2019 CVE Vulnerabilities

17,624 CVEs published in 2019.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2019-12397——Policy import functionality in Apache Ranger 0.7.0 to 1.2.0 is vulnerable to a cross-site scripting issue. Upgrade to 2....
CVE-2019-5301——Huawei smart phones Honor V20 with the versions before 9.0.1.161(C00E161R2P2) have an information leak vulnerability. An...
CVE-2019-5239——Huawei PCManager with the versions before 9.0.1.66 (Oversea) and versions before 9.0.1.70 (China) have an information le...
CVE-2019-5238——Huawei PCManager with the versions before 9.0.1.66 (Oversea) and versions before 9.0.1.70 (China) have a code execution ...
CVE-2019-5237——Huawei PCManager with the versions before 9.0.1.66 (Oversea) and versions before 9.0.1.70 (China) have a code execution ...
CVE-2019-5236——Huawei smart phones Emily-L29C with versions of 8.1.0.132a(C432), 8.1.0.135(C782), 8.1.0.154(C10), 8.1.0.154(C461), 8.1....
CVE-2019-13176——An issue was discovered in the 3CX Phone system (web) management console 12.5.44178.1002 through 12.5 SP2. The Content.M...
CVE-2019-14772——verdaccio before 3.12.0 allows XSS.
CVE-2019-14754——Open-School 3.0, and Community Edition 2.3, allows SQL Injection via the index.php?r=students/students/document id param...
CVE-2019-14255——A Server Side Request Forgery (SSRF) vulnerability in go-camo up to version 1.1.4 allows a remote attacker to perform HT...
CVE-2019-14221——1CRM On-Premise Software 8.5.7 allows XSS via a payload that is mishandled during a Run Report operation.
CVE-2019-14771——Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3 allows the upload of entire-site configuration archives throu...
CVE-2019-14770——In Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3, some menu links within the administration bar may be craf...
CVE-2019-14769——Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3 doesn't sufficiently filter output when displaying certain bl...
CVE-2019-14474——eQ-3 Homematic CCU3 3.47.15 and prior has Improper Input Validation in function 'Call()' of ReGa core logic process, res...
CVE-2019-14537——YOURLS through 1.7.3 is affected by a type juggling vulnerability in the api component that can result in login bypass.
CVE-2019-11653——Remote Access Control Bypass in Micro Focus Content Manager. versions 9.1, 9.2, 9.3. The vulnerability could be exploite...
CVE-2019-14747——DWSurvey through 2019-07-22 has stored XSS via the design/my-survey-design!copySurvey.action surveyName parameter.
CVE-2019-14746——A issue was discovered in KuaiFanCMS 5.0. It allows eval injection by placing PHP code in the install.php db_name parame...
CVE-2019-14743——In Valve Steam Client for Windows through 2019-08-07, HKLM\SOFTWARE\Wow6432Node\Valve\Steam has explicit "Full control" ...
CVE-2019-14432——Incorrect authentication of application WebSocket connections in Loom Desktop for Mac up to 0.16.0 allows remote code ex...
CVE-2019-10368——A cross-site request forgery vulnerability in Jenkins JClouds Plugin 2.14 and earlier in BlobStoreProfile.DescriptorImpl...
CVE-2019-14731——An issue was discovered in ZenTao 11.5.1. There is an XSS (stored) vulnerability that leads to the capture of other peop...
CVE-2019-14709——A cleartext password storage issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. The...
CVE-2019-14708——An issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. A buffer overflow in the acti...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now