2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-8308Flatpak before 1.0.7, and 1.1.x and 1.2.x before 1.2.3, exposes /proc in the apply_extra script sandbox, which allows at...
CVE-2019-7550In JForum 2.1.8, an unauthenticated, remote attacker can enumerate whether a user exists by using the "create user" func...
CVE-2019-1688HIGH7.1A vulnerability in the management web interface of Cisco Network Assurance Engine (NAE) could allow an unauthenticated, ...
CVE-2019-7744An issue was discovered in Joomla! before 3.9.3. Inadequate filtering on URL fields in various core components could lea...
CVE-2019-7743An issue was discovered in Joomla! before 3.9.3. The phar:// stream wrapper can be used for objection injection attacks ...
CVE-2019-7742An issue was discovered in Joomla! before 3.9.3. A combination of specific web server configurations, in connection with...
CVE-2019-7741An issue was discovered in Joomla! before 3.9.3. Inadequate checks at the Global Configuration helpurl settings allowed ...
CVE-2019-7740An issue was discovered in Joomla! before 3.9.3. Inadequate parameter handling in JavaScript code (core.js writeDynaList...
CVE-2019-7739An issue was discovered in Joomla! before 3.9.3. The "No Filtering" textfilter overrides child settings in the Global Co...
CVE-2019-6549HIGH7.2An attacker could retrieve plain-text credentials stored in a XML file on PR100088 Modbus gateway versions prior to Rele...
CVE-2019-6533CRITICAL9.1Registers used to store Modbus values can be read and written from the web interface without authentication in the PR100...
CVE-2019-6527CRITICAL9.8PR100088 Modbus gateway versions prior to Release R02 (or Software Version 1.1.13166) may allow an attacker to be able t...
CVE-2019-7753Verydows 2.0 has XSS via the index.php?m=api&c=stats&a=count referrer parameter.
CVE-2019-5596In FreeBSD 11.2-STABLE after r338618 and before r343786, 12.0-STABLE before r343781, and 12.0-RELEASE before 12.0-RELEAS...
CVE-2019-5595In FreeBSD before 11.2-STABLE(r343782), 11.2-RELEASE-p9, 12.0-STABLE(r343781), and 12.0-RELEASE-p3, kernel callee-save r...
CVE-2019-3923Nessus versions 8.2.1 and earlier were found to contain a stored XSS vulnerability due to improper validation of user-su...
CVE-2019-7748_includes\online.php in DbNinja 3.2.7 allows XSS via the data.php task parameter if _users/admin/tasks.php exists.
CVE-2019-7747DbNinja 3.2.7 allows session fixation via the data.php sessid parameter.
CVE-2019-7738C.P.Sub before 5.3 allows CSRF via a manage.php?p=article_del&id= URI.
CVE-2019-7737A CSRF vulnerability was found in Verydows v2.0 that can add an admin account via index.php?m=backend&c=admin&a=add&step...
CVE-2019-6489Certain Lexmark CX, MX, X, XC, XM, XS, and 6500e devices before 2019-02-11 allow remote attackers to erase stored shortc...
CVE-2019-5736HIGH8.6runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b...
CVE-2019-7736D-Link DIR-600M C1 3.04 devices allow authentication bypass via a direct request to the wan.htm page. NOTE: this may ove...
CVE-2019-7733In Live555 0.95, there is a buffer overflow via a large integer in a Content-Length HTTP header because handleRequestByt...
CVE-2019-7732In Live555 0.95, a setup packet can cause a memory leak leading to DoS because, when there are multiple instances of a s...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now