2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-16344MEDIUM6.1A cross-site scripting (XSS) vulnerability in the login form (/ScadaBR/login.htm) in ScadaBR 1.0CE allows a remote attac...
CVE-2019-14858MEDIUM5.5A vulnerability was found in Ansible engine 2.x up to 2.8 and Ansible tower 3.x up to 3.5. When a module has an argument...
CVE-2019-14838MEDIUM4.9A flaw was found in wildfly-core before 7.2.5.GA. The Management users with Monitor, Auditor and Deployer Roles should n...
CVE-2019-4572MEDIUM4.4IBM FileNet Content Manager 5.5.2 and 5.5.3 in specific configurations, could log the web service user credentials into ...
CVE-2019-17536MEDIUM4.9Gila CMS through 1.11.4 allows Unrestricted Upload of a File with a Dangerous Type via the moveAction function in core/c...
CVE-2019-17535MEDIUM6.1Gila CMS through 1.11.4 allows blog-list.php XSS, in both the gila-blog and gila-mag themes, via the search parameter, a...
CVE-2019-17522MEDIUM4.8A stored XSS vulnerability was discovered in Hotaru CMS v1.7.2 via the admin_index.php?page=settings SITE NAME field (ak...
CVE-2019-17521MEDIUM6.5An issue was discovered in Landing-CMS 0.0.6. There is a CSRF vulnerability that can change the admin's password via the...
CVE-2019-17176MEDIUM6.1Genesys PureEngage Digital (eServices) 8.1.x allows XSS via HtmlChatPanel.jsp or HtmlChatFrameSet.jsp (ActionColor, Clie...
CVE-2019-2187MEDIUM5.5In nfc_ncif_decode_rf_params of nfc_ncif.cc, there is a possible out of bounds read due to an integer underflow. This co...
CVE-2019-2183MEDIUM5.5In generateServicesMap of RegisteredServicesCache.java, there is a possible account protection bypass due to a caching o...
CVE-2019-2110MEDIUM5.5In ScreenRotationAnimation of ScreenRotationAnimation.java, there is a possible capture of a secure screen due to a miss...
CVE-2019-6333MEDIUM6.7A potential security vulnerability has been identified with certain versions of HP Touchpoint Analytics prior to version...
CVE-2019-17504MEDIUM6.1An issue was discovered in Kirona Dynamic Resource Scheduling (DRS) 5.5.3.5. A reflected Cross-site scripting (XSS) vuln...
CVE-2019-17503MEDIUM5.3An issue was discovered in Kirona Dynamic Resource Scheduling (DRS) 5.5.3.5. An unauthenticated user can access /osm/REG...
CVE-2019-14510MEDIUM6.7An issue was discovered in Kaseya VSA RMM through 9.5.0.22. When using the default configuration, the LAN Cache feature ...
CVE-2019-17497MEDIUM6.5Tracker PDF-XChange Editor before 8.0.330.0 has an NTLM SSO hash theft vulnerability using crafted FDF or XFDF files (a ...
CVE-2019-17496MEDIUM6.1Craft CMS before 3.3.8 has stored XSS via a name field. This field is mishandled during site deletion.
CVE-2019-17494MEDIUM6.1laravel-bjyblog 6.1.1 has XSS via a crafted URL.
CVE-2019-17493MEDIUM6.1Jiangnan Online Judge (aka jnoj) 0.8.0 has XSS via the Problem[sample_input] parameter to web/admin/problem/create or we...
CVE-2019-17491MEDIUM6.1Jiangnan Online Judge (aka jnoj) 0.8.0 has XSS via the Problem[description] parameter to web/admin/problem/create or web...
CVE-2019-17489MEDIUM6.1Jiangnan Online Judge (aka jnoj) 0.8.0 has XSS via the Problem[title] parameter to web/polygon/problem/create or web/pol...
CVE-2019-17488MEDIUM6.1b3log Symphony (aka Sym) before 3.6.0 has XSS via the HTTP User-Agent header.
CVE-2019-9530MEDIUM5.5The web root directory of the Cobham EXPLORER 710, firmware version 1.07, has no access restrictions on downloading and ...
CVE-2019-9529MEDIUM5.5The web application portal of the Cobham EXPLORER 710, firmware version 1.07, has no authentication by default. This cou...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now