2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2019-14327A CSRF vulnerability in Settings form in the Custom Simple Rss plugin 2.0.6 for WordPress allows attackers to change the...
CVE-2019-13635The WP Fastest Cache plugin through 0.8.9.5 for WordPress allows wpFastestCache.php and inc/cache.php Directory Traversa...
CVE-2019-3948The Amcrest IP2M-841B V2.520.AC00.18.R, Dahua IPC-XXBXX V2.622.0000000.9.R, Dahua IPC HX5X3X and HX4X3X V2.800.0000008.0...
CVE-2019-13655Imgix through 2019-06-19 allows remote attackers to cause a denial of service (resource consumption) by manipulating a s...
CVE-2019-6726The WP Fastest Cache plugin through 0.8.9.0 for WordPress allows remote attackers to delete arbitrary files because wp_p...
CVE-2019-12948A vulnerability in the web-based management interface of VVX, Trio, SoundStructure, SoundPoint, and SoundStation phones ...
CVE-2019-12743HumHub Social Network Kit Enterprise v1.3.13 allows remote attackers to find the user accounts existing on any Social Ne...
CVE-2019-11201Dolibarr ERP/CRM 9.0.1 provides a module named website that provides for creation of public websites with a WYSIWYG edit...
CVE-2019-11200Dolibarr ERP/CRM 9.0.1 provides a web-based functionality that backs up the database content to a dump file. However, th...
CVE-2019-11199Dolibarr ERP/CRM 9.0.1 was affected by stored XSS within uploaded files. These vulnerabilities allowed the execution of ...
CVE-2019-12613Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn. Further inves...
CVE-2019-1020009Fleet before 2.1.2 allows exposure of SMTP credentials.
CVE-2019-1020008stacktable.js before 1.0.4 allows XSS.
CVE-2019-1020007Dependency-Track before 3.5.1 allows XSS.
CVE-2019-1020006invenio-app before 1.1.1 allows host header injection.
CVE-2019-1020005invenio-communities before 1.0.0a20 allows XSS.
CVE-2019-1020004Tridactyl before 1.16.0 allows fake key events.
CVE-2019-1020003invenio-records before 1.2.2 allows XSS.
CVE-2019-1020002Pterodactyl before 0.7.14 with 2FA allows credential sniffing.
CVE-2019-1105A spoofing vulnerability exists in the way Microsoft Outlook for Android software parses specifically crafted email mess...
CVE-2019-1020019invenio-previewer before 1.0.0a12 allows XSS.
CVE-2019-1020016ASH-AIO before 2.0.0.3 allows an open redirect.
CVE-2019-1020015graphql-engine (aka Hasura GraphQL Engine) before 1.0.0-beta.3 mishandles the audience check while verifying JWT.
CVE-2019-1020013parse-server before 3.6.0 allows account enumeration.
CVE-2019-1020012parse-server before 3.4.1 allows DoS after any POST to a volatile class.

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now