2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2019-15642rpc.cgi in Webmin through 1.920 allows authenticated Remote Code Execution via a crafted object name because unserialise...
CVE-2019-15641xmlrpc.cgi in Webmin through 1.930 allows authenticated XXE attacks. By default, only root, admin, and sysadm can access...
CVE-2019-15548An issue was discovered in the ncurses crate through 5.99.0 for Rust. There are instr and mvwinstr buffer overflows beca...
CVE-2019-15547An issue was discovered in the ncurses crate through 5.99.0 for Rust. There are format string issues in printw functions...
CVE-2019-15546An issue was discovered in the pancurses crate through 0.16.1 for Rust. printw and mvprintw have format string vulnerabi...
CVE-2019-15545An issue was discovered in the libp2p-core crate before 0.8.1 for Rust. Attackers can spoof ed25519 signatures.
CVE-2019-15543An issue was discovered in the slice-deque crate before 0.2.0 for Rust. There is memory corruption in certain allocation...
CVE-2019-15542An issue was discovered in the ammonia crate before 2.1.0 for Rust. There is uncontrolled recursion during HTML DOM tree...
CVE-2019-15533XENFCoreSharp before 2019-07-16 allows SQL injection in web/verify.php.
CVE-2019-15515Discourse 2.3.2 sends the CSRF token in the query string.
CVE-2019-15503cgi-cpn/xcoding/prontus_videocut.cgi in AltaVoz Prontus (aka ProntusCMS) through 12.0.3.0 has "Improper Neutralization o...
CVE-2019-13020The fetch API in Tightrope Media Carousel before 7.1.3 has CarouselAPI/v0/fetch?url= SSRF. This has two potential areas ...
CVE-2019-15640Limesurvey before 3.17.10 does not validate both the MIME type and file extension of an image.
CVE-2019-15558XM^online 2 Common Utils and Endpoints 0.2.1 allows SQL injection, related to Constants.java, DropSchemaResolver.java, a...
CVE-2019-15557XM^online 2 User Account and Authentication server 1.0.0 allows SQL injection via a tenant key.
CVE-2019-15555FredReinink Wellness-app before 2019-06-19 allows SQL injection, related to dietTrack.php, exerciseGenerator.php, fitnes...
CVE-2019-15549An issue was discovered in the asn1_der crate before 0.6.2 for Rust. Attackers can trigger memory exhaustion by supplyin...
CVE-2019-15560The Reviews Module before 2019-06-14 for OpenSource Table allows SQL injection in database/index.js.
CVE-2019-15559DianoxDragon Hawn before 2019-07-10 allows SQL injection.
CVE-2019-15574Gesior-AAC before 2019-05-01 allows serviceID SQL injection in accountmanagement.php.
CVE-2019-15573Gesior-AAC before 2019-05-01 allows SQL injection in tankyou.php.
CVE-2019-15572Gesior-AAC before 2019-05-01 allows ServiceCategoryID SQL injection in shop.php.
CVE-2019-15571The WEB control panel before 2019-04-30 for ClonOS allows SQL injection in clonos.php.
CVE-2019-15570BEdita through 4.0.0-RC2 allows SQL injection during a save operation for a relation with parameters.
CVE-2019-15569HM Courts & Tribunals ccd-data-store-api before 2019-06-10 allows SQL injection, related to SearchQueryFactoryOperation....

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now