2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-1617HIGH7.4A vulnerability in the Fibre Channel over Ethernet (FCoE) N-port Virtualization (NPV) protocol implementation in Cisco N...
CVE-2019-1616HIGH8.6A vulnerability in the Cisco Fabric Services component of Cisco NX-OS Software could allow an unauthenticated, remote at...
CVE-2019-1615MEDIUM6.7A vulnerability in the Image Signature Verification feature of Cisco NX-OS Software could allow an authenticated, local ...
CVE-2019-1614HIGH8.8A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote attacker to execute a...
CVE-2019-1613MEDIUM6.7A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary com...
CVE-2019-1612MEDIUM4.2A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary com...
CVE-2019-1611MEDIUM6.7A vulnerability in the CLI of Cisco NX-OS Software and Cisco FXOS Software could allow an authenticated, local attacker ...
CVE-2019-1610MEDIUM6.7A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary com...
CVE-2019-9693In CMS Made Simple (CMSMS) before 2.2.10, an authenticated user can achieve SQL Injection in class.showtime2_data.php vi...
CVE-2019-9692class.showtime2_image.php in CMS Made Simple (CMSMS) before 2.2.10 does not ensure that a watermark file has a standard ...
CVE-2019-9688sftnow through 2018-12-29 allows index.php?g=Admin&m=User&a=add_post CSRF to add an admin account.
CVE-2019-9687PoDoFo 0.9.6 has a heap-based buffer overflow in PdfString::ConvertUTF16toUTF8 in base/PdfString.cpp.
CVE-2019-9686HIGH8.8pacman before 5.1.3 allows directory traversal when installing a remote package via a specified URL "pacman -U <url>" du...
CVE-2019-9659The Chuango 433 MHz burglar-alarm product line uses static codes in the RF remote control, allowing an attacker to arm, ...
CVE-2019-9675An issue was discovered in PHP 7.x before 7.1.27 and 7.3.x before 7.3.3. phar_tar_writeheaders_int in ext/phar/tar.c has...
CVE-2019-9662An issue was discovered in JTBC(PHP) 3.0.1.8. Its cache management module is flawed. An arbitrary file ending in "inc.ph...
CVE-2019-9661Stored XSS exists in YzmCMS 5.2 via the admin/system_manage/user_config_edit.html "value" parameter,
CVE-2019-9660Stored XSS exists in YzmCMS 5.2 via the admin/category/edit.html "catname" parameter.
CVE-2019-9658Checkstyle before 8.18 loads external DTDs by default.
CVE-2019-9656HIGH8.8An issue was discovered in LibOFX 0.9.14. There is a NULL pointer dereference in the function OFXApplication::startEleme...
CVE-2019-9652There is a CSRF in SDCMS V1.7 via an m=admin&c=theme&a=edit request. It allows PHP code injection by providing a filenam...
CVE-2019-9651An issue was discovered in SDCMS V1.7. In the \app\admin\controller\themecontroller.php file, the check_bad() function's...
CVE-2019-9650An XSS issue was discovered in upcoming_events.php in the Upcoming Events plugin before 1.33 for MyBB via a crafted name...
CVE-2019-9646The Contact Form Email plugin before 1.2.66 for WordPress allows wp-admin/admin.php item XSS, related to cp_admin_int_ed...
CVE-2019-9580In st2web in StackStorm Web UI before 2.9.3 and 2.10.x before 2.10.3, it is possible to bypass the CORS protection mecha...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now