2019 CVE Vulnerabilities

17,624 CVEs published in 2019.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2019-15570——BEdita through 4.0.0-RC2 allows SQL injection during a save operation for a relation with parameters.
CVE-2019-15569——HM Courts & Tribunals ccd-data-store-api before 2019-06-10 allows SQL injection, related to SearchQueryFactoryOperation....
CVE-2019-15568——idseq-web before 2019-07-01 in Infectious Disease Sequencing Platform IDseq allows SQL injection via tax_levels.
CVE-2019-15567——OpenForis Arena before 2019-05-07 allows SQL injection in the sorting feature.
CVE-2019-15566——The Alfresco application before 1.8.7 for Android allows SQL injection in HistorySearchProvider.java.
CVE-2019-15565——The ICOMMKT connector before 1.0.7 for PrestaShop allows SQL injection in icommktconnector.php.
CVE-2019-15564——The Compassion Switzerland addons 10.01.4 for Odoo allow SQL injection in models/partner_compassion.py.
CVE-2019-15563——Observational Health Data Sciences and Informatics (OHDSI) WebAPI before 2.7.2 allows SQL injection in FeatureExtraction...
CVE-2019-15554——An issue was discovered in the smallvec crate before 0.6.10 for Rust. There is memory corruption for certain grow attemp...
CVE-2019-15553——An issue was discovered in the memoffset crate before 0.5.0 for Rust. offset_of and span_of can cause exposure of uninit...
CVE-2019-15552——An issue was discovered in the libflate crate before 0.1.25 for Rust. MultiDecoder::read has a use-after-free, leading t...
CVE-2019-15551——An issue was discovered in the smallvec crate before 0.6.10 for Rust. There is a double free for certain grow attempts w...
CVE-2019-15501——Reflected cross site scripting (XSS) in L-Soft LISTSERV before 16.5-2018a exists via the /scripts/wa.exe OK parameter.
CVE-2019-15479——Status Board 1.1.81 has reflected XSS via dashboard.ts.
CVE-2019-15561——FlashLingo before 2019-06-12 allows SQL injection, related to flashlingo.js and db.js.
CVE-2019-15556——Pvanloon1983 social_network before 2019-07-03 allows SQL injection in includes/form_handlers/register_handler.php.
CVE-2019-15524——CSZ CMS 1.2.3 allows arbitrary file upload, as demonstrated by a .php file to admin/filemanager in the File Management M...
CVE-2019-15521——Spoon Library through 2014-02-06, as used in Fork CMS before 1.4.1 and other products, allows PHP object injection via a...
CVE-2019-15304——Lierda Grill Temperature Monitor V1.00_50006 has a default password of admin for the admin account, which allows an atta...
CVE-2019-15541——rustls-mio/examples/tlsserver.rs in the rustls crate before 0.16.0 for Rust allows attackers to cause a denial of servic...
CVE-2019-15534——Raml-Module-Builder 26.4.0 allows SQL Injection in PostgresClient.update.
CVE-2019-15532——CyberChef before 8.31.2 allows XSS in core/operations/TextEncodingBruteForce.mjs.
CVE-2019-15506——An issue was discovered in Kaseya Virtual System Administrator (VSA) through 9.4.0.37. It has a critical information dis...
CVE-2019-15489——laracom (aka Laravel FREE E-Commerce Software) 1.4.11 has search?q= XSS.
CVE-2019-15478——Status Board 1.1.81 has reflected XSS via logic.ts.

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now