2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-15106 | — | — | 25.5% | Aug 16, 2019 | An issue was discovered in Zoho ManageEngine OpManager in builds before 14310. One can bypass the user password requirem... |
| CVE-2019-15105 | — | — | 7.8% | Aug 16, 2019 | An issue was discovered in Zoho ManageEngine Application Manager through 14.2. There is a SQL Injection vulnerability in... |
| CVE-2019-15104 | — | — | 7.8% | Aug 16, 2019 | An issue was discovered in Zoho ManageEngine OpManager through 12.4x. There is a SQL Injection vulnerability in jsp/NewT... |
| CVE-2019-15095 | — | — | 0.9% | Aug 16, 2019 | DWSurvey through 2019-07-22 has reflected XSS via the design/qu-multi-fillblank!answers.action surveyId parameter. |
| CVE-2019-15084 | — | — | 0.9% | Aug 16, 2019 | Realtek Waves MaxxAudio driver 1.6.2.0, as used on Dell laptops, installs with incorrect file permissions. As a result, ... |
| CVE-2019-10081 | — | — | 14.6% | Aug 15, 2019 | HTTP/2 (2.4.20 through 2.4.39) very early pushes, for example configured with "H2PushResource", could lead to an overwri... |
| CVE-2019-12792 | — | — | 4.9% | Aug 15, 2019 | A command injection vulnerability in UploadHandler.php in Vesta Control Panel 0.9.8-24 allows remote attackers to escala... |
| CVE-2019-12791 | — | — | 6.5% | Aug 15, 2019 | A directory traversal vulnerability in the v-list-user script in Vesta Control Panel 0.9.8-24 allows remote attackers to... |
| CVE-2019-3974 | — | — | 1.8% | Aug 15, 2019 | Nessus 8.5.2 and earlier on Windows platforms were found to contain an issue where certain system files could be overwri... |
| CVE-2019-13515 | — | — | 1.3% | Aug 15, 2019 | OSIsoft PI Web API 2018 and prior may allow disclosure of sensitive information. |
| CVE-2019-13510 | — | — | 12.0% | Aug 15, 2019 | Rockwell Automation Arena Simulation Software versions 16.00.00 and earlier contain a USE AFTER FREE CWE-416. A maliciou... |
| CVE-2019-14422 | — | — | 16.4% | Aug 15, 2019 | An issue was discovered in in TortoiseSVN 1.12.1. The Tsvncmd: URI handler allows a customised diff operation on Excel w... |
| CVE-2019-11187 | — | — | 1.7% | Aug 15, 2019 | Incorrect Access Control in the LDAP class of GONICUS GOsa through 2019-04-11 allows an attacker to log into any account... |
| CVE-2019-14789 | — | — | 1.9% | Aug 15, 2019 | The Custom 404 Pro plugin 3.2.8 for WordPress has XSS via the wp-admin/admin.php?page=c4p-main page parameter. |
| CVE-2019-14784 | — | — | 0.9% | Aug 15, 2019 | The "CP Contact Form with PayPal" plugin before 1.2.98 for WordPress has XSS in CSS edition. |
| CVE-2019-14518 | — | — | 1.2% | Aug 15, 2019 | Evolution CMS 2.0.x allows XSS via a description and new category location in a template. NOTE: the vendor states that t... |
| CVE-2019-14800 | — | — | 1.5% | Aug 15, 2019 | The FV Flowplayer Video Player plugin before 7.3.15.727 for WordPress allows guests to obtain the email subscription lis... |
| CVE-2019-14795 | — | — | 1.0% | Aug 15, 2019 | The toggle-the-title (aka Toggle The Title) plugin 1.4 for WordPress has XSS via the wp-admin/admin-ajax.php?action=upda... |
| CVE-2019-14790 | — | — | 1.4% | Aug 15, 2019 | The limb-gallery (aka Limb Gallery) plugin 1.4.0 for WordPress has XSS via the wp-admin/admin-ajax.php?action=grsGallery... |
| CVE-2019-14755 | — | — | 1.7% | Aug 15, 2019 | The profile photo upload feature in Leaf Admin 61.9.0212.10 f allows Unrestricted Upload of a File with a Dangerous Type... |
| CVE-2019-15062 | — | — | 0.6% | Aug 14, 2019 | An issue was discovered in Dolibarr 11.0.0-alpha. A user can store an IFRAME element (containing a user/card.php CSRF re... |
| CVE-2019-14427 | — | — | 1.0% | Aug 14, 2019 | XSS exists in WEB STUDIO Ultimate Loan Manager 2.0 by adding a branch under the Branches button that sets the notes para... |
| CVE-2019-9585 | — | — | 2.7% | Aug 14, 2019 | eQ-3 Homematic CCU2 prior to 2.47.10 and CCU3 prior to 3.47.10 JSON API has Improper Access Control for Interface.***Met... |
| CVE-2019-9584 | — | — | 2.7% | Aug 14, 2019 | eQ-3 Homematic AddOn 'CloudMatic' on CCU2 and CCU3 allows uncontrolled admin access, resulting in the ability to obtain ... |
| CVE-2019-1258 | — | — | 3.8% | Aug 14, 2019 | An elevation of privilege vulnerability exists in Azure Active Directory Authentication Library On-Behalf-Of flow, in th... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now