2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-14696 | — | — | 15.4% | Aug 6, 2019 | Open-School 3.0, and Community Edition 2.3, allows XSS via the osv/index.php?r=students/guardians/create id parameter. |
| CVE-2019-14346 | — | — | 2.7% | Aug 6, 2019 | Internal/Views/config.php in Schben Adive 2.0.7 allows admin/config CSRF to change a user password. |
| CVE-2019-14672 | — | — | 0.7% | Aug 5, 2019 | Firefly III 4.7.17.5 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the liability na... |
| CVE-2019-14671 | — | — | 0.5% | Aug 5, 2019 | Firefly III 4.7.17.3 is vulnerable to local file enumeration. An attacker can enumerate local files due to the lack of p... |
| CVE-2019-14670 | — | — | 0.8% | Aug 5, 2019 | Firefly III 4.7.17.3 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the bill name fi... |
| CVE-2019-14669 | — | — | 0.8% | Aug 5, 2019 | Firefly III 4.7.17.3 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the asset accoun... |
| CVE-2019-14668 | — | — | 0.8% | Aug 5, 2019 | Firefly III 4.7.17.3 is vulnerable to stored XSS due to the lack of filtration of user-supplied data in the transaction ... |
| CVE-2019-14667 | — | — | 1.3% | Aug 5, 2019 | Firefly III 4.7.17.4 is vulnerable to multiple stored XSS issues due to the lack of filtration of user-supplied data in ... |
| CVE-2019-14475 | — | — | 2.0% | Aug 5, 2019 | eQ-3 Homematic CCU2 2.47.15 and prior and CCU3 3.47.15 and prior use session IDs for authentication but lack authorizati... |
| CVE-2019-5502 | — | — | 0.9% | Aug 5, 2019 | SMB in Data ONTAP operating in 7-Mode versions prior to 8.2.5P3 has weak cryptography which when exploited could lead to... |
| CVE-2019-14665 | — | — | 0.8% | Aug 5, 2019 | Brandy 1.20.1 has a heap-based buffer overflow in define_array in variables.c via crafted BASIC source code. |
| CVE-2019-14550 | — | — | 1.1% | Aug 5, 2019 | An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed when a victim clicks on the Edit Dashboard feat... |
| CVE-2019-14549 | — | — | 1.1% | Aug 5, 2019 | An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed inside the title and breadcrumb of a newly form... |
| CVE-2019-14548 | — | — | 1.1% | Aug 5, 2019 | An issue was discovered in EspoCRM before 5.6.9. Stored XSS in the body of an Article was executed when a victim opens a... |
| CVE-2019-14547 | — | — | 1.1% | Aug 5, 2019 | An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed when a attacker sends an attachment to admin wi... |
| CVE-2019-14546 | — | — | 1.1% | Aug 5, 2019 | An issue was discovered in EspoCRM before 5.6.9. Stored XSS was executed on the Preference page as well as while sending... |
| CVE-2019-10994 | — | — | 0.9% | Aug 5, 2019 | Processing a specially crafted project file in LAquis SCADA 4.3.1.71 may trigger an out-of-bounds read, which may allow ... |
| CVE-2019-11198 | — | — | 1.1% | Aug 5, 2019 | Multiple cross-site scripting (XSS) vulnerabilities in Sitecore CMS 9.0.1 and earlier allow remote attackers to inject a... |
| CVE-2019-14348 | — | — | 21.1% | Aug 5, 2019 | The BearDev JoomSport plugin 3.3 for WordPress allows SQL injection to steal, modify, or delete database information via... |
| CVE-2019-14663 | — | — | 0.8% | Aug 5, 2019 | Brandy 1.20.1 has a stack-based buffer overflow in fileio_openin in fileio.c via crafted BASIC source code. |
| CVE-2019-14662 | — | — | 0.8% | Aug 5, 2019 | Brandy 1.20.1 has a stack-based buffer overflow in fileio_openout in fileio.c via crafted BASIC source code. |
| CVE-2019-14525 | — | — | 1.5% | Aug 5, 2019 | In Octopus Deploy 2019.4.0 through 2019.6.x before 2019.6.6, and 2019.7.x before 2019.7.6, an authenticated system admin... |
| CVE-2019-14521 | — | — | 2.4% | Aug 5, 2019 | The api/admin/logoupload Logo File upload feature in EMCA Energy Logserver 6.1.2 allows attackers to send any kind of fi... |
| CVE-2019-14655 | — | — | — | Aug 5, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2019-14654 | — | — | 2.3% | Aug 5, 2019 | In Joomla! 3.9.7 and 3.9.8, inadequate filtering allows users authorised to create custom fields to manipulate the filte... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now