2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-15642 | — | — | 38.0% | Aug 26, 2019 | rpc.cgi in Webmin through 1.920 allows authenticated Remote Code Execution via a crafted object name because unserialise... |
| CVE-2019-15641 | — | — | 1.5% | Aug 26, 2019 | xmlrpc.cgi in Webmin through 1.930 allows authenticated XXE attacks. By default, only root, admin, and sysadm can access... |
| CVE-2019-15548 | — | — | 1.6% | Aug 26, 2019 | An issue was discovered in the ncurses crate through 5.99.0 for Rust. There are instr and mvwinstr buffer overflows beca... |
| CVE-2019-15547 | — | — | 1.2% | Aug 26, 2019 | An issue was discovered in the ncurses crate through 5.99.0 for Rust. There are format string issues in printw functions... |
| CVE-2019-15546 | — | — | 1.1% | Aug 26, 2019 | An issue was discovered in the pancurses crate through 0.16.1 for Rust. printw and mvprintw have format string vulnerabi... |
| CVE-2019-15545 | — | — | 0.8% | Aug 26, 2019 | An issue was discovered in the libp2p-core crate before 0.8.1 for Rust. Attackers can spoof ed25519 signatures. |
| CVE-2019-15543 | — | — | 1.6% | Aug 26, 2019 | An issue was discovered in the slice-deque crate before 0.2.0 for Rust. There is memory corruption in certain allocation... |
| CVE-2019-15542 | — | — | 1.4% | Aug 26, 2019 | An issue was discovered in the ammonia crate before 2.1.0 for Rust. There is uncontrolled recursion during HTML DOM tree... |
| CVE-2019-15533 | — | — | 1.4% | Aug 26, 2019 | XENFCoreSharp before 2019-07-16 allows SQL injection in web/verify.php. |
| CVE-2019-15515 | — | — | 0.6% | Aug 26, 2019 | Discourse 2.3.2 sends the CSRF token in the query string. |
| CVE-2019-15503 | — | — | 2.4% | Aug 26, 2019 | cgi-cpn/xcoding/prontus_videocut.cgi in AltaVoz Prontus (aka ProntusCMS) through 12.0.3.0 has "Improper Neutralization o... |
| CVE-2019-13020 | — | — | 1.1% | Aug 26, 2019 | The fetch API in Tightrope Media Carousel before 7.1.3 has CarouselAPI/v0/fetch?url= SSRF. This has two potential areas ... |
| CVE-2019-15640 | — | — | 1.2% | Aug 26, 2019 | Limesurvey before 3.17.10 does not validate both the MIME type and file extension of an image. |
| CVE-2019-15558 | — | — | 1.4% | Aug 26, 2019 | XM^online 2 Common Utils and Endpoints 0.2.1 allows SQL injection, related to Constants.java, DropSchemaResolver.java, a... |
| CVE-2019-15557 | — | — | 1.5% | Aug 26, 2019 | XM^online 2 User Account and Authentication server 1.0.0 allows SQL injection via a tenant key. |
| CVE-2019-15555 | — | — | 1.4% | Aug 26, 2019 | FredReinink Wellness-app before 2019-06-19 allows SQL injection, related to dietTrack.php, exerciseGenerator.php, fitnes... |
| CVE-2019-15549 | — | — | 1.4% | Aug 26, 2019 | An issue was discovered in the asn1_der crate before 0.6.2 for Rust. Attackers can trigger memory exhaustion by supplyin... |
| CVE-2019-15560 | — | — | 1.4% | Aug 26, 2019 | The Reviews Module before 2019-06-14 for OpenSource Table allows SQL injection in database/index.js. |
| CVE-2019-15559 | — | — | 1.4% | Aug 26, 2019 | DianoxDragon Hawn before 2019-07-10 allows SQL injection. |
| CVE-2019-15574 | — | — | 1.4% | Aug 26, 2019 | Gesior-AAC before 2019-05-01 allows serviceID SQL injection in accountmanagement.php. |
| CVE-2019-15573 | — | — | 1.4% | Aug 26, 2019 | Gesior-AAC before 2019-05-01 allows SQL injection in tankyou.php. |
| CVE-2019-15572 | — | — | 1.4% | Aug 26, 2019 | Gesior-AAC before 2019-05-01 allows ServiceCategoryID SQL injection in shop.php. |
| CVE-2019-15571 | — | — | 1.4% | Aug 26, 2019 | The WEB control panel before 2019-04-30 for ClonOS allows SQL injection in clonos.php. |
| CVE-2019-15570 | — | — | 1.5% | Aug 26, 2019 | BEdita through 4.0.0-RC2 allows SQL injection during a save operation for a relation with parameters. |
| CVE-2019-15569 | — | — | 1.4% | Aug 26, 2019 | HM Courts & Tribunals ccd-data-store-api before 2019-06-10 allows SQL injection, related to SearchQueryFactoryOperation.... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now