2019 CVE Vulnerabilities

17,624 CVEs published in 2019.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2019-7969——Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a type confusion vulnerability. Successful ex...
CVE-2019-7968——Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a command injection vulnerability. Successful...
CVE-2019-15642——rpc.cgi in Webmin through 1.920 allows authenticated Remote Code Execution via a crafted object name because unserialise...
CVE-2019-15641——xmlrpc.cgi in Webmin through 1.930 allows authenticated XXE attacks. By default, only root, admin, and sysadm can access...
CVE-2019-15548——An issue was discovered in the ncurses crate through 5.99.0 for Rust. There are instr and mvwinstr buffer overflows beca...
CVE-2019-15547——An issue was discovered in the ncurses crate through 5.99.0 for Rust. There are format string issues in printw functions...
CVE-2019-15546——An issue was discovered in the pancurses crate through 0.16.1 for Rust. printw and mvprintw have format string vulnerabi...
CVE-2019-15545——An issue was discovered in the libp2p-core crate before 0.8.1 for Rust. Attackers can spoof ed25519 signatures.
CVE-2019-15543——An issue was discovered in the slice-deque crate before 0.2.0 for Rust. There is memory corruption in certain allocation...
CVE-2019-15542——An issue was discovered in the ammonia crate before 2.1.0 for Rust. There is uncontrolled recursion during HTML DOM tree...
CVE-2019-15533——XENFCoreSharp before 2019-07-16 allows SQL injection in web/verify.php.
CVE-2019-15515——Discourse 2.3.2 sends the CSRF token in the query string.
CVE-2019-15503——cgi-cpn/xcoding/prontus_videocut.cgi in AltaVoz Prontus (aka ProntusCMS) through 12.0.3.0 has "Improper Neutralization o...
CVE-2019-13020——The fetch API in Tightrope Media Carousel before 7.1.3 has CarouselAPI/v0/fetch?url= SSRF. This has two potential areas ...
CVE-2019-15640——Limesurvey before 3.17.10 does not validate both the MIME type and file extension of an image.
CVE-2019-15558——XM^online 2 Common Utils and Endpoints 0.2.1 allows SQL injection, related to Constants.java, DropSchemaResolver.java, a...
CVE-2019-15557——XM^online 2 User Account and Authentication server 1.0.0 allows SQL injection via a tenant key.
CVE-2019-15555——FredReinink Wellness-app before 2019-06-19 allows SQL injection, related to dietTrack.php, exerciseGenerator.php, fitnes...
CVE-2019-15549——An issue was discovered in the asn1_der crate before 0.6.2 for Rust. Attackers can trigger memory exhaustion by supplyin...
CVE-2019-15560——The Reviews Module before 2019-06-14 for OpenSource Table allows SQL injection in database/index.js.
CVE-2019-15559——DianoxDragon Hawn before 2019-07-10 allows SQL injection.
CVE-2019-15574——Gesior-AAC before 2019-05-01 allows serviceID SQL injection in accountmanagement.php.
CVE-2019-15573——Gesior-AAC before 2019-05-01 allows SQL injection in tankyou.php.
CVE-2019-15572——Gesior-AAC before 2019-05-01 allows ServiceCategoryID SQL injection in shop.php.
CVE-2019-15571——The WEB control panel before 2019-04-30 for ClonOS allows SQL injection in clonos.php.

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now