2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-1617 | HIGH | 7.4 | 1.5% | Mar 11, 2019 | A vulnerability in the Fibre Channel over Ethernet (FCoE) N-port Virtualization (NPV) protocol implementation in Cisco N... |
| CVE-2019-1616 | HIGH | 8.6 | 2.4% | Mar 11, 2019 | A vulnerability in the Cisco Fabric Services component of Cisco NX-OS Software could allow an unauthenticated, remote at... |
| CVE-2019-1615 | MEDIUM | 6.7 | 0.2% | Mar 11, 2019 | A vulnerability in the Image Signature Verification feature of Cisco NX-OS Software could allow an authenticated, local ... |
| CVE-2019-1614 | HIGH | 8.8 | 4.1% | Mar 11, 2019 | A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote attacker to execute a... |
| CVE-2019-1613 | MEDIUM | 6.7 | 0.5% | Mar 11, 2019 | A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary com... |
| CVE-2019-1612 | MEDIUM | 4.2 | 0.5% | Mar 11, 2019 | A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary com... |
| CVE-2019-1611 | MEDIUM | 6.7 | 0.5% | Mar 11, 2019 | A vulnerability in the CLI of Cisco NX-OS Software and Cisco FXOS Software could allow an authenticated, local attacker ... |
| CVE-2019-1610 | MEDIUM | 6.7 | 0.5% | Mar 11, 2019 | A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary com... |
| CVE-2019-9693 | — | — | 1.2% | Mar 11, 2019 | In CMS Made Simple (CMSMS) before 2.2.10, an authenticated user can achieve SQL Injection in class.showtime2_data.php vi... |
| CVE-2019-9692 | — | — | 46.5% | Mar 11, 2019 | class.showtime2_image.php in CMS Made Simple (CMSMS) before 2.2.10 does not ensure that a watermark file has a standard ... |
| CVE-2019-9688 | — | — | 0.7% | Mar 11, 2019 | sftnow through 2018-12-29 allows index.php?g=Admin&m=User&a=add_post CSRF to add an admin account. |
| CVE-2019-9687 | — | — | 2.2% | Mar 11, 2019 | PoDoFo 0.9.6 has a heap-based buffer overflow in PdfString::ConvertUTF16toUTF8 in base/PdfString.cpp. |
| CVE-2019-9686 | HIGH | 8.8 | 3.4% | Mar 11, 2019 | pacman before 5.1.3 allows directory traversal when installing a remote package via a specified URL "pacman -U <url>" du... |
| CVE-2019-9659 | — | — | 1.3% | Mar 11, 2019 | The Chuango 433 MHz burglar-alarm product line uses static codes in the RF remote control, allowing an attacker to arm, ... |
| CVE-2019-9675 | — | — | 6.0% | Mar 11, 2019 | An issue was discovered in PHP 7.x before 7.1.27 and 7.3.x before 7.3.3. phar_tar_writeheaders_int in ext/phar/tar.c has... |
| CVE-2019-9662 | — | — | 1.7% | Mar 11, 2019 | An issue was discovered in JTBC(PHP) 3.0.1.8. Its cache management module is flawed. An arbitrary file ending in "inc.ph... |
| CVE-2019-9661 | — | — | 0.7% | Mar 11, 2019 | Stored XSS exists in YzmCMS 5.2 via the admin/system_manage/user_config_edit.html "value" parameter, |
| CVE-2019-9660 | — | — | 0.7% | Mar 11, 2019 | Stored XSS exists in YzmCMS 5.2 via the admin/category/edit.html "catname" parameter. |
| CVE-2019-9658 | — | — | 3.7% | Mar 11, 2019 | Checkstyle before 8.18 loads external DTDs by default. |
| CVE-2019-9656 | HIGH | 8.8 | 2.1% | Mar 11, 2019 | An issue was discovered in LibOFX 0.9.14. There is a NULL pointer dereference in the function OFXApplication::startEleme... |
| CVE-2019-9652 | — | — | 0.6% | Mar 11, 2019 | There is a CSRF in SDCMS V1.7 via an m=admin&c=theme&a=edit request. It allows PHP code injection by providing a filenam... |
| CVE-2019-9651 | — | — | 2.6% | Mar 11, 2019 | An issue was discovered in SDCMS V1.7. In the \app\admin\controller\themecontroller.php file, the check_bad() function's... |
| CVE-2019-9650 | — | — | 3.4% | Mar 11, 2019 | An XSS issue was discovered in upcoming_events.php in the Upcoming Events plugin before 1.33 for MyBB via a crafted name... |
| CVE-2019-9646 | — | — | 1.4% | Mar 10, 2019 | The Contact Form Email plugin before 1.2.66 for WordPress allows wp-admin/admin.php item XSS, related to cp_admin_int_ed... |
| CVE-2019-9580 | — | — | 3.0% | Mar 9, 2019 | In st2web in StackStorm Web UI before 2.9.3 and 2.10.x before 2.10.3, it is possible to bypass the CORS protection mecha... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now