2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-7731 | — | — | 4.2% | Feb 11, 2019 | MyWebSQL 3.7 has a remote code execution (RCE) vulnerability after an attacker writes shell code into the database, and ... |
| CVE-2019-7730 | — | — | 0.4% | Feb 11, 2019 | MyWebSQL 3.7 has a Cross-site request forgery (CSRF) vulnerability for deleting a database via the /?q=wrkfrm&type=datab... |
| CVE-2019-7722 | — | — | 1.2% | Feb 11, 2019 | PMD 5.8.1 and earlier processes XML external entities in ruleset files it parses as part of the analysis process, allowi... |
| CVE-2019-6975 | — | — | 5.4% | Feb 11, 2019 | Django 1.11.x before 1.11.19, 2.0.x before 2.0.11, and 2.1.x before 2.1.6 allows Uncontrolled Memory Consumption via a m... |
| CVE-2019-7721 | — | — | 1.2% | Feb 11, 2019 | lib/NCCms.class.php in nc-cms 3.5 allows upload of .php files via the index.php?action=save name and editordata paramete... |
| CVE-2019-7720 | — | — | 1.6% | Feb 11, 2019 | taocms through 2014-05-24 allows eval injection by placing PHP code in the install.php db_name parameter and then making... |
| CVE-2019-7719 | — | — | 1.7% | Feb 11, 2019 | Nibbleblog 4.0.5 allows eval injection by placing PHP code in the install.php username parameter and then making a conte... |
| CVE-2019-7718 | — | — | 1.0% | Feb 11, 2019 | An issue was discovered in Metinfo 6.x. An attacker can leverage a race condition in the backend database backup functio... |
| CVE-2019-7704 | MEDIUM | 6.5 | 1.2% | Feb 10, 2019 | wasm::WasmBinaryBuilder::readUserSection in wasm-binary.cpp in Binaryen 1.38.22 triggers an attempt at excessive memory ... |
| CVE-2019-7703 | MEDIUM | 6.5 | 1.5% | Feb 10, 2019 | In Binaryen 1.38.22, there is a use-after-free problem in wasm::WasmBinaryBuilder::visitCall in wasm-binary.cpp. Remote ... |
| CVE-2019-7702 | MEDIUM | 6.5 | 1.1% | Feb 10, 2019 | A NULL pointer dereference was discovered in wasm::SExpressionWasmBuilder::parseExpression in wasm-s-parser.cpp in Binar... |
| CVE-2019-7701 | MEDIUM | 6.5 | 1.2% | Feb 10, 2019 | A heap-based buffer over-read was discovered in wasm::SExpressionParser::skipWhitespace() in wasm-s-parser.cpp in Binary... |
| CVE-2019-7700 | MEDIUM | 6.5 | 1.2% | Feb 10, 2019 | A heap-based buffer over-read was discovered in wasm::WasmBinaryBuilder::visitCall in wasm-binary.cpp in Binaryen 1.38.2... |
| CVE-2019-7699 | — | — | 1.5% | Feb 10, 2019 | A heap-based buffer over-read occurs in AP4_BitStream::WriteBytes in Codecs/Ap4BitStream.cpp in Bento4 v1.5.1-627. Remot... |
| CVE-2019-7698 | — | — | 1.2% | Feb 10, 2019 | An issue was discovered in AP4_Array<AP4_CttsTableEntry>::EnsureCapacity in Core/Ap4Array.h in Bento4 1.5.1-627. Crafted... |
| CVE-2019-7697 | — | — | 1.1% | Feb 10, 2019 | An issue was discovered in Bento4 v1.5.1-627. There is an assertion failure in AP4_AtomListWriter::Action in Core/Ap4Ato... |
| CVE-2019-7693 | — | — | 0.9% | Feb 10, 2019 | Axios Italia Axios RE 1.7.0/7.0.0 devices have XSS via the RELogOff.aspx Error_Parameters parameter. In some situations,... |
| CVE-2019-7692 | — | — | 2.2% | Feb 10, 2019 | install/install.php in CIM 0.9.3 allows remote attackers to execute arbitrary PHP code via a crafted prefix value becaus... |
| CVE-2019-7684 | — | — | 2.1% | Feb 9, 2019 | inxedu through 2018-12-24 has a vulnerability that can lead to the upload of a malicious JSP file. The vulnerable code l... |
| CVE-2019-7678 | — | — | 2.5% | Feb 9, 2019 | A directory traversal vulnerability was discovered in Enphase Envoy R3.*.* via images/, include/, include/js, or include... |
| CVE-2019-7677 | — | — | 0.9% | Feb 9, 2019 | XSS exists in Enphase Envoy R3.*.* via the profileName parameter to the /home URI on TCP port 8888. |
| CVE-2019-7676 | — | — | 1.7% | Feb 9, 2019 | A weak password vulnerability was discovered in Enphase Envoy R3.*.*. One can login via TCP port 8888 with the admin pas... |
| CVE-2019-7675 | — | — | 1.1% | Feb 9, 2019 | An issue was discovered on MOBOTIX S14 MX-V4.2.1.61 devices. The default management application is delivered over cleart... |
| CVE-2019-7674 | — | — | 1.3% | Feb 9, 2019 | An issue was discovered on MOBOTIX S14 MX-V4.2.1.61 devices. /admin/access accepts a request to set the "aaaaa" password... |
| CVE-2019-7673 | — | — | 0.9% | Feb 9, 2019 | An issue was discovered on MOBOTIX S14 MX-V4.2.1.61 devices. Administrator Credentials are stored in the 13-character DE... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now