2019 CVE Vulnerabilities

17,624 CVEs published in 2019.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2019-14965——An issue was discovered in Frappe Framework 10 through 12 before 12.0.4. A server side template injection (SSTI) issue e...
CVE-2019-13462——Lansweeper before 7.1.117.4 allows unauthenticated SQL injection.
CVE-2019-12618——HashiCorp Nomad 0.9.0 through 0.9.1 has Incorrect Access Control via the exec driver.
CVE-2019-14951——The Telenav Scout GPS Link app 1.x for iOS, as used with Toyota and Lexus vehicles, has an incorrect protection mechanis...
CVE-2019-14947——The ultimate-member plugin before 2.0.52 for WordPress has XSS during an account upgrade.
CVE-2019-14946——The ultimate-member plugin before 2.0.52 for WordPress has XSS related to UM Roles create and edit operations.
CVE-2019-14945——The ultimate-member plugin before 2.0.54 for WordPress has XSS.
CVE-2019-14950——The wp-live-chat-support plugin before 8.0.27 for WordPress has XSS via the GDPR page.
CVE-2019-14932——The Recruitment module in Humanica Humatrix 7 1.0.0.681 and 1.0.0.203 allows remote attackers to access all candidates' ...
CVE-2019-14940——In Storage Performance Development Kit (SPDK) before 19.07, a user of a vhost can cause a crash if the target is sent in...
CVE-2019-14939——An issue was discovered in the mysql (aka mysqljs) module 2.17.1 for Node.js. The LOAD DATA LOCAL INFILE option is open ...
CVE-2019-14935——3CX Phone 15 on Windows has insecure permissions on the "%PROGRAMDATA%\3CXPhone for Windows\PhoneApp" installation direc...
CVE-2019-14933——Bagisto 0.1.5 allows CSRF under /admin URIs.
CVE-2019-14924——An issue was discovered in GCDWebServer before 3.5.3. The method moveItem in the GCDWebUploader class checks the FileExt...
CVE-2019-14357——On Mooltipass Mini devices, a side channel for the row-based OLED display was found. The power consumption of each row-b...
CVE-2019-14355——On ShapeShift KeepKey devices, a side channel for the row-based OLED display was found. The power consumption of each ro...
CVE-2019-14354——On Ledger Nano S and Nano X devices, a side channel for the row-based OLED display was found. The power consumption of e...
CVE-2019-5498——OnCommand Insight versions through 7.3.6 may disclose sensitive account information to an authenticated user.
CVE-2019-5408——Command View Advanced Edition (CVAE) products contain a vulnerability that could expose configuration information of hos...
CVE-2019-5407——A remote information disclosure vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media ve...
CVE-2019-5406——A remote session reuse vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s):...
CVE-2019-5405——A remote authorization bypass vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media vers...
CVE-2019-5404——A remote script injection vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(...
CVE-2019-5403——A remote multiple cross-site scripting vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software M...
CVE-2019-5402——A remote authorization bypass vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media vers...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now