2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2019-15106An issue was discovered in Zoho ManageEngine OpManager in builds before 14310. One can bypass the user password requirem...
CVE-2019-15105An issue was discovered in Zoho ManageEngine Application Manager through 14.2. There is a SQL Injection vulnerability in...
CVE-2019-15104An issue was discovered in Zoho ManageEngine OpManager through 12.4x. There is a SQL Injection vulnerability in jsp/NewT...
CVE-2019-15095DWSurvey through 2019-07-22 has reflected XSS via the design/qu-multi-fillblank!answers.action surveyId parameter.
CVE-2019-15084Realtek Waves MaxxAudio driver 1.6.2.0, as used on Dell laptops, installs with incorrect file permissions. As a result, ...
CVE-2019-10081HTTP/2 (2.4.20 through 2.4.39) very early pushes, for example configured with "H2PushResource", could lead to an overwri...
CVE-2019-12792A command injection vulnerability in UploadHandler.php in Vesta Control Panel 0.9.8-24 allows remote attackers to escala...
CVE-2019-12791A directory traversal vulnerability in the v-list-user script in Vesta Control Panel 0.9.8-24 allows remote attackers to...
CVE-2019-3974Nessus 8.5.2 and earlier on Windows platforms were found to contain an issue where certain system files could be overwri...
CVE-2019-13515OSIsoft PI Web API 2018 and prior may allow disclosure of sensitive information.
CVE-2019-13510Rockwell Automation Arena Simulation Software versions 16.00.00 and earlier contain a USE AFTER FREE CWE-416. A maliciou...
CVE-2019-14422An issue was discovered in in TortoiseSVN 1.12.1. The Tsvncmd: URI handler allows a customised diff operation on Excel w...
CVE-2019-11187Incorrect Access Control in the LDAP class of GONICUS GOsa through 2019-04-11 allows an attacker to log into any account...
CVE-2019-14789The Custom 404 Pro plugin 3.2.8 for WordPress has XSS via the wp-admin/admin.php?page=c4p-main page parameter.
CVE-2019-14784The "CP Contact Form with PayPal" plugin before 1.2.98 for WordPress has XSS in CSS edition.
CVE-2019-14518Evolution CMS 2.0.x allows XSS via a description and new category location in a template. NOTE: the vendor states that t...
CVE-2019-14800The FV Flowplayer Video Player plugin before 7.3.15.727 for WordPress allows guests to obtain the email subscription lis...
CVE-2019-14795The toggle-the-title (aka Toggle The Title) plugin 1.4 for WordPress has XSS via the wp-admin/admin-ajax.php?action=upda...
CVE-2019-14790The limb-gallery (aka Limb Gallery) plugin 1.4.0 for WordPress has XSS via the wp-admin/admin-ajax.php?action=grsGallery...
CVE-2019-14755The profile photo upload feature in Leaf Admin 61.9.0212.10 f allows Unrestricted Upload of a File with a Dangerous Type...
CVE-2019-15062An issue was discovered in Dolibarr 11.0.0-alpha. A user can store an IFRAME element (containing a user/card.php CSRF re...
CVE-2019-14427XSS exists in WEB STUDIO Ultimate Loan Manager 2.0 by adding a branch under the Branches button that sets the notes para...
CVE-2019-9585eQ-3 Homematic CCU2 prior to 2.47.10 and CCU3 prior to 3.47.10 JSON API has Improper Access Control for Interface.***Met...
CVE-2019-9584eQ-3 Homematic AddOn 'CloudMatic' on CCU2 and CCU3 allows uncontrolled admin access, resulting in the ability to obtain ...
CVE-2019-1258An elevation of privilege vulnerability exists in Azure Active Directory Authentication Library On-Behalf-Of flow, in th...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now