2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-18416MEDIUM6.1Sourcecodester Restaurant Management System 1.0 allows XSS via the Last Name field of a member.
CVE-2019-18415MEDIUM6.1Sourcecodester Restaurant Management System 1.0 allows XSS via the "send a message" screen.
CVE-2019-12094MEDIUM6.1Horde Groupware Webmail Edition through 5.2.22 allows XSS via an admin/user.php?form=update_f&user_name= or admin/user.p...
CVE-2019-9699MEDIUM4.5Symantec Messaging Gateway (prior to 10.7.0), may be susceptible to an information disclosure issue, which is a type of ...
CVE-2019-18196MEDIUM6.7A DLL side loading vulnerability in the Windows Service in TeamViewer versions up to 11.0.133222 (fixed in 11.0.214397),...
CVE-2019-18199MEDIUM6.6An issue was discovered on Fujitsu Wireless Keyboard Set LX390 GK381 devices. Because of the lack of proper encryption o...
CVE-2019-17581MEDIUM6.1tonyy dormsystem through 1.3 allows DOM XSS.
CVE-2019-4486MEDIUM5.4IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrar...
CVE-2019-4459MEDIUM5.4IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise 2.5 through 2.5.0.9 and 2.4 through 2.4.0.5 is vulnerable t...
CVE-2019-4397MEDIUM6.5IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise 2.5 through 2.5.0.9 and 2.4 through 2.4.0.5 stores sensitiv...
CVE-2019-18393MEDIUM5.3PluginServlet.java in Ignite Realtime Openfire through 4.4.2 does not ensure that retrieved files are located under the ...
CVE-2019-18212MEDIUM6.5XMLLanguageService.java in XML Language Server (aka lsp4xml) before 0.9.1, as used in Red Hat XML Language Support (aka ...
CVE-2019-18384MEDIUM6.5An issue was discovered on TerraMaster FS-210 4.0.19 devices. An authenticated remote non-administrative user can read u...
CVE-2019-18359MEDIUM5.5A buffer over-read was discovered in ReadMP3APETag in apetag.c in MP3Gain 1.6.2. The vulnerability causes an application...
CVE-2019-12415MEDIUM5.5In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a spe...
CVE-2019-9597MEDIUM6.5Darktrace Enterprise Immune System before 3.1 allows CSRF via the /config endpoint.
CVE-2019-9596MEDIUM6.5Darktrace Enterprise Immune System before 3.1 allows CSRF via the /whitelisteddomains endpoint.
CVE-2019-6144MEDIUM6.5This vulnerability allows a normal (non-admin) user to disable the Forcepoint One Endpoint (versions 19.04 through 19.08...
CVE-2019-3982MEDIUM6.5Nessus versions 8.6.0 and earlier were found to contain a Denial of Service vulnerability due to improper validation of ...
CVE-2019-18357MEDIUM6.1An XSS issue was discovered in Thycotic Secret Server before 10.7 (issue 2 of 2).
CVE-2019-18356MEDIUM6.1An XSS issue was discovered in Thycotic Secret Server before 10.7 (issue 1 of 2).
CVE-2019-18350MEDIUM6.1In Ant Design Pro 4.0.0, reflected XSS in the user/login redirect GET parameter affects the authorization component, lea...
CVE-2019-18348MEDIUM6.1An issue was discovered in urllib2 in Python 2.x through 2.7.17 and urllib in Python 3.x through 3.8.0. CRLF injection i...
CVE-2019-17606MEDIUM6.1The Post editor functionality in the hexo-admin plugin versions 2.3.0 and earlier for Node.js is vulnerable to stored XS...
CVE-2019-16977MEDIUM6.1In FusionPBX up to 4.5.7, the file app\extensions\extension_imports.php uses an unsanitized "query_string" variable comi...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now