2019 CVE Vulnerabilities
17,624 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-19089 | MEDIUM | 6.1 | 1.0% | Apr 2, 2020 | For ABB eSOMS versions 4.0 to 6.0.3, the X-Content-Type-Options Header is missing in the HTTP response, potentially caus... |
| CVE-2019-19003 | MEDIUM | 6.1 | 0.8% | Apr 2, 2020 | For ABB eSOMS versions 4.0 to 6.0.2, the HTTPOnly flag is not set. This can allow Javascript to access the cookie conten... |
| CVE-2019-19002 | MEDIUM | 5.4 | 0.8% | Apr 2, 2020 | For ABB eSOMS versions 4.0 to 6.0.2, the X-XSS-Protection HTTP response header is not set in responses from the web serv... |
| CVE-2019-19001 | MEDIUM | 6.5 | 1.5% | Apr 2, 2020 | For ABB eSOMS versions 4.0 to 6.0.2, the X-Frame-Options header is not configured in HTTP response. This can potentially... |
| CVE-2019-19000 | MEDIUM | 6.5 | 1.1% | Apr 2, 2020 | For ABB eSOMS 4.0 to 6.0.3, the Cache-Control and Pragma HTTP header(s) have not been properly configured within the app... |
| CVE-2019-14868 | HIGH | 7.8 | 1.4% | Apr 2, 2020 | In ksh version 20120801, a flaw was found in the way it evaluates certain environment variables. An attacker could use t... |
| CVE-2019-20635 | MEDIUM | 6.1 | 0.9% | Apr 2, 2020 | codeBeamer before 9.5.0-RC3 does not properly restrict the ability to execute custom Java code and access the Java class... |
| CVE-2019-7017 | — | — | — | Apr 2, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2019-7016 | — | — | — | Apr 2, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2019-7015 | — | — | — | Apr 2, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2019-7014 | — | — | — | Apr 2, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2019-7013 | — | — | — | Apr 2, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2019-7012 | — | — | — | Apr 2, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2019-7011 | — | — | — | Apr 2, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2019-7010 | — | — | — | Apr 2, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2019-7009 | — | — | — | Apr 2, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2019-7008 | — | — | — | Apr 2, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2019-6999 | — | — | — | Apr 2, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2019-17564 | CRITICAL | 9.8 | 35.6% | Apr 1, 2020 | Unsafe deserialization occurs within a Dubbo application which has HTTP remoting enabled. An attacker may submit a POST ... |
| CVE-2019-9163 | CRITICAL | 9.8 | 2.3% | Apr 1, 2020 | The connection initiation process in March Networks Command Client before 2.7.2 allows remote attackers to execute arbit... |
| CVE-2019-11254 | MEDIUM | 6.5 | 2.3% | Apr 1, 2020 | The Kubernetes API Server component in versions 1.1-1.14, and versions prior to 1.15.10, 1.16.7 and 1.17.3 allows an aut... |
| CVE-2019-3945 | HIGH | 7.5 | 1.1% | Apr 1, 2020 | Web server running on Parrot ANAFI can be crashed due to the SDK command "Common_CurrentDateTime" being sent to control ... |
| CVE-2019-3944 | HIGH | 7.5 | 1.5% | Apr 1, 2020 | Parrot ANAFI is vulnerable to Wi-Fi deauthentication attack, allowing remote and unauthenticated attackers to disconnect... |
| CVE-2019-3942 | HIGH | 7.5 | 1.4% | Apr 1, 2020 | Advantech WebAccess 8.3.4 does not properly restrict an RPC call that allows unauthenticated, remote users to read files... |
| CVE-2019-13495 | MEDIUM | 5.4 | 0.6% | Mar 31, 2020 | In firmware version 4.50 of Zyxel XGS2210-52HP, multiple stored cross-site scripting (XSS) issues allows remote authenti... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now