2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-7874 | — | — | 0.4% | Aug 2, 2019 | A cross-site request forgery vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.... |
| CVE-2019-7873 | — | — | 0.4% | Aug 2, 2019 | A cross-site request forgery vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.... |
| CVE-2019-7872 | — | — | 0.9% | Aug 2, 2019 | An insecure direct object reference (IDOR) vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2... |
| CVE-2019-7871 | — | — | 1.3% | Aug 2, 2019 | A security bypass exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 that cou... |
| CVE-2019-7869 | — | — | 0.6% | Aug 2, 2019 | A stored cross-site scripting vulnerability exists in the admin panel of Magento 2.1 prior to 2.1.18, Magento 2.2 prior ... |
| CVE-2019-7868 | — | — | 0.6% | Aug 2, 2019 | A stored cross-site scripting vulnerability exists in the admin panel of Magento 2.1 prior to 2.1.18, Magento 2.2 prior ... |
| CVE-2019-7867 | — | — | 0.6% | Aug 2, 2019 | A stored cross-site scripting vulnerability exists in the admin panel of Magento 2.1 prior to 2.1.18, Magento 2.2 prior ... |
| CVE-2019-7866 | — | — | 0.6% | Aug 2, 2019 | A stored cross-site scripting vulnerability exists in the admin panel of Magento 2.1 prior to 2.1.18, Magento 2.2 prior ... |
| CVE-2019-7865 | — | — | 0.5% | Aug 2, 2019 | A cross-site request forgery (CSRF) vulnerability exists in the checkout cart item of Magento 2.1 prior to 2.1.18, Magen... |
| CVE-2019-7864 | — | — | 0.9% | Aug 2, 2019 | An insecure direct object reference (IDOR) vulnerability exists in the RSS feeds of Magento 2.1 prior to 2.1.18, Magento... |
| CVE-2019-7863 | — | — | 0.6% | Aug 2, 2019 | A stored cross-site scripting vulnerability exists in the admin panel for Magento 2.1 prior to 2.1.18, Magento 2.2 prior... |
| CVE-2019-7862 | — | — | 0.6% | Aug 2, 2019 | A reflected cross-site scripting vulnerability exists in the Product widget chooser functionality in the admin panel for... |
| CVE-2019-7861 | — | — | 2.0% | Aug 2, 2019 | Insufficient server-side validation of user input could allow an attacker to bypass file upload restrictions in Magento ... |
| CVE-2019-7860 | — | — | 1.2% | Aug 2, 2019 | A cryptographically weak pseudo-rando number generator is used in multiple security relevant contexts in Magento 2.1 pri... |
| CVE-2019-7859 | — | — | 1.5% | Aug 2, 2019 | A path traversal vulnerability in the WYSIWYG editor for Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magent... |
| CVE-2019-7858 | — | — | 0.7% | Aug 2, 2019 | A cryptographic flaw in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9 and Magento 2.3 prior to 2.3.2 resulted ... |
| CVE-2019-7857 | — | — | 0.4% | Aug 2, 2019 | A cross-site request forgery vulnerability in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior... |
| CVE-2019-7855 | — | — | 1.0% | Aug 2, 2019 | A cryptograhic flaw in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 could be abus... |
| CVE-2019-7854 | — | — | 1.1% | Aug 2, 2019 | An insecure direct object reference (IDOR) vulnerability in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Mag... |
| CVE-2019-7853 | — | — | 0.6% | Aug 2, 2019 | A stored cross-site scripting vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2... |
| CVE-2019-7852 | — | — | 0.9% | Aug 2, 2019 | A path disclosure vulnerability exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to ... |
| CVE-2019-7851 | — | — | 0.4% | Aug 2, 2019 | A cross-site request forgery vulnerability in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior... |
| CVE-2019-7849 | — | — | 1.2% | Aug 2, 2019 | A defense-in-depth check was added to mitigate inadequate session validation handling by 3rd party checkout modules. Thi... |
| CVE-2019-14544 | — | — | 1.5% | Aug 2, 2019 | routes/api/v1/api.go in Gogs 0.11.86 lacks permission checks for routes: deploy keys, collaborators, and hooks. |
| CVE-2019-7163 | — | — | 2.1% | Aug 2, 2019 | The web interface of Alcatel LINKZONE MW40-V-V1.0 MW40_LU_02.00_02 devices is vulnerable to an authentication bypass tha... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now