2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-9925S-CMS PHP v1.0 has XSS in 4.edu.php via the S_id parameter.
CVE-2019-9924HIGH7.8rbash in Bash before 4.4-beta2 did not prevent the shell user from modifying BASH_CMDS, thus allowing the user to execut...
CVE-2019-9923HIGH7.5pax_decode_header in sparse.c in GNU Tar before 1.32 had a NULL pointer dereference when parsing certain archives that h...
CVE-2019-9915GetSimpleCMS 3.3.13 has an Open Redirect via the admin/index.php redirect parameter.
CVE-2019-9914The yop-poll plugin before 6.0.3 for WordPress has wp-admin/admin.php?page=yop-polls&action=view-votes poll_id XSS.
CVE-2019-9913The wp-live-chat-support plugin before 8.0.18 for WordPress has wp-admin/admin.php?page=wplivechat-menu-gdpr-page term X...
CVE-2019-9912MEDIUM6.1The wp-google-maps plugin before 7.10.43 for WordPress has XSS via the wp-admin/admin.php PATH_INFO.
CVE-2019-9911MEDIUM6.1The social-networks-auto-poster-facebook-twitter-g plugin before 4.2.8 for WordPress has wp-admin/admin.php?page=nxssnap...
CVE-2019-9910The kingcomposer plugin 2.7.6 for WordPress has wp-admin/admin.php?page=kc-mapper id XSS.
CVE-2019-9909The "Donation Plugin and Fundraising Platform" plugin before 2.3.1 for WordPress has wp-admin/edit.php csv XSS.
CVE-2019-9908The font-organizer plugin 2.1.1 for WordPress has wp-admin/options-general.php manage_font_id XSS.
CVE-2019-8351Heimdal Thor Agent 2.5.17x before 2.5.173 does not verify X.509 certificates from TLS servers, which allows remote attac...
CVE-2019-7539A code injection issue was discovered in ipycache through 2016-05-31.
CVE-2019-3871MEDIUM6.5A vulnerability was found in PowerDNS Authoritative Server before 4.0.7 and before 4.1.7. An insufficient validation of ...
CVE-2019-3858MEDIUM5An out of bounds read flaw was discovered in libssh2 before 1.8.1 when a specially crafted SFTP packet is received from ...
CVE-2019-3855HIGH8.8An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before 1.8.1 in the way pa...
CVE-2019-7537An issue was discovered in Donfig 0.3.0. There is a vulnerability in the collect_yaml method in config_obj.py. It can ex...
CVE-2019-5490Certain versions between 2.x to 5.x (refer to advisory) of the NetApp Service Processor firmware were shipped with a def...
CVE-2019-9904MEDIUM6.5An issue was discovered in lib\cdt\dttree.c in libcdt.a in graphviz 2.40.1. Stack consumption occurs because of recursiv...
CVE-2019-9903MEDIUM6.5PDFDoc::markObject in PDFDoc.cc in Poppler 0.74.0 mishandles dict marking, leading to stack consumption in the function ...
CVE-2019-8997An XML External Entity Injection (XXE) vulnerability in the Management System (console) of BlackBerry AtHoc versions ear...
CVE-2019-0198Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca...
CVE-2019-7238CRITICAL9.8Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.
CVE-2019-6491RISI Gestao de Horarios v3201.09.08 rev.23 allows SQL Injection.
CVE-2019-9898Potential recycling of random numbers used in cryptography exists within PuTTY before 0.71.

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now