2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-7296typora through 0.9.64 has XSS, with resultant remote command execution, during inline rendering of a mathematical formul...
CVE-2019-7295typora through 0.9.63 has XSS, with resultant remote command execution, during block rendering of a mathematical formula...
CVE-2019-7283HIGH7.4An issue was discovered in rcp in NetKit through 0.17. For an rcp operation, the server chooses which files/directories ...
CVE-2019-7282MEDIUM5.9In NetKit through 0.17, rcp.c in the rcp client allows remote rsh servers to bypass intended access restrictions via the...
CVE-2019-6111MEDIUM5.9An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses wh...
CVE-2019-6110MEDIUM6.8In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-T...
CVE-2019-6109MEDIUM6.8An issue was discovered in OpenSSH 7.9. Due to missing character encoding in the progress display, a malicious server (o...
CVE-2019-4040MEDIUM6.1IBM I 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript c...
CVE-2019-7250An issue was discovered in the Cross Reference Add-on 36 for Google Docs. Stored XSS in the preview boxes in the configu...
CVE-2019-7249In Keybase before 2.12.6 on macOS, the move RPC to the Helper was susceptible to time-to-check-time-to-use bugs and woul...
CVE-2019-7216An issue was discovered in FileChucker 4.99e-free-e02. filechucker.cgi has a filter bypass that allows a malicious user ...
CVE-2019-6438SchedMD Slurm before 17.11.13 and 18.x before 18.08.5 mishandles 32-bit systems.
CVE-2019-0190HIGH7.5A bug exists in the way mod_ssl handled client renegotiations. A remote attacker could send a carefully crafted request ...
CVE-2019-7237An issue was discovered in idreamsoft iCMS 7.0.13 on Windows. editor/editor.admincp.php allows admincp.php?app=files&do=...
CVE-2019-7236An issue was discovered in idreamsoft iCMS 7.0.13. editor/editor.admincp.php allows admincp.php?app=editor&do=fileManage...
CVE-2019-7235An issue was discovered in idreamsoft iCMS 7.0.13. admincp.php?app=apps&do=save allows directory traversal via _app=/../...
CVE-2019-7234An issue was discovered in idreamsoft iCMS 7.0.13. admincp.php?app=apps&do=save allows directory traversal via _app=/../...
CVE-2019-7233In libdoc through 2019-01-28, doc2text in catdoc.c has a NULL pointer dereference.
CVE-2019-3913MEDIUM4.9Command manipulation in LabKey Server Community Edition before 18.3.0-61806.763 allows an authenticated remote attacker ...
CVE-2019-3912MEDIUM6.1An open redirect vulnerability in LabKey Server Community Edition before 18.3.0-61806.763 via the /__r1/ returnURL param...
CVE-2019-3911MEDIUM6.1Reflected cross-site scripting (XSS) vulnerability in LabKey Server Community Edition before 18.3.0-61806.763 allows an ...
CVE-2019-1566MEDIUM6.1The PAN-OS management web interface in PAN-OS 7.1.21 and earlier, PAN-OS 8.0.14 and earlier, and PAN-OS 8.1.5 and earlie...
CVE-2019-1565The PAN-OS external dynamics lists in PAN-OS 7.1.21 and earlier, PAN-OS 8.0.14 and earlier, and PAN-OS 8.1.5 and earlier...
CVE-2019-7173A stored-self XSS exists in Croogo through v3.0.5, allowing an attacker to execute HTML or JavaScript code in a vulnerab...
CVE-2019-7172A stored-self XSS exists in ATutor through v2.2.4, allowing an attacker to execute HTML or JavaScript code in a vulnerab...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now