2019 CVE Vulnerabilities

17,624 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-4602MEDIUM5.4IBM Quality Manager (RQM) 6.02, 6.06, and 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users...
CVE-2019-4601MEDIUM4.3IBM Quality Manager (RQM) 6.02, 6.06, and 6.0.6.1 could allow an authenticated user to obtain sensitive information from...
CVE-2019-20636MEDIUM6.7In the Linux kernel before 5.4.12, drivers/input/input.c has out-of-bounds writes via a crafted keycode table, as demons...
CVE-2019-15789HIGH7.8Privilege escalation vulnerability in MicroK8s allows a low privilege user with local access to obtain root access to th...
CVE-2019-17657HIGH7.5An Uncontrolled Resource Consumption vulnerability in Fortinet FortiSwitch below 3.6.11, 6.0.6 and 6.2.2, FortiAnalyzer ...
CVE-2019-13559HIGH7.8GE Mark VIe Controller is shipped with pre-configured hard-coded credentials that may allow root-user access to the cont...
CVE-2019-13554HIGH8.8GE Mark VIe Controller has an unsecured Telnet protocol that may allow a user to create an authenticated session using g...
CVE-2019-4393CRITICAL9.8HCL AppScan Standard is vulnerable to excessive authorization attempts
CVE-2019-4391HIGH8.2HCL AppScan Standard is vulnerable to XML External Entity Injection (XXE) attack when processing XML data
CVE-2019-19699HIGH7.2There is Authenticated remote code execution in Centreon Infrastructure Monitoring Software through 19.10 via Pollers mi...
CVE-2019-17231MEDIUM6.1includes/theme-functions.php in the OneTone theme through 3.0.6 for WordPress has multiple stored XSS issues.
CVE-2019-17230MEDIUM5.3includes/theme-functions.php in the OneTone theme through 3.0.6 for WordPress allows unauthenticated options changes.
CVE-2019-18905MEDIUM5.9A Insufficient Verification of Data Authenticity vulnerability in autoyast2 of SUSE Linux Enterprise Server 12, SUSE Lin...
CVE-2019-18904HIGH7.5A Uncontrolled Resource Consumption vulnerability in rmt of SUSE Linux Enterprise High Performance Computing 15-ESPOS, S...
CVE-2019-19914——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2019-19348HIGH7An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/apb-base, affecting ...
CVE-2019-19346HIGH7An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/mariadb-apb, affecti...
CVE-2019-19097HIGH7.5ABB eSOMS versions 4.0 to 6.0.3 accept connections using medium strength ciphers. If a connection is enabled using such ...
CVE-2019-19096MEDIUM6.1The Redis data structure component used in ABB eSOMS versions 6.0 to 6.0.2 stores credentials in clear text. If an attac...
CVE-2019-19095MEDIUM5.4Lack of adequate input/output validation for ABB eSOMS versions 4.0 to 6.0.2 might allow an attacker to attack such as s...
CVE-2019-19094HIGH7.6Lack of input checks for SQL queries in ABB eSOMS versions 3.9 to 6.0.3 might allow an attacker SQL injection attacks ag...
CVE-2019-19093MEDIUM6.5eSOMS versions 4.0 to 6.0.3 do not enforce password complexity settings, potentially resulting in lower access security ...
CVE-2019-19092LOW3.5ABB eSOMS versions 4.0 to 6.0.3 use ASP.NET Viewstate without Message Authentication Code (MAC). Alterations to Viewstat...
CVE-2019-19091MEDIUM4.3For ABB eSOMS versions 4.0 to 6.0.3, HTTPS responses contain comments with sensitive information about the application. ...
CVE-2019-19090LOW3.5For ABB eSOMS versions 4.0 to 6.0.2, the Secure Flag is not set in the HTTP response header. Unencrypted connections mig...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now