2019 CVE Vulnerabilities

17,624 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-19023HIGH8.8Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 has a Privilege Escalation Vulnerability in the VMware...
CVE-2019-18785HIGH7.5SuiteCRM 7.10.x prior to 7.10.21 and 7.11.x prior to 7.11.9 mishandles API access tokens and credentials.
CVE-2019-18782MEDIUM5.3SuiteCRM 7.10.x prior to 7.10.21 and 7.11.x prior to 7.11.9 does not correctly implement the .htaccess protection mechan...
CVE-2019-16108HIGH7.5phpBB 3.2.7 allows adding an arbitrary Cascading Style Sheets (CSS) token sequence to a page through BBCode.
CVE-2019-16072CRITICAL9.8An OS command injection vulnerability in the discover_and_manage CGI script in NETSAS Enigma NMS 65.0.0 and prior allows...
CVE-2019-16071HIGH8.8Enigma NMS 65.0.0 and prior allows administrative users to create low-privileged accounts that do not have the ability t...
CVE-2019-16529MEDIUM5.3An issue was discovered in the CheckUser extension through 1.35.0 for MediaWiki. Oversighted edit summaries are still vi...
CVE-2019-16069MEDIUM6.1A number of stored Cross-site Scripting (XSS) vulnerabilities were identified in NETSAS Enigma NMS 65.0.0 and prior that...
CVE-2019-16068HIGH8.8A CSRF vulnerability exists in NETSAS ENIGMA NMS version 65.0.0 and prior that could allow an attacker to be able to tri...
CVE-2019-16063HIGH7.5NETSAS Enigma NMS 65.0.0 and prior does not encrypt sensitive data rendered within web pages. It is possible for an atta...
CVE-2019-15539MEDIUM6.1The proj_doc_edit_page.php Project Documentation feature in MantisBT before 2.21.3 has a stored cross-site scripting (XS...
CVE-2019-15124MEDIUM6.1In the MobileFrontend extension for MediaWiki, XSS exists within the edit summary field of the watchlist feed. This affe...
CVE-2019-20526MEDIUM6.1Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp password parameter.
CVE-2019-20525MEDIUM6.1Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp driver parameter.
CVE-2019-20521MEDIUM6.1ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the api/ URI.
CVE-2019-20520MEDIUM6.1ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the api/method/ URI.
CVE-2019-20519MEDIUM6.1ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the user/ URI, as demonstrated by a crafted e-mail address.
CVE-2019-20518MEDIUM6.1ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the project/ URI.
CVE-2019-20517MEDIUM6.1ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the contact/ URI.
CVE-2019-20516MEDIUM6.1ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the blog/ URI.
CVE-2019-20515MEDIUM6.1ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the addresses/ URI.
CVE-2019-20514MEDIUM6.1ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the address/ URI.
CVE-2019-20513MEDIUM6.1Open edX Ironwood.1 allows support/certificates?user= reflected XSS.
CVE-2019-16375MEDIUM5.4An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.11, and Community Edition 5.0.x through 5...
CVE-2019-16338HIGH7.8The tfo_common component in HwordApp.dll in Hancom Office 9.6.1.7634 allows a use-after-free via a crafted .docx file.

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now