2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-8411 | — | — | 2.7% | Feb 17, 2019 | admin/dl_data.php in zzcms 2018 (2018-10-19) allows remote attackers to delete arbitrary files via action=del&filename=.... |
| CVE-2019-8408 | — | — | 1.2% | Feb 17, 2019 | OneFileCMS 3.6.13 allows remote attackers to modify onefilecms.php by clicking the Copy button twice. |
| CVE-2019-8407 | — | — | 1.5% | Feb 17, 2019 | HongCMS 3.0.0 allows arbitrary file read and write operations via a ../ in the filename parameter to the admin/index.php... |
| CVE-2019-8393 | — | — | 1.1% | Feb 17, 2019 | Hotels_Server through 2018-11-05 has SQL Injection via the API because the controller/api/login.php telephone parameter ... |
| CVE-2019-8400 | — | — | 1.3% | Feb 17, 2019 | ORY Hydra before v1.0.0-rc.3+oryOS.9 has Reflected XSS via the oauth2/fallbacks/error error_hint parameter. |
| CVE-2019-8398 | — | — | 1.2% | Feb 17, 2019 | An issue was discovered in the HDF HDF5 1.10.4 library. There is an out of bounds read in the function H5T_get_size in H... |
| CVE-2019-8397 | — | — | 1.2% | Feb 17, 2019 | An issue was discovered in the HDF HDF5 1.10.4 library. There is an out of bounds read in the function H5T_close_real in... |
| CVE-2019-8396 | — | — | 1.3% | Feb 17, 2019 | A buffer overflow in H5O__layout_encode in H5Olayout.c in the HDF HDF5 through 1.10.4 library allows attackers to cause ... |
| CVE-2019-8395 | — | — | 7.1% | Feb 17, 2019 | An Insecure Direct Object Reference (IDOR) vulnerability exists in Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 ... |
| CVE-2019-8394 | MEDIUM | 6.5 | 64.1% | Feb 17, 2019 | Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via l... |
| CVE-2019-8392 | — | — | 2.2% | Feb 17, 2019 | An issue was discovered on D-Link DIR-823G devices with firmware 1.02B03. There is incorrect access control allowing rem... |
| CVE-2019-7399 | — | — | 0.7% | Feb 17, 2019 | Amazon Fire OS before 5.3.6.4 allows a man-in-the-middle attack against HTTP requests for "Terms of Use" and Privacy pag... |
| CVE-2019-8389 | HIGH | 8.1 | 1.5% | Feb 17, 2019 | A file-read vulnerability was identified in the Wi-Fi transfer feature of Musicloud 1.6. By default, the application run... |
| CVE-2019-8383 | HIGH | 7.8 | 1.2% | Feb 17, 2019 | An issue was discovered in AdvanceCOMP through 2.1. An invalid memory address occurs in the function adv_png_unfilter_8 ... |
| CVE-2019-8382 | — | — | 1.6% | Feb 17, 2019 | An issue was discovered in Bento4 1.5.1-628. A NULL pointer dereference occurs in the function AP4_List:Find located in ... |
| CVE-2019-8381 | HIGH | 7.8 | 1.0% | Feb 17, 2019 | An issue was discovered in Tcpreplay 4.3.1. An invalid memory access occurs in do_checksum in checksum.c. It can be trig... |
| CVE-2019-8380 | — | — | 1.6% | Feb 17, 2019 | An issue was discovered in Bento4 1.5.1-628. A NULL pointer dereference occurs in AP4_Track::GetSampleIndexForTimeStampM... |
| CVE-2019-8379 | HIGH | 7.8 | 1.2% | Feb 17, 2019 | An issue was discovered in AdvanceCOMP through 2.1. A NULL pointer dereference exists in the function be_uint32_read() l... |
| CVE-2019-8378 | — | — | 1.6% | Feb 17, 2019 | An issue was discovered in Bento4 1.5.1-628. A heap-based buffer over-read exists in AP4_BitStream::ReadBytes() in Codec... |
| CVE-2019-8377 | HIGH | 7.8 | 1.3% | Feb 17, 2019 | An issue was discovered in Tcpreplay 4.3.1. A NULL pointer dereference occurred in the function get_ipv6_l4proto() locat... |
| CVE-2019-8376 | HIGH | 7.8 | 1.3% | Feb 17, 2019 | An issue was discovered in Tcpreplay 4.3.1. A NULL pointer dereference occurred in the function get_layer4_v6() located ... |
| CVE-2019-8363 | — | — | 0.8% | Feb 16, 2019 | Verydows 2.0 has XSS via the index.php?c=main a parameter, as demonstrated by an a=index[XSS] value. |
| CVE-2019-8362 | — | — | 1.5% | Feb 16, 2019 | DedeCMS through V5.7SP2 allows arbitrary file upload in dede/album_edit.php or dede/album_add.php, as demonstrated by a ... |
| CVE-2019-8361 | — | — | 0.9% | Feb 16, 2019 | PHP Scripts Mall Responsive Video News Script has XSS via the Search Bar. This might, for example, be leveraged for HTML... |
| CVE-2019-8360 | — | — | 2.0% | Feb 16, 2019 | Themerig Find a Place CMS Directory 1.5 has SQL Injection via the find/assets/external/data_2.php cate parameter. |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now