2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-20849MEDIUM5.3An issue was discovered in Mattermost Mobile Apps before 1.26.0. Cookie data can persist on a device after a logout.
CVE-2019-20848HIGH7.5An issue was discovered in Mattermost Mobile Apps before 1.26.0. The Quick Reply feature mishandles crafted replies.
CVE-2019-20847MEDIUM5.3An issue was discovered in Mattermost Server before 5.18.0. An attacker can send a user_typing WebSocket event to any ch...
CVE-2019-20846HIGH7.5An issue was discovered in Mattermost Server before 5.18.0. It has weak permissions for server-local file storage.
CVE-2019-20845HIGH7.5An issue was discovered in Mattermost Server before 5.18.0. It allows attackers to cause a denial of service (memory con...
CVE-2019-20844MEDIUM6.5An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. An attacker can spoof a d...
CVE-2019-20843HIGH7.5An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. There are weak permission...
CVE-2019-20842HIGH7.2An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. There is SQL injection by...
CVE-2019-20841HIGH8.8An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. CSRF can sometimes occur ...
CVE-2019-13033LOW3.3In CISOfy Lynis 2.x through 2.7.5, the license key can be obtained by looking at the process list when a data upload is ...
CVE-2019-9944HIGH7.5In Open Microscopy Environment OMERO.server 5.0.0 through 5.6.0, the reading of files from imported image filesets may c...
CVE-2019-9943HIGH7.5In ome.services.graphs.GraphTraversal.findObjectDetails in Open Microscopy Environment OMERO.server 5.1.0 through 5.6.0,...
CVE-2019-16245MEDIUM5.3OMERO before 5.6.1 makes the details of each user available to all users.
CVE-2019-20840HIGH7.5An issue was discovered in LibVNCServer before 0.9.13. libvncserver/ws_decode.c can lead to a crash because of unaligned...
CVE-2019-20839HIGH7.5libvncclient/sockets.c in LibVNCServer before 0.9.13 has a buffer overflow via a long socket filename.
CVE-2019-17655HIGH7.5A cleartext storage in a file or on disk (CWE-313) vulnerability in FortiOS SSL VPN 6.2.0 through 6.2.2, 6.0.9 and earli...
CVE-2019-18614HIGH7.8On the Cypress CYW20735 evaluation board, any data that exceeds 384 bytes is copied and causes an overflow. This is beca...
CVE-2019-20838HIGH7.5libpcre in PCRE before 8.43 allows a subject buffer over-read in JIT when UTF is disabled, and \X or \R has more than on...
CVE-2019-19112MEDIUM6.1The wpForo plugin 1.6.5 for WordPress allows XSS involving the wpf-dw-td-value class of dashboard.php.
CVE-2019-19111MEDIUM6.1The wpForo plugin 1.6.5 for WordPress allows XSS via the wp-admin/admin.php?page=wpforo-phrases langid parameter.
CVE-2019-19110MEDIUM4.8The wpForo plugin 1.6.5 for WordPress allows XSS via the wp-admin/admin.php?page=wpforo-phrases s parameter.
CVE-2019-19109HIGH8.8The wpForo plugin 1.6.5 for WordPress allows wp-admin/admin.php?page=wpforo-usergroups CSRF.
CVE-2019-16252MEDIUM5.9Missing SSL Certificate Validation in the Nutfind.com application through 3.9.12 for Android allows a man-in-the-middle ...
CVE-2019-15123HIGH7.2The Branding Module in Viki Vera 4.9.1.26180 allows an authenticated user to change the logo on the website. An attacker...
CVE-2019-5735Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now