2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-9925 | — | — | 0.8% | Mar 22, 2019 | S-CMS PHP v1.0 has XSS in 4.edu.php via the S_id parameter. |
| CVE-2019-9924 | HIGH | 7.8 | 0.4% | Mar 22, 2019 | rbash in Bash before 4.4-beta2 did not prevent the shell user from modifying BASH_CMDS, thus allowing the user to execut... |
| CVE-2019-9923 | HIGH | 7.5 | 3.0% | Mar 22, 2019 | pax_decode_header in sparse.c in GNU Tar before 1.32 had a NULL pointer dereference when parsing certain archives that h... |
| CVE-2019-9915 | — | — | 3.6% | Mar 22, 2019 | GetSimpleCMS 3.3.13 has an Open Redirect via the admin/index.php redirect parameter. |
| CVE-2019-9914 | — | — | 1.7% | Mar 22, 2019 | The yop-poll plugin before 6.0.3 for WordPress has wp-admin/admin.php?page=yop-polls&action=view-votes poll_id XSS. |
| CVE-2019-9913 | — | — | 1.4% | Mar 22, 2019 | The wp-live-chat-support plugin before 8.0.18 for WordPress has wp-admin/admin.php?page=wplivechat-menu-gdpr-page term X... |
| CVE-2019-9912 | MEDIUM | 6.1 | 3.0% | Mar 22, 2019 | The wp-google-maps plugin before 7.10.43 for WordPress has XSS via the wp-admin/admin.php PATH_INFO. |
| CVE-2019-9911 | MEDIUM | 6.1 | 1.3% | Mar 22, 2019 | The social-networks-auto-poster-facebook-twitter-g plugin before 4.2.8 for WordPress has wp-admin/admin.php?page=nxssnap... |
| CVE-2019-9910 | — | — | 1.4% | Mar 22, 2019 | The kingcomposer plugin 2.7.6 for WordPress has wp-admin/admin.php?page=kc-mapper id XSS. |
| CVE-2019-9909 | — | — | 1.4% | Mar 22, 2019 | The "Donation Plugin and Fundraising Platform" plugin before 2.3.1 for WordPress has wp-admin/edit.php csv XSS. |
| CVE-2019-9908 | — | — | 1.4% | Mar 22, 2019 | The font-organizer plugin 2.1.1 for WordPress has wp-admin/options-general.php manage_font_id XSS. |
| CVE-2019-8351 | — | — | 1.3% | Mar 21, 2019 | Heimdal Thor Agent 2.5.17x before 2.5.173 does not verify X.509 certificates from TLS servers, which allows remote attac... |
| CVE-2019-7539 | — | — | 1.6% | Mar 21, 2019 | A code injection issue was discovered in ipycache through 2016-05-31. |
| CVE-2019-3871 | MEDIUM | 6.5 | 12.9% | Mar 21, 2019 | A vulnerability was found in PowerDNS Authoritative Server before 4.0.7 and before 4.1.7. An insufficient validation of ... |
| CVE-2019-3858 | MEDIUM | 5 | 6.4% | Mar 21, 2019 | An out of bounds read flaw was discovered in libssh2 before 1.8.1 when a specially crafted SFTP packet is received from ... |
| CVE-2019-3855 | HIGH | 8.8 | 9.2% | Mar 21, 2019 | An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before 1.8.1 in the way pa... |
| CVE-2019-7537 | — | — | 3.4% | Mar 21, 2019 | An issue was discovered in Donfig 0.3.0. There is a vulnerability in the collect_yaml method in config_obj.py. It can ex... |
| CVE-2019-5490 | — | — | 3.5% | Mar 21, 2019 | Certain versions between 2.x to 5.x (refer to advisory) of the NetApp Service Processor firmware were shipped with a def... |
| CVE-2019-9904 | MEDIUM | 6.5 | 2.7% | Mar 21, 2019 | An issue was discovered in lib\cdt\dttree.c in libcdt.a in graphviz 2.40.1. Stack consumption occurs because of recursiv... |
| CVE-2019-9903 | MEDIUM | 6.5 | 2.3% | Mar 21, 2019 | PDFDoc::markObject in PDFDoc.cc in Poppler 0.74.0 mishandles dict marking, leading to stack consumption in the function ... |
| CVE-2019-8997 | — | — | 2.3% | Mar 21, 2019 | An XML External Entity Injection (XXE) vulnerability in the Management System (console) of BlackBerry AtHoc versions ear... |
| CVE-2019-0198 | — | — | — | Mar 21, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca... |
| CVE-2019-7238 | CRITICAL | 9.8 | 76.5% | Mar 21, 2019 | Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control. |
| CVE-2019-6491 | — | — | 1.3% | Mar 21, 2019 | RISI Gestao de Horarios v3201.09.08 rev.23 allows SQL Injection. |
| CVE-2019-9898 | — | — | 3.9% | Mar 21, 2019 | Potential recycling of random numbers used in cryptography exists within PuTTY before 0.71. |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now