2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-14653 | — | — | 0.8% | Aug 3, 2019 | pandao Editor.md 1.5.0 allows XSS via an attribute of an ABBR or SUP element. |
| CVE-2019-14551 | — | — | 1.1% | Aug 3, 2019 | Das Q before 2019-08-02 allows web sites to execute arbitrary code on client machines, as demonstrated by a cross-origin... |
| CVE-2019-7951 | — | — | 1.2% | Aug 2, 2019 | An information leakage vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prio... |
| CVE-2019-7950 | — | — | 2.2% | Aug 2, 2019 | An access control bypass vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 pr... |
| CVE-2019-7947 | — | — | 0.4% | Aug 2, 2019 | A cross-site request forgery vulnerability exists in the GiftCardAccount removal feature for Magento Open Source prior t... |
| CVE-2019-7945 | — | — | 0.6% | Aug 2, 2019 | A stored cross-cite scripting vulnerability exists in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior t... |
| CVE-2019-7944 | — | — | 0.6% | Aug 2, 2019 | A stored cross-site scripting vulnerability exists in the product comments field of Magento Open Source prior to 1.9.4.2... |
| CVE-2019-7942 | — | — | 1.9% | Aug 2, 2019 | A remote code execution vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 pri... |
| CVE-2019-7940 | — | — | 0.6% | Aug 2, 2019 | A stored cross-site scripting vulnerability exists in the admin panel of Magento Open Source prior to 1.9.4.2, and Magen... |
| CVE-2019-7939 | — | — | 1.0% | Aug 2, 2019 | A reflected cross-site scripting vulnerability exists on the customer cart checkout page of Magento 2.1 prior to 2.1.18,... |
| CVE-2019-7938 | — | — | 0.6% | Aug 2, 2019 | A stored cross-site scripting vulnerability exists in the admin panel of Magento Open Source prior to 1.9.4.2, and Magen... |
| CVE-2019-7937 | — | — | 0.6% | Aug 2, 2019 | A stored cross-site scripting vulnerability exists in the admin panel of Magento 2.1 prior to 2.1.18, Magento 2.2 prior ... |
| CVE-2019-7936 | — | — | 0.6% | Aug 2, 2019 | A stored cross-site scripting vulnerability exists in the admin panel of Magento 2.1 prior to 2.1.18, Magento 2.2 prior ... |
| CVE-2019-7935 | — | — | 0.6% | Aug 2, 2019 | A stored cross-site scripting vulnerability exists in the admin panel of Magento Open Source prior to 1.9.4.2, and Magen... |
| CVE-2019-7934 | — | — | 0.6% | Aug 2, 2019 | A stored cross-site scripting vulnerability exists in the admin panel of Magento Open Source prior to 1.9.4.2, and Magen... |
| CVE-2019-7932 | — | — | 2.4% | Aug 2, 2019 | A remote code execution vulnerability exists in Magento Open Source prior to 1.9.4.2, and Magento Commerce prior to 1.14... |
| CVE-2019-7930 | — | — | 2.4% | Aug 2, 2019 | A file upload restriction bypass exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to... |
| CVE-2019-7929 | — | — | 1.2% | Aug 2, 2019 | An information leakage vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prio... |
| CVE-2019-7928 | — | — | 1.2% | Aug 2, 2019 | A denial-of-service (DoS) vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 p... |
| CVE-2019-7927 | — | — | 0.6% | Aug 2, 2019 | A stored cross-site scripting vulnerability exists in the admin panel of Magento 2.1 prior to 2.1.18, Magento 2.2 prior ... |
| CVE-2019-7926 | — | — | 0.6% | Aug 2, 2019 | A stored cross-site scripting vulnerability exists in the admin panel of Magento 2.1 prior to 2.1.18, Magento 2.2 prior ... |
| CVE-2019-7925 | — | — | 0.7% | Aug 2, 2019 | An insecure direct object reference (IDOR) vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2... |
| CVE-2019-7923 | — | — | 1.4% | Aug 2, 2019 | A server-side request forgery (SSRF) vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Ma... |
| CVE-2019-7921 | — | — | 0.6% | Aug 2, 2019 | A stored cross-site scripting vulnerability exists in the product catalog form of Magento 2.1 prior to 2.1.18, Magento 2... |
| CVE-2019-7915 | — | — | 1.2% | Aug 2, 2019 | A denial-of-service vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior t... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now