2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-17657 | HIGH | 7.5 | 2.4% | Apr 7, 2020 | An Uncontrolled Resource Consumption vulnerability in Fortinet FortiSwitch below 3.6.11, 6.0.6 and 6.2.2, FortiAnalyzer ... |
| CVE-2019-13559 | HIGH | 7.8 | 0.3% | Apr 7, 2020 | GE Mark VIe Controller is shipped with pre-configured hard-coded credentials that may allow root-user access to the cont... |
| CVE-2019-13554 | HIGH | 8.8 | 1.0% | Apr 7, 2020 | GE Mark VIe Controller has an unsecured Telnet protocol that may allow a user to create an authenticated session using g... |
| CVE-2019-4393 | CRITICAL | 9.8 | 1.0% | Apr 7, 2020 | HCL AppScan Standard is vulnerable to excessive authorization attempts |
| CVE-2019-4391 | HIGH | 8.2 | 1.2% | Apr 7, 2020 | HCL AppScan Standard is vulnerable to XML External Entity Injection (XXE) attack when processing XML data |
| CVE-2019-19699 | HIGH | 7.2 | 27.5% | Apr 6, 2020 | There is Authenticated remote code execution in Centreon Infrastructure Monitoring Software through 19.10 via Pollers mi... |
| CVE-2019-17231 | MEDIUM | 6.1 | 1.2% | Apr 3, 2020 | includes/theme-functions.php in the OneTone theme through 3.0.6 for WordPress has multiple stored XSS issues. |
| CVE-2019-17230 | MEDIUM | 5.3 | 2.1% | Apr 3, 2020 | includes/theme-functions.php in the OneTone theme through 3.0.6 for WordPress allows unauthenticated options changes. |
| CVE-2019-18905 | MEDIUM | 5.9 | 0.7% | Apr 3, 2020 | A Insufficient Verification of Data Authenticity vulnerability in autoyast2 of SUSE Linux Enterprise Server 12, SUSE Lin... |
| CVE-2019-18904 | HIGH | 7.5 | 1.5% | Apr 3, 2020 | A Uncontrolled Resource Consumption vulnerability in rmt of SUSE Linux Enterprise High Performance Computing 15-ESPOS, S... |
| CVE-2019-19914 | — | — | — | Apr 3, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2019-19348 | HIGH | 7 | 0.3% | Apr 2, 2020 | An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/apb-base, affecting ... |
| CVE-2019-19346 | HIGH | 7 | 0.3% | Apr 2, 2020 | An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/mariadb-apb, affecti... |
| CVE-2019-19097 | HIGH | 7.5 | 0.7% | Apr 2, 2020 | ABB eSOMS versions 4.0 to 6.0.3 accept connections using medium strength ciphers. If a connection is enabled using such ... |
| CVE-2019-19096 | MEDIUM | 6.1 | 0.3% | Apr 2, 2020 | The Redis data structure component used in ABB eSOMS versions 6.0 to 6.0.2 stores credentials in clear text. If an attac... |
| CVE-2019-19095 | MEDIUM | 5.4 | 0.6% | Apr 2, 2020 | Lack of adequate input/output validation for ABB eSOMS versions 4.0 to 6.0.2 might allow an attacker to attack such as s... |
| CVE-2019-19094 | HIGH | 7.6 | 0.9% | Apr 2, 2020 | Lack of input checks for SQL queries in ABB eSOMS versions 3.9 to 6.0.3 might allow an attacker SQL injection attacks ag... |
| CVE-2019-19093 | MEDIUM | 6.5 | 0.8% | Apr 2, 2020 | eSOMS versions 4.0 to 6.0.3 do not enforce password complexity settings, potentially resulting in lower access security ... |
| CVE-2019-19092 | LOW | 3.5 | 0.8% | Apr 2, 2020 | ABB eSOMS versions 4.0 to 6.0.3 use ASP.NET Viewstate without Message Authentication Code (MAC). Alterations to Viewstat... |
| CVE-2019-19091 | MEDIUM | 4.3 | 0.8% | Apr 2, 2020 | For ABB eSOMS versions 4.0 to 6.0.3, HTTPS responses contain comments with sensitive information about the application. ... |
| CVE-2019-19090 | LOW | 3.5 | 0.5% | Apr 2, 2020 | For ABB eSOMS versions 4.0 to 6.0.2, the Secure Flag is not set in the HTTP response header. Unencrypted connections mig... |
| CVE-2019-19089 | MEDIUM | 6.1 | 1.0% | Apr 2, 2020 | For ABB eSOMS versions 4.0 to 6.0.3, the X-Content-Type-Options Header is missing in the HTTP response, potentially caus... |
| CVE-2019-19003 | MEDIUM | 6.1 | 0.8% | Apr 2, 2020 | For ABB eSOMS versions 4.0 to 6.0.2, the HTTPOnly flag is not set. This can allow Javascript to access the cookie conten... |
| CVE-2019-19002 | MEDIUM | 5.4 | 0.8% | Apr 2, 2020 | For ABB eSOMS versions 4.0 to 6.0.2, the X-XSS-Protection HTTP response header is not set in responses from the web serv... |
| CVE-2019-19001 | MEDIUM | 6.5 | 1.5% | Apr 2, 2020 | For ABB eSOMS versions 4.0 to 6.0.2, the X-Frame-Options header is not configured in HTTP response. This can potentially... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now