2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-14327 | — | — | 0.6% | Jul 30, 2019 | A CSRF vulnerability in Settings form in the Custom Simple Rss plugin 2.0.6 for WordPress allows attackers to change the... |
| CVE-2019-13635 | — | — | 45.4% | Jul 30, 2019 | The WP Fastest Cache plugin through 0.8.9.5 for WordPress allows wpFastestCache.php and inc/cache.php Directory Traversa... |
| CVE-2019-3948 | — | — | 26.7% | Jul 29, 2019 | The Amcrest IP2M-841B V2.520.AC00.18.R, Dahua IPC-XXBXX V2.622.0000000.9.R, Dahua IPC HX5X3X and HX4X3X V2.800.0000008.0... |
| CVE-2019-13655 | — | — | 1.4% | Jul 29, 2019 | Imgix through 2019-06-19 allows remote attackers to cause a denial of service (resource consumption) by manipulating a s... |
| CVE-2019-6726 | — | — | 4.3% | Jul 29, 2019 | The WP Fastest Cache plugin through 0.8.9.0 for WordPress allows remote attackers to delete arbitrary files because wp_p... |
| CVE-2019-12948 | — | — | 1.7% | Jul 29, 2019 | A vulnerability in the web-based management interface of VVX, Trio, SoundStructure, SoundPoint, and SoundStation phones ... |
| CVE-2019-12743 | — | — | 1.5% | Jul 29, 2019 | HumHub Social Network Kit Enterprise v1.3.13 allows remote attackers to find the user accounts existing on any Social Ne... |
| CVE-2019-11201 | — | — | 2.2% | Jul 29, 2019 | Dolibarr ERP/CRM 9.0.1 provides a module named website that provides for creation of public websites with a WYSIWYG edit... |
| CVE-2019-11200 | — | — | 2.1% | Jul 29, 2019 | Dolibarr ERP/CRM 9.0.1 provides a web-based functionality that backs up the database content to a dump file. However, th... |
| CVE-2019-11199 | — | — | 1.0% | Jul 29, 2019 | Dolibarr ERP/CRM 9.0.1 was affected by stored XSS within uploaded files. These vulnerabilities allowed the execution of ... |
| CVE-2019-12613 | — | — | — | Jul 29, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn. Further inves... |
| CVE-2019-1020009 | — | — | 1.4% | Jul 29, 2019 | Fleet before 2.1.2 allows exposure of SMTP credentials. |
| CVE-2019-1020008 | — | — | 0.8% | Jul 29, 2019 | stacktable.js before 1.0.4 allows XSS. |
| CVE-2019-1020007 | — | — | 0.6% | Jul 29, 2019 | Dependency-Track before 3.5.1 allows XSS. |
| CVE-2019-1020006 | — | — | 0.9% | Jul 29, 2019 | invenio-app before 1.1.1 allows host header injection. |
| CVE-2019-1020005 | — | — | 0.7% | Jul 29, 2019 | invenio-communities before 1.0.0a20 allows XSS. |
| CVE-2019-1020004 | — | — | 1.2% | Jul 29, 2019 | Tridactyl before 1.16.0 allows fake key events. |
| CVE-2019-1020003 | — | — | 0.7% | Jul 29, 2019 | invenio-records before 1.2.2 allows XSS. |
| CVE-2019-1020002 | — | — | 1.5% | Jul 29, 2019 | Pterodactyl before 0.7.14 with 2FA allows credential sniffing. |
| CVE-2019-1105 | — | — | 1.8% | Jul 29, 2019 | A spoofing vulnerability exists in the way Microsoft Outlook for Android software parses specifically crafted email mess... |
| CVE-2019-1020019 | — | — | 0.9% | Jul 29, 2019 | invenio-previewer before 1.0.0a12 allows XSS. |
| CVE-2019-1020016 | — | — | 0.8% | Jul 29, 2019 | ASH-AIO before 2.0.0.3 allows an open redirect. |
| CVE-2019-1020015 | — | — | 1.2% | Jul 29, 2019 | graphql-engine (aka Hasura GraphQL Engine) before 1.0.0-beta.3 mishandles the audience check while verifying JWT. |
| CVE-2019-1020013 | — | — | 1.2% | Jul 29, 2019 | parse-server before 3.6.0 allows account enumeration. |
| CVE-2019-1020012 | — | — | 1.4% | Jul 29, 2019 | parse-server before 3.4.1 allows DoS after any POST to a volatile class. |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now