf 4.01.01. There is an FPE in the function ImageStream::ImageStream at Stream.cc for nBits...
CVE-2019-10024An issue was discovered in Xpdf 4.01.01. There is an FPE in the function Splash::scaleImageYuXu at Splash.cc for y Brese...
CVE-2019-10023An issue was discovered in Xpdf 4.01.01. There is an FPE in the function PostScriptFunction::exec at Function.cc for the...
CVE-2019-10022An issue was discovered in Xpdf 4.01.01. There is a NULL pointer dereference in the function Gfx::opSetExtGState in Gfx....
CVE-2019-10021An issue was discovered in Xpdf 4.01.01. There is an FPE in the function ImageStream::ImageStream at Stream.cc for nComp...
CVE-2019-10020An issue was discovered in Xpdf 4.01.01. There is an FPE in the function Splash::scaleImageYuXu at Splash.cc for x Brese...
CVE-2019-10019An issue was discovered in Xpdf 4.01.01. There is an FPE in the function PSOutputDev::checkPageSlice at PSOutputDev.cc f...
CVE-2019-10018MEDIUM5.5An issue was discovered in Xpdf 4.01.01. There is an FPE in the function PostScriptFunction::exec at Function.cc for the...
CVE-2019-10017CMS Made Simple 2.2.10 has XSS via the moduleinterface.php Name field, which is reachable via an "Add a new Profile" act...
CVE-2019-10015baigoStudio baigoSSO v3.0.1 allows remote attackers to execute arbitrary PHP code via the first form field of a configur...
CVE-2019-10014In DedeCMS 5.7SP2, member/resetpassword.php allows remote authenticated users to reset the passwords of arbitrary users ...
CVE-2019-10010Cross-site scripting (XSS) vulnerability in the PHP League CommonMark library before 0.18.3 allows remote attackers to i...
CVE-2019-9978MEDIUM6.1The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio...
CVE-2019-9977The renderer process in the entertainment system on Tesla Model 3 vehicles mishandles JIT compilation, which allows atta...
CVE-2019-9970Open Whisper Signal (aka Signal-Desktop) through 1.23.1 and the Signal Private Messenger application through 4.35.3 for ...
CVE-2019-9969XnView Classic 2.48 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have...
CVE-2019-9968XnView Classic 2.48 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have...
CVE-2019-9967XnView Classic 2.48 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now