2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-9897 | — | — | 3.0% | Mar 21, 2019 | Multiple denial-of-service attacks that can be triggered by writing to the terminal exist in PuTTY versions before 0.71. |
| CVE-2019-9896 | HIGH | 7.8 | 0.8% | Mar 21, 2019 | In PuTTY versions before 0.71 on Windows, local attackers could hijack the application by putting a malicious help file ... |
| CVE-2019-9895 | — | — | 2.6% | Mar 21, 2019 | In PuTTY versions before 0.71 on Unix, a remotely triggerable buffer overflow exists in any kind of server-to-client for... |
| CVE-2019-9894 | — | — | 2.4% | Mar 21, 2019 | A remotely triggerable memory overwrite in RSA key exchange in PuTTY before 0.71 can occur before host key verification. |
| CVE-2019-9893 | — | — | 3.0% | Mar 21, 2019 | libseccomp before 2.4.0 did not correctly generate 64-bit syscall argument comparisons using the arithmetic operators (L... |
| CVE-2019-9889 | — | — | 2.4% | Mar 21, 2019 | In Vanilla before 2.6.4, a flaw exists within the getSingleIndex function of the AddonManager class. The issue results i... |
| CVE-2019-9878 | — | — | 1.2% | Mar 21, 2019 | There is an invalid memory access in the function GfxIndexedColorSpace::mapColorToBase() located in GfxState.cc in Xpdf ... |
| CVE-2019-9877 | — | — | 1.1% | Mar 21, 2019 | There is an invalid memory access vulnerability in the function TextPage::findGaps() located at TextOutputDev.c in Xpdf ... |
| CVE-2019-9870 | — | — | 1.8% | Mar 21, 2019 | plugin.js in the w8tcha oEmbed plugin before 2019-03-14 for CKEditor mishandles SCRIPT elements. |
| CVE-2019-9868 | — | — | 1.3% | Mar 21, 2019 | An issue was discovered in the Web Console in Veritas NetBackup Appliance through 3.1.2. The SMTP password is displayed ... |
| CVE-2019-9867 | — | — | 1.2% | Mar 21, 2019 | An issue was discovered in the Web Console in Veritas NetBackup Appliance through 3.1.2. The proxy server password is di... |
| CVE-2019-9857 | — | — | 0.4% | Mar 21, 2019 | In the Linux kernel through 5.0.2, the function inotify_update_existing_watch() in fs/notify/inotify/inotify_user.c negl... |
| CVE-2019-9837 | — | — | 1.3% | Mar 21, 2019 | Doorkeeper::OpenidConnect (aka the OpenID Connect extension for Doorkeeper) 1.4.x and 1.5.x before 1.5.4 has an open red... |
| CVE-2019-9094 | — | — | 0.8% | Mar 21, 2019 | A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in /s/adada/cfiles/upload in Humhub 1.3.10 Community... |
| CVE-2019-9093 | — | — | 0.8% | Mar 21, 2019 | A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in file/file/upload in Humhub 1.3.10 Community Editi... |
| CVE-2019-9083 | — | — | 17.6% | Mar 21, 2019 | SQLiteManager 1.20 and 1.24 allows SQL injection via the /sqlitemanager/main.php dbsel parameter. NOTE: This product is ... |
| CVE-2019-8938 | — | — | 1.5% | Mar 21, 2019 | VertrigoServ 2.17 allows XSS via the /inc/extensions.php ext parameter. |
| CVE-2019-8934 | LOW | 3.3 | 0.6% | Mar 21, 2019 | hw/ppc/spapr.c in QEMU through 3.1.0 allows Information Exposure because the hypervisor shares the /proc/device-tree/sys... |
| CVE-2019-7441 | — | — | 6.0% | Mar 21, 2019 | cgi-bin/webscr?cmd=_cart in the WooCommerce PayPal Checkout Payment Gateway plugin 1.6.8 for WordPress allows Parameter ... |
| CVE-2019-7440 | — | — | 2.0% | Mar 21, 2019 | JioFi 4G M2S 1.0.2 devices have CSRF via the SSID name and Security Key field under Edit Wi-Fi Settings (aka a SetWiFi_S... |
| CVE-2019-7439 | — | — | 4.8% | Mar 21, 2019 | cgi-bin/qcmap_web_cgi on JioFi 4G M2S 1.0.2 devices allows a DoS (Hang) via the mask POST parameter. |
| CVE-2019-7438 | — | — | 4.0% | Mar 21, 2019 | cgi-bin/qcmap_web_cgi on JioFi 4G M2S 1.0.2 devices has XSS and HTML injection via the mask POST parameter. |
| CVE-2019-7437 | — | — | 0.8% | Mar 21, 2019 | PHP Scripts Mall Opensource Classified Ads Script 3.2.2 has reflected Cross-Site Scripting (XSS) via the Search field. |
| CVE-2019-7436 | — | — | 1.4% | Mar 21, 2019 | PHP Scripts Mall Opensource Classified Ads Script 3.2.2 has directory traversal via a direct request for a listing of an... |
| CVE-2019-7435 | — | — | 1.0% | Mar 21, 2019 | PHP Scripts Mall Opensource Classified Ads Script 3.2.2 has reflected HTML injection via the Search Form. |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now