2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-17657HIGH7.5An Uncontrolled Resource Consumption vulnerability in Fortinet FortiSwitch below 3.6.11, 6.0.6 and 6.2.2, FortiAnalyzer ...
CVE-2019-13559HIGH7.8GE Mark VIe Controller is shipped with pre-configured hard-coded credentials that may allow root-user access to the cont...
CVE-2019-13554HIGH8.8GE Mark VIe Controller has an unsecured Telnet protocol that may allow a user to create an authenticated session using g...
CVE-2019-4393CRITICAL9.8HCL AppScan Standard is vulnerable to excessive authorization attempts
CVE-2019-4391HIGH8.2HCL AppScan Standard is vulnerable to XML External Entity Injection (XXE) attack when processing XML data
CVE-2019-19699HIGH7.2There is Authenticated remote code execution in Centreon Infrastructure Monitoring Software through 19.10 via Pollers mi...
CVE-2019-17231MEDIUM6.1includes/theme-functions.php in the OneTone theme through 3.0.6 for WordPress has multiple stored XSS issues.
CVE-2019-17230MEDIUM5.3includes/theme-functions.php in the OneTone theme through 3.0.6 for WordPress allows unauthenticated options changes.
CVE-2019-18905MEDIUM5.9A Insufficient Verification of Data Authenticity vulnerability in autoyast2 of SUSE Linux Enterprise Server 12, SUSE Lin...
CVE-2019-18904HIGH7.5A Uncontrolled Resource Consumption vulnerability in rmt of SUSE Linux Enterprise High Performance Computing 15-ESPOS, S...
CVE-2019-19914Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2019-19348HIGH7An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/apb-base, affecting ...
CVE-2019-19346HIGH7An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/mariadb-apb, affecti...
CVE-2019-19097HIGH7.5ABB eSOMS versions 4.0 to 6.0.3 accept connections using medium strength ciphers. If a connection is enabled using such ...
CVE-2019-19096MEDIUM6.1The Redis data structure component used in ABB eSOMS versions 6.0 to 6.0.2 stores credentials in clear text. If an attac...
CVE-2019-19095MEDIUM5.4Lack of adequate input/output validation for ABB eSOMS versions 4.0 to 6.0.2 might allow an attacker to attack such as s...
CVE-2019-19094HIGH7.6Lack of input checks for SQL queries in ABB eSOMS versions 3.9 to 6.0.3 might allow an attacker SQL injection attacks ag...
CVE-2019-19093MEDIUM6.5eSOMS versions 4.0 to 6.0.3 do not enforce password complexity settings, potentially resulting in lower access security ...
CVE-2019-19092LOW3.5ABB eSOMS versions 4.0 to 6.0.3 use ASP.NET Viewstate without Message Authentication Code (MAC). Alterations to Viewstat...
CVE-2019-19091MEDIUM4.3For ABB eSOMS versions 4.0 to 6.0.3, HTTPS responses contain comments with sensitive information about the application. ...
CVE-2019-19090LOW3.5For ABB eSOMS versions 4.0 to 6.0.2, the Secure Flag is not set in the HTTP response header. Unencrypted connections mig...
CVE-2019-19089MEDIUM6.1For ABB eSOMS versions 4.0 to 6.0.3, the X-Content-Type-Options Header is missing in the HTTP response, potentially caus...
CVE-2019-19003MEDIUM6.1For ABB eSOMS versions 4.0 to 6.0.2, the HTTPOnly flag is not set. This can allow Javascript to access the cookie conten...
CVE-2019-19002MEDIUM5.4For ABB eSOMS versions 4.0 to 6.0.2, the X-XSS-Protection HTTP response header is not set in responses from the web serv...
CVE-2019-19001MEDIUM6.5For ABB eSOMS versions 4.0 to 6.0.2, the X-Frame-Options header is not configured in HTTP response. This can potentially...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now