2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-7332Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaSc...
CVE-2019-7331Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3 while editing an existing monitor field nam...
CVE-2019-7330Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaSc...
CVE-2019-7329Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, as the form action on multiple views utilizes ...
CVE-2019-7328Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaSc...
CVE-2019-7327Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaSc...
CVE-2019-7326Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or Ja...
CVE-2019-7325Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, as multiple views under web/skins/classic/view...
CVE-2019-7324app/Core/Paginator.php in Kanboard before 1.2.8 has XSS in pagination sorting.
CVE-2019-3813HIGH7.5Spice, versions 0.5.2 through 0.14.1, are vulnerable to an out-of-bounds read due to an off-by-one error in memslot_get_...
CVE-2019-3461Debian tmpreaper version 1.6.13+nmu1 has a race condition when doing a (bind) mount via rename() which could result in l...
CVE-2019-7323GUP (generic update process) in LightySoft LogMX before 7.4.0 does not properly verify the authenticity of updates, whic...
CVE-2019-7317MEDIUM5.3png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called und...
CVE-2019-7316An issue was discovered in CSS-TRICKS Chat2 through 2015-05-05. The userid parameter in jumpin.php has a SQL injection v...
CVE-2019-7314liblivemedia in Live555 before 2019.02.03 mishandles the termination of an RTSP stream after RTP/RTCP-over-RTSP has been...
CVE-2019-7313www/resource.py in Buildbot before 1.8.1 allows CRLF injection in the Location header of /auth/login and /auth/logout vi...
CVE-2019-7312Limited plaintext disclosure exists in PRIMX Zed Entreprise for Windows before 6.1.2240, Zed Entreprise for Windows (ANS...
CVE-2019-7310HIGH7.8In Poppler 0.73.0, a heap-based buffer over-read (due to an integer signedness error in the XRef::getEntry function in X...
CVE-2019-7309In the GNU C Library (aka glibc or libc6) through 2.29, the memcmp function for the x32 architecture can incorrectly ret...
CVE-2019-7308kernel/bpf/verifier.c in the Linux kernel before 4.20.6 performs undesirable out-of-bounds speculation on pointer arithm...
CVE-2019-3604MEDIUM4.8Cross-Site Request Forgery (CSRF) vulnerability in McAfee ePO (legacy) Cloud allows unauthenticated users to perform uni...
CVE-2019-7301Zen Load Balancer 3.10.1 allows remote authenticated admin users to execute arbitrary commands as root via shell metacha...
CVE-2019-7300Artica Proxy 3.06.200056 allows remote attackers to execute arbitrary commands as root by reading the ressources/setting...
CVE-2019-7298An issue was discovered on D-Link DIR-823G devices with firmware through 1.02B03. A command Injection vulnerability allo...
CVE-2019-7297An issue was discovered on D-Link DIR-823G devices with firmware through 1.02B03. A command Injection vulnerability allo...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now