2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-18416 | MEDIUM | 6.1 | 0.7% | Oct 24, 2019 | Sourcecodester Restaurant Management System 1.0 allows XSS via the Last Name field of a member. |
| CVE-2019-18415 | MEDIUM | 6.1 | 0.7% | Oct 24, 2019 | Sourcecodester Restaurant Management System 1.0 allows XSS via the "send a message" screen. |
| CVE-2019-12094 | MEDIUM | 6.1 | 1.5% | Oct 24, 2019 | Horde Groupware Webmail Edition through 5.2.22 allows XSS via an admin/user.php?form=update_f&user_name= or admin/user.p... |
| CVE-2019-9699 | MEDIUM | 4.5 | 0.5% | Oct 24, 2019 | Symantec Messaging Gateway (prior to 10.7.0), may be susceptible to an information disclosure issue, which is a type of ... |
| CVE-2019-18196 | MEDIUM | 6.7 | 0.6% | Oct 24, 2019 | A DLL side loading vulnerability in the Windows Service in TeamViewer versions up to 11.0.133222 (fixed in 11.0.214397),... |
| CVE-2019-18199 | MEDIUM | 6.6 | 0.4% | Oct 24, 2019 | An issue was discovered on Fujitsu Wireless Keyboard Set LX390 GK381 devices. Because of the lack of proper encryption o... |
| CVE-2019-17581 | MEDIUM | 6.1 | 0.7% | Oct 24, 2019 | tonyy dormsystem through 1.3 allows DOM XSS. |
| CVE-2019-4486 | MEDIUM | 5.4 | 0.7% | Oct 24, 2019 | IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrar... |
| CVE-2019-4459 | MEDIUM | 5.4 | 0.6% | Oct 24, 2019 | IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise 2.5 through 2.5.0.9 and 2.4 through 2.4.0.5 is vulnerable t... |
| CVE-2019-4397 | MEDIUM | 6.5 | 1.0% | Oct 24, 2019 | IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise 2.5 through 2.5.0.9 and 2.4 through 2.4.0.5 stores sensitiv... |
| CVE-2019-18393 | MEDIUM | 5.3 | 13.9% | Oct 24, 2019 | PluginServlet.java in Ignite Realtime Openfire through 4.4.2 does not ensure that retrieved files are located under the ... |
| CVE-2019-18212 | MEDIUM | 6.5 | 2.8% | Oct 23, 2019 | XMLLanguageService.java in XML Language Server (aka lsp4xml) before 0.9.1, as used in Red Hat XML Language Support (aka ... |
| CVE-2019-18384 | MEDIUM | 6.5 | 1.4% | Oct 23, 2019 | An issue was discovered on TerraMaster FS-210 4.0.19 devices. An authenticated remote non-administrative user can read u... |
| CVE-2019-18359 | MEDIUM | 5.5 | 1.4% | Oct 23, 2019 | A buffer over-read was discovered in ReadMP3APETag in apetag.c in MP3Gain 1.6.2. The vulnerability causes an application... |
| CVE-2019-12415 | MEDIUM | 5.5 | 1.0% | Oct 23, 2019 | In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a spe... |
| CVE-2019-9597 | MEDIUM | 6.5 | 1.0% | Oct 23, 2019 | Darktrace Enterprise Immune System before 3.1 allows CSRF via the /config endpoint. |
| CVE-2019-9596 | MEDIUM | 6.5 | 1.6% | Oct 23, 2019 | Darktrace Enterprise Immune System before 3.1 allows CSRF via the /whitelisteddomains endpoint. |
| CVE-2019-6144 | MEDIUM | 6.5 | 1.0% | Oct 23, 2019 | This vulnerability allows a normal (non-admin) user to disable the Forcepoint One Endpoint (versions 19.04 through 19.08... |
| CVE-2019-3982 | MEDIUM | 6.5 | 1.8% | Oct 23, 2019 | Nessus versions 8.6.0 and earlier were found to contain a Denial of Service vulnerability due to improper validation of ... |
| CVE-2019-18357 | MEDIUM | 6.1 | 0.8% | Oct 23, 2019 | An XSS issue was discovered in Thycotic Secret Server before 10.7 (issue 2 of 2). |
| CVE-2019-18356 | MEDIUM | 6.1 | 0.8% | Oct 23, 2019 | An XSS issue was discovered in Thycotic Secret Server before 10.7 (issue 1 of 2). |
| CVE-2019-18350 | MEDIUM | 6.1 | 1.1% | Oct 23, 2019 | In Ant Design Pro 4.0.0, reflected XSS in the user/login redirect GET parameter affects the authorization component, lea... |
| CVE-2019-18348 | MEDIUM | 6.1 | 3.5% | Oct 23, 2019 | An issue was discovered in urllib2 in Python 2.x through 2.7.17 and urllib in Python 3.x through 3.8.0. CRLF injection i... |
| CVE-2019-17606 | MEDIUM | 6.1 | 1.0% | Oct 23, 2019 | The Post editor functionality in the hexo-admin plugin versions 2.3.0 and earlier for Node.js is vulnerable to stored XS... |
| CVE-2019-16977 | MEDIUM | 6.1 | 0.7% | Oct 23, 2019 | In FusionPBX up to 4.5.7, the file app\extensions\extension_imports.php uses an unsanitized "query_string" variable comi... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now