2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-16344 | MEDIUM | 6.1 | 1.0% | Oct 14, 2019 | A cross-site scripting (XSS) vulnerability in the login form (/ScadaBR/login.htm) in ScadaBR 1.0CE allows a remote attac... |
| CVE-2019-14858 | MEDIUM | 5.5 | 0.4% | Oct 14, 2019 | A vulnerability was found in Ansible engine 2.x up to 2.8 and Ansible tower 3.x up to 3.5. When a module has an argument... |
| CVE-2019-14838 | MEDIUM | 4.9 | 1.1% | Oct 14, 2019 | A flaw was found in wildfly-core before 7.2.5.GA. The Management users with Monitor, Auditor and Deployer Roles should n... |
| CVE-2019-4572 | MEDIUM | 4.4 | 0.3% | Oct 14, 2019 | IBM FileNet Content Manager 5.5.2 and 5.5.3 in specific configurations, could log the web service user credentials into ... |
| CVE-2019-17536 | MEDIUM | 4.9 | 2.3% | Oct 13, 2019 | Gila CMS through 1.11.4 allows Unrestricted Upload of a File with a Dangerous Type via the moveAction function in core/c... |
| CVE-2019-17535 | MEDIUM | 6.1 | 2.0% | Oct 13, 2019 | Gila CMS through 1.11.4 allows blog-list.php XSS, in both the gila-blog and gila-mag themes, via the search parameter, a... |
| CVE-2019-17522 | MEDIUM | 4.8 | 0.6% | Oct 12, 2019 | A stored XSS vulnerability was discovered in Hotaru CMS v1.7.2 via the admin_index.php?page=settings SITE NAME field (ak... |
| CVE-2019-17521 | MEDIUM | 6.5 | 0.4% | Oct 12, 2019 | An issue was discovered in Landing-CMS 0.0.6. There is a CSRF vulnerability that can change the admin's password via the... |
| CVE-2019-17176 | MEDIUM | 6.1 | 0.9% | Oct 11, 2019 | Genesys PureEngage Digital (eServices) 8.1.x allows XSS via HtmlChatPanel.jsp or HtmlChatFrameSet.jsp (ActionColor, Clie... |
| CVE-2019-2187 | MEDIUM | 5.5 | 0.2% | Oct 11, 2019 | In nfc_ncif_decode_rf_params of nfc_ncif.cc, there is a possible out of bounds read due to an integer underflow. This co... |
| CVE-2019-2183 | MEDIUM | 5.5 | 0.2% | Oct 11, 2019 | In generateServicesMap of RegisteredServicesCache.java, there is a possible account protection bypass due to a caching o... |
| CVE-2019-2110 | MEDIUM | 5.5 | 0.1% | Oct 11, 2019 | In ScreenRotationAnimation of ScreenRotationAnimation.java, there is a possible capture of a secure screen due to a miss... |
| CVE-2019-6333 | MEDIUM | 6.7 | 0.5% | Oct 11, 2019 | A potential security vulnerability has been identified with certain versions of HP Touchpoint Analytics prior to version... |
| CVE-2019-17504 | MEDIUM | 6.1 | 2.8% | Oct 11, 2019 | An issue was discovered in Kirona Dynamic Resource Scheduling (DRS) 5.5.3.5. A reflected Cross-site scripting (XSS) vuln... |
| CVE-2019-17503 | MEDIUM | 5.3 | 49.2% | Oct 11, 2019 | An issue was discovered in Kirona Dynamic Resource Scheduling (DRS) 5.5.3.5. An unauthenticated user can access /osm/REG... |
| CVE-2019-14510 | MEDIUM | 6.7 | 0.5% | Oct 11, 2019 | An issue was discovered in Kaseya VSA RMM through 9.5.0.22. When using the default configuration, the LAN Cache feature ... |
| CVE-2019-17497 | MEDIUM | 6.5 | 5.2% | Oct 11, 2019 | Tracker PDF-XChange Editor before 8.0.330.0 has an NTLM SSO hash theft vulnerability using crafted FDF or XFDF files (a ... |
| CVE-2019-17496 | MEDIUM | 6.1 | 0.8% | Oct 11, 2019 | Craft CMS before 3.3.8 has stored XSS via a name field. This field is mishandled during site deletion. |
| CVE-2019-17494 | MEDIUM | 6.1 | 0.9% | Oct 10, 2019 | laravel-bjyblog 6.1.1 has XSS via a crafted URL. |
| CVE-2019-17493 | MEDIUM | 6.1 | 1.1% | Oct 10, 2019 | Jiangnan Online Judge (aka jnoj) 0.8.0 has XSS via the Problem[sample_input] parameter to web/admin/problem/create or we... |
| CVE-2019-17491 | MEDIUM | 6.1 | 1.1% | Oct 10, 2019 | Jiangnan Online Judge (aka jnoj) 0.8.0 has XSS via the Problem[description] parameter to web/admin/problem/create or web... |
| CVE-2019-17489 | MEDIUM | 6.1 | 1.1% | Oct 10, 2019 | Jiangnan Online Judge (aka jnoj) 0.8.0 has XSS via the Problem[title] parameter to web/polygon/problem/create or web/pol... |
| CVE-2019-17488 | MEDIUM | 6.1 | 0.8% | Oct 10, 2019 | b3log Symphony (aka Sym) before 3.6.0 has XSS via the HTTP User-Agent header. |
| CVE-2019-9530 | MEDIUM | 5.5 | 0.4% | Oct 10, 2019 | The web root directory of the Cobham EXPLORER 710, firmware version 1.07, has no access restrictions on downloading and ... |
| CVE-2019-9529 | MEDIUM | 5.5 | 0.3% | Oct 10, 2019 | The web application portal of the Cobham EXPLORER 710, firmware version 1.07, has no authentication by default. This cou... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now