Skip to main content

Year archive

CVEs published in 2019

Archive summary

17,305 CVEs published in 2019 — 2,593 Critical, 7,142 High, 7,228 Medium, 342 Low, 0 Unrated.

CVE-2019-5884

Published Jan 10, 2019

php/elFinder.class.php in elFinder before 2.1.45 leaks information if PHP's curl extension is enabled and safe_mode or open_basedir is not set.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20683

Published Jan 10, 2019

commands/rsync in Gitolite before 3.6.11, if .gitolite.rc enables rsync, mishandles the rsync command line, which allows attackers to have a "bad" impact by triggering use of an o…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2018-20682

Published Jan 9, 2019

Fork CMS 5.0.6 allows stored XSS via the private/en/settings facebook_admin_ids parameter (aka "Admin ids" input in the Facebook section).

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20681

Published Jan 9, 2019

mate-screensaver before 1.20.2 in MATE Desktop Environment allows physically proximate attackers to view screen content and possibly control applications. By unplugging and re-plu…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-16205

Published Jan 9, 2019

Cross-site scripting vulnerability in GROWI v3.2.3 and earlier allows remote attackers to inject arbitrary web script or HTML via New Page modal.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-16203

Published Jan 9, 2019

PgpoolAdmin 4.0 and earlier allows remote attackers to bypass the login authentication and obtain the administrative privilege of the PostgreSQL database via unspecified vectors.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-16202

Published Jan 9, 2019

Directory traversal vulnerability in cordova-plugin-ionic-webview versions prior to 2.2.0 (not including 2.0.0-beta.0, 2.0.0-beta.1, 2.0.0-beta.2, and 2.1.0-0) allows remote attac…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2018-16196

Published Jan 9, 2019

Multiple Yokogawa products that contain Vnet/IP Open Communication Driver (CENTUM CS 3000(R3.05.00 - R3.09.50), CENTUM CS 3000 Entry Class(R3.05.00 - R3.09.50), CENTUM VP(R4.01.00…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5

CVE-2018-16191

Published Jan 9, 2019

Open redirect vulnerability in EC-CUBE (EC-CUBE 3.0.0, EC-CUBE 3.0.1, EC-CUBE 3.0.2, EC-CUBE 3.0.3, EC-CUBE 3.0.4, EC-CUBE 3.0.5, EC-CUBE 3.0.6, EC-CUBE 3.0.7, EC-CUBE 3.0.8, EC-C…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-16188

Published Jan 9, 2019

SQL injection vulnerability in the RICOH Interactive Whiteboard D2200 V1.3 to V2.2, D5500 V1.3 to V2.2, D5510 V1.3 to V2.2, the display versions with RICOH Interactive Whiteboard…

CVSS 9.8 · Critical

CVE-2018-16187

Published Jan 9, 2019

The RICOH Interactive Whiteboard D2200 V1.3 to V2.2, D5500 V1.3 to V2.2, D5510 V1.3 to V2.2, the display versions with RICOH Interactive Whiteboard Controller Type1 V1.3 to V2.2 a…

CVSS 5.9 · Medium
Showing 16,926-16,950 of 17,305 CVEsPage 678 of 693