2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-1689 | HIGH | 7.3 | 1.6% | Feb 25, 2019 | A vulnerability in the client application for iOS of Cisco Webex Teams could allow an authenticated, remote attacker to ... |
| CVE-2019-1683 | HIGH | 7.4 | 0.9% | Feb 25, 2019 | A vulnerability in the certificate handling component of the Cisco SPA112, SPA525, and SPA5X5 Series IP Phones could all... |
| CVE-2019-9144 | — | — | 2.8% | Feb 25, 2019 | An issue was discovered in Exiv2 0.27. There is infinite recursion at BigTiffImage::printIFD in the file bigtiffimage.cp... |
| CVE-2019-9143 | — | — | 2.8% | Feb 25, 2019 | An issue was discovered in Exiv2 0.27. There is infinite recursion at Exiv2::Image::printTiffStructure in the file image... |
| CVE-2019-9142 | — | — | 0.8% | Feb 25, 2019 | An issue was discovered in b3log Symphony (aka Sym) before v3.4.7. XSS exists via the userIntro and userNickname fields ... |
| CVE-2019-9116 | — | — | 1.1% | Feb 25, 2019 | DLL hijacking is possible in Sublime Text 3 version 3.1.1 build 3176 on 32-bit Windows platforms because a Trojan horse ... |
| CVE-2019-9126 | HIGH | 7.5 | 1.7% | Feb 25, 2019 | An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. There is an information disclosure vulnerability via reque... |
| CVE-2019-9125 | — | — | 3.0% | Feb 25, 2019 | An issue was discovered on D-Link DIR-878 1.12B01 devices. Because strncpy is misused, there is a stack-based buffer ove... |
| CVE-2019-9124 | — | — | 2.2% | Feb 25, 2019 | An issue was discovered on D-Link DIR-878 1.12B01 devices. At the /HNAP1 URI, an attacker can log in with a blank passwo... |
| CVE-2019-9123 | CRITICAL | 9.8 | 1.5% | Feb 25, 2019 | An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. The "user" account has a blank password. |
| CVE-2019-9122 | HIGH | 8.8 | 23.5% | Feb 25, 2019 | An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. They allow remote attackers to execute arbitrary commands ... |
| CVE-2019-9115 | — | — | 2.3% | Feb 25, 2019 | In irisnet-crypto before 1.1.7 for IRISnet, the util/utils.js file allows code execution because of unsafe eval usage. |
| CVE-2019-9114 | — | — | 1.3% | Feb 25, 2019 | Ming (aka libming) 0.4.8 has an out of bounds write vulnerability in the function strcpyext() in the decompile.c file in... |
| CVE-2019-9113 | — | — | 1.4% | Feb 25, 2019 | Ming (aka libming) 0.4.8 has a NULL pointer dereference in the function getString() in the decompile.c file in libutil.a... |
| CVE-2019-9112 | — | — | 0.8% | Feb 25, 2019 | The msm gpu driver for custom Linux kernels on the Xiaomi perseus-p-oss MIX 3 device through 2018-11-26 has an integer o... |
| CVE-2019-9111 | — | — | 0.8% | Feb 25, 2019 | The msm gpu driver for custom Linux kernels on the Xiaomi perseus-p-oss MIX 3 device through 2018-11-26 has an integer o... |
| CVE-2019-9110 | — | — | 0.9% | Feb 25, 2019 | XSS exists in WUZHI CMS 4.1.0 via index.php?m=content&f=postinfo&v=listing&set_iframe=[XSS] to coreframe/app/content/pos... |
| CVE-2019-9109 | — | — | 0.9% | Feb 25, 2019 | XSS exists in WUZHI CMS 4.1.0 via index.php?m=message&f=message&v=add&username=[XSS] to coreframe/app/message/message.ph... |
| CVE-2019-9108 | — | — | 0.9% | Feb 25, 2019 | XSS exists in WUZHI CMS 4.1.0 via index.php?m=core&f=map&v=baidumap&x=[XSS]&y=[XSS] to coreframe/app/core/map.php. |
| CVE-2019-9107 | — | — | 0.9% | Feb 25, 2019 | XSS exists in WUZHI CMS 4.1.0 via index.php?m=attachment&f=imagecut&v=init&imgurl=[XSS] to coreframe/app/attachment/imag... |
| CVE-2019-9082 | HIGH | 8.8 | 97.4% | Feb 24, 2019 | ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public/... |
| CVE-2019-9081 | — | — | — | Feb 24, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2019-9078 | — | — | 0.6% | Feb 24, 2019 | zzcms 2019 has XSS via an arbitrary user/ask.php?do=modify parameter because inc/stopsqlin.php does not block a mixed-ca... |
| CVE-2019-8375 | — | — | 16.1% | Feb 24, 2019 | The UIProcess subsystem in WebKit, as used in WebKitGTK through 2.23.90 and WebKitGTK+ through 2.22.6 and other products... |
| CVE-2019-9077 | HIGH | 7.8 | 2.0% | Feb 24, 2019 | An issue was discovered in GNU Binutils 2.32. It is a heap-based buffer overflow in process_mips_specific in readelf.c v... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now