2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-15568 | — | — | 1.4% | Aug 26, 2019 | idseq-web before 2019-07-01 in Infectious Disease Sequencing Platform IDseq allows SQL injection via tax_levels. |
| CVE-2019-15567 | — | — | 1.4% | Aug 26, 2019 | OpenForis Arena before 2019-05-07 allows SQL injection in the sorting feature. |
| CVE-2019-15566 | — | — | 1.6% | Aug 26, 2019 | The Alfresco application before 1.8.7 for Android allows SQL injection in HistorySearchProvider.java. |
| CVE-2019-15565 | — | — | 1.5% | Aug 26, 2019 | The ICOMMKT connector before 1.0.7 for PrestaShop allows SQL injection in icommktconnector.php. |
| CVE-2019-15564 | — | — | 1.4% | Aug 26, 2019 | The Compassion Switzerland addons 10.01.4 for Odoo allow SQL injection in models/partner_compassion.py. |
| CVE-2019-15563 | — | — | 1.9% | Aug 26, 2019 | Observational Health Data Sciences and Informatics (OHDSI) WebAPI before 2.7.2 allows SQL injection in FeatureExtraction... |
| CVE-2019-15554 | — | — | 2.1% | Aug 26, 2019 | An issue was discovered in the smallvec crate before 0.6.10 for Rust. There is memory corruption for certain grow attemp... |
| CVE-2019-15553 | — | — | 1.8% | Aug 26, 2019 | An issue was discovered in the memoffset crate before 0.5.0 for Rust. offset_of and span_of can cause exposure of uninit... |
| CVE-2019-15552 | — | — | 2.5% | Aug 26, 2019 | An issue was discovered in the libflate crate before 0.1.25 for Rust. MultiDecoder::read has a use-after-free, leading t... |
| CVE-2019-15551 | — | — | 1.9% | Aug 26, 2019 | An issue was discovered in the smallvec crate before 0.6.10 for Rust. There is a double free for certain grow attempts w... |
| CVE-2019-15501 | — | — | 8.2% | Aug 26, 2019 | Reflected cross site scripting (XSS) in L-Soft LISTSERV before 16.5-2018a exists via the /scripts/wa.exe OK parameter. |
| CVE-2019-15479 | — | — | 0.8% | Aug 26, 2019 | Status Board 1.1.81 has reflected XSS via dashboard.ts. |
| CVE-2019-15561 | — | — | 1.4% | Aug 26, 2019 | FlashLingo before 2019-06-12 allows SQL injection, related to flashlingo.js and db.js. |
| CVE-2019-15556 | — | — | 1.4% | Aug 26, 2019 | Pvanloon1983 social_network before 2019-07-03 allows SQL injection in includes/form_handlers/register_handler.php. |
| CVE-2019-15524 | — | — | 3.1% | Aug 26, 2019 | CSZ CMS 1.2.3 allows arbitrary file upload, as demonstrated by a .php file to admin/filemanager in the File Management M... |
| CVE-2019-15521 | — | — | 2.5% | Aug 26, 2019 | Spoon Library through 2014-02-06, as used in Fork CMS before 1.4.1 and other products, allows PHP object injection via a... |
| CVE-2019-15304 | — | — | 3.4% | Aug 26, 2019 | Lierda Grill Temperature Monitor V1.00_50006 has a default password of admin for the admin account, which allows an atta... |
| CVE-2019-15541 | — | — | 2.2% | Aug 26, 2019 | rustls-mio/examples/tlsserver.rs in the rustls crate before 0.16.0 for Rust allows attackers to cause a denial of servic... |
| CVE-2019-15534 | — | — | 1.4% | Aug 26, 2019 | Raml-Module-Builder 26.4.0 allows SQL Injection in PostgresClient.update. |
| CVE-2019-15532 | — | — | 1.3% | Aug 26, 2019 | CyberChef before 8.31.2 allows XSS in core/operations/TextEncodingBruteForce.mjs. |
| CVE-2019-15506 | — | — | 1.8% | Aug 26, 2019 | An issue was discovered in Kaseya Virtual System Administrator (VSA) through 9.4.0.37. It has a critical information dis... |
| CVE-2019-15489 | — | — | 0.9% | Aug 26, 2019 | laracom (aka Laravel FREE E-Commerce Software) 1.4.11 has search?q= XSS. |
| CVE-2019-15478 | — | — | 0.8% | Aug 26, 2019 | Status Board 1.1.81 has reflected XSS via logic.ts. |
| CVE-2019-15540 | — | — | 0.6% | Aug 25, 2019 | filters/filter-cso/filter-stream.c in the CSO filter in libMirage 3.2.2 in CDemu does not validate the part size, trigge... |
| CVE-2019-5594 | — | — | 0.7% | Aug 23, 2019 | An Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") in Fortinet FortiNAC 8.3.0 to 8.... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now