2019 CVE Vulnerabilities

17,624 CVEs published in 2019.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2019-3963——In OpenEMR 5.0.1 and earlier, controller.php contains a reflected XSS vulnerability in the patient_id parameter. This co...
CVE-2019-15238——The cforms2 plugin before 15.0.2 for WordPress has CSRF related to the IP address field.
CVE-2019-15291——An issue was discovered in the Linux kernel through 5.2.9. There is a NULL pointer dereference caused by a malicious USB...
CVE-2019-15290——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-15098. Reason: This candidate is a duplicate of ...
CVE-2019-15082——The 360-product-rotation plugin before 1.4.8 for WordPress has reflected XSS.
CVE-2019-14687——A DLL hijacking vulnerability exists in Trend Micro Password Manager 5.0 in which, if exploited, would allow an attacker...
CVE-2019-14684——A DLL hijacking vulnerability exists in Trend Micro Password Manager 5.0 in which, if exploited, would allow an attacker...
CVE-2019-14430——plugin/Audit/Objects/AuditTable.php in YouPHPTube through 7.2 allows SQL Injection.
CVE-2019-11806——OX App Suite 7.10.1 and earlier has Insecure Permissions.
CVE-2019-11522——OX App Suite 7.10.0 to 7.10.2 allows XSS.
CVE-2019-11521——OX App Suite 7.10.1 allows Content Spoofing.
CVE-2019-12889——An unauthenticated privilege escalation exists in SailPoint Desktop Password Reset 7.2. A user with local access to only...
CVE-2019-15239——In the Linux kernel, a certain net/ipv4/tcp_output.c change, which was properly incorporated into 4.16.12, was incorrect...
CVE-2019-15227——FlightPath 4.8.3 has XSS in the Content, Edit urgent message, and Users sections of the Admin Console. This could lead t...
CVE-2019-15231——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-15107. Reason: This candidate is a duplicate of ...
CVE-2019-15229——FUEL CMS 1.4.4 has CSRF in the blocks/create/ Create Blocks section of the Admin console. This could lead to an attacker...
CVE-2019-15228——FUEL CMS 1.4.4 has XSS in the Create Blocks section of the Admin console. This could lead to cookie stealing and other m...
CVE-2019-15225——In Envoy through 1.11.1, users may configure a route to match incoming path headers via the libstdc++ regular expression...
CVE-2019-15224——The rest-client gem 1.6.10 through 1.6.13 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor i...
CVE-2019-11163——Insufficient access control in a hardware abstraction driver for Intel(R) Processor Identification Utility for Windows b...
CVE-2019-11162——Insufficient access control in hardware abstraction in SEMA driver for Intel(R) Computing Improvement Program before ver...
CVE-2019-11148——Improper permissions in the installer for Intel(R) Remote Displays SDK before version 2.0.1 R2 may allow an authenticate...
CVE-2019-11146——Improper file verification in Intel® Driver & Support Assistant before 19.7.30.2 may allow an authenticated user to pote...
CVE-2019-11143——Improper permissions in the software installer for Intel(R) Authenticate before 3.8 may allow an authenticated user to p...
CVE-2019-11140——Insufficient session validation in system firmware for Intel(R) NUC may allow a privileged user to potentially enable es...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now