2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-3778 | MEDIUM | 6.5 | 15.6% | Mar 7, 2019 | Spring Security OAuth, versions 2.3 prior to 2.3.5, and 2.2 prior to 2.2.4, and 2.1 prior to 2.1.4, and 2.0 prior to 2.0... |
| CVE-2019-3777 | HIGH | 8 | 1.9% | Mar 7, 2019 | Pivotal Application Service (PAS), versions 2.2.x prior to 2.2.12, 2.3.x prior to 2.3.7 and 2.4.x prior to 2.4.3, contai... |
| CVE-2019-3776 | HIGH | 7.2 | 0.9% | Mar 7, 2019 | Pivotal Operations Manager, 2.1.x versions prior to 2.1.20, 2.2.x versions prior to 2.2.16, 2.3.x versions prior to 2.3.... |
| CVE-2019-3775 | HIGH | 7.1 | 0.9% | Mar 7, 2019 | Cloud Foundry UAA, versions prior to v70.0, allows a user to update their own email address. A remote authenticated user... |
| CVE-2019-3712 | HIGH | 8.2 | 0.9% | Mar 7, 2019 | Dell WES Wyse Device Agent versions prior to 14.1.2.9 and Dell Wyse ThinLinux HAgent versions prior to 5.4.55 00.10 cont... |
| CVE-2019-9626 | — | — | 1.4% | Mar 7, 2019 | PHPSHE 1.7 allows module/index/cart.php pintuan_id SQL Injection to index.php. |
| CVE-2019-9625 | — | — | 2.4% | Mar 7, 2019 | JBMC DirectAdmin 1.55 allows CSRF via the /CMD_ACCOUNT_ADMIN URI to create a new admin account. |
| CVE-2019-9624 | — | — | 23.7% | Mar 7, 2019 | Webmin 1.900 allows remote attackers to execute arbitrary code by leveraging the "Java file manager" and "Upload and Dow... |
| CVE-2019-9623 | — | — | 8.1% | Mar 7, 2019 | Feng Office 3.7.0.5 allows remote attackers to execute arbitrary code via "<!--#exec cmd=" in a .shtml file to ck_upload... |
| CVE-2019-9622 | — | — | 4.9% | Mar 7, 2019 | eBrigade through 4.5 allows Arbitrary File Download via ../ directory traversal in the showfile.php file parameter, as d... |
| CVE-2019-9617 | — | — | 2.8% | Mar 6, 2019 | An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and ... |
| CVE-2019-9616 | — | — | 2.8% | Mar 6, 2019 | An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and ... |
| CVE-2019-9615 | — | — | 1.3% | Mar 6, 2019 | An issue was discovered in OFCMS before 1.1.3. It allows admin/system/generate/create?sql= SQL injection, related to Sys... |
| CVE-2019-9614 | — | — | 2.6% | Mar 6, 2019 | An issue was discovered in OFCMS before 1.1.3. A command execution vulnerability exists via a template file with '<#assi... |
| CVE-2019-9613 | — | — | 2.8% | Mar 6, 2019 | An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and ... |
| CVE-2019-9612 | — | — | 2.7% | Mar 6, 2019 | An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and ... |
| CVE-2019-9611 | — | — | 1.5% | Mar 6, 2019 | An issue was discovered in OFCMS before 1.1.3. It allows admin/cms/template/getTemplates.html?res_path=res directory tra... |
| CVE-2019-9610 | — | — | 1.4% | Mar 6, 2019 | An issue was discovered in OFCMS before 1.1.3. It has admin/cms/template/getTemplates.html?res_path=res&up_dir=../ direc... |
| CVE-2019-9609 | — | — | 2.7% | Mar 6, 2019 | An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and ... |
| CVE-2019-9608 | — | — | 2.7% | Mar 6, 2019 | An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and ... |
| CVE-2019-9607 | — | — | 1.6% | Mar 6, 2019 | PHP Scripts Mall Medical Store Script 3.0.3 allows Path Traversal by navigating to the parent directory of a jpg or png ... |
| CVE-2019-9606 | — | — | 0.6% | Mar 6, 2019 | PHP Scripts Mall Personal Video Collection Script 4.0.4 has Stored XSS via the "Update profile" feature. |
| CVE-2019-1595 | HIGH | 7.4 | 0.6% | Mar 6, 2019 | A vulnerability in the Fibre Channel over Ethernet (FCoE) protocol implementation in Cisco NX-OS Software could allow an... |
| CVE-2019-1594 | HIGH | 7.4 | 0.8% | Mar 6, 2019 | A vulnerability in the 802.1X implementation for Cisco NX-OS Software could allow an unauthenticated, adjacent attacker ... |
| CVE-2019-1593 | HIGH | 7.8 | 0.4% | Mar 6, 2019 | A vulnerability in the Bash shell implementation for Cisco NX-OS Software could allow an authenticated, local attacker t... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now