2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-20523MEDIUM6.1ilchCMS 2.1.23 allows XSS via the index.php/partner/index Name parameter.
CVE-2019-20522MEDIUM6.1ilchCMS 2.1.23 allows XSS via the index.php/partner/index Link parameter.
CVE-2019-19336MEDIUM6.1A cross-site scripting vulnerability was reported in the oVirt-engine's OAuth authorization endpoint before version 4.3....
CVE-2019-12130CRITICAL9.8In ONAP CLI through Dublin, by accessing an applicable port (30234, 30290, 32010, 30270, 30224, 30281, 30254, 30285, and...
CVE-2019-12129CRITICAL9.8In ONAP MSB through Dublin, by accessing an applicable port (30234, 30290, 32010, 30270, 30224, 30281, 30254, 30285, and...
CVE-2019-12128CRITICAL9.8In ONAP SO through Dublin, by accessing an applicable port (30234, 30290, 32010, 30270, 30224, 30281, 30254, 30285, and/...
CVE-2019-14872MEDIUM6.5The _dtoa_r function of the newlib libc library, prior to version 3.3.0, performs multiple memory allocations without ch...
CVE-2019-20485MEDIUM5.7qemu/qemu_driver.c in libvirt before 6.0.0 mishandles the holding of a monitor job during a query to a guest agent, whic...
CVE-2019-19677MEDIUM4.3arxes-tolina 3.0.0 allows User Enumeration.
CVE-2019-19676CRITICAL9.6A CSV injection in arxes-tolina 3.0.0 allows malicious users to gain remote control of other computers. By entering form...
CVE-2019-18979HIGH7.8Adaware antivirus 12.6.1005.11662 and 12.7.1055.0 has a quarantine flaw that allows privilege escalation. Exploitation u...
CVE-2019-3762HIGH7.5Data Protection Central versions 1.0, 1.0.1, 18.1, 18.2, and 19.1 contains an Improper Certificate Chain of Trust Vulner...
CVE-2019-20529HIGH7.5In core/doctype/prepared_report/prepared_report.py in Frappe 11 and 12, data files generated with Prepared Report were b...
CVE-2019-20528MEDIUM6.1Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp username parameter.
CVE-2019-20512MEDIUM6.1Open edX Ironwood.1 allows support/certificates?course_id= reflected XSS.
CVE-2019-20511MEDIUM6.1ERPNext 11.1.47 allows blog?blog_category= Frame Injection.
CVE-2019-18582HIGH7.2Dell EMC Data Protection Advisor versions 6.3, 6.4, 6.5, 18.2 versions prior to patch 83, and 19.1 versions prior to pat...
CVE-2019-18581HIGH7.2Dell EMC Data Protection Advisor versions 6.3, 6.4, 6.5, 18.2 versions prior to patch 83, and 19.1 versions prior to pat...
CVE-2019-12921MEDIUM6.5In GraphicsMagick before 1.3.32, the text filename component allows remote attackers to read arbitrary files via a craft...
CVE-2019-12769HIGH8.8SolarWinds Serv-U Managed File Transfer (MFT) Web client before 15.1.6 Hotfix 2 is vulnerable to Cross-Site Request Forg...
CVE-2019-12370MEDIUM6.1The Spark application through 2.0.2 for Android allows XSS via an event attribute and arbitrary file loading via a src a...
CVE-2019-12369MEDIUM6.1The TypeApp application through 1.9.5.35 for Android allows XSS via an event attribute and arbitrary file loading via a ...
CVE-2019-12368MEDIUM6.1The Edison Mail application through 1.7.1 for Android allows XSS via an event attribute and arbitrary file loading via a...
CVE-2019-12367MEDIUM6.1The BlueMail application through 1.9.5.36 for Android allows XSS via an event attribute and arbitrary file loading via a...
CVE-2019-12366MEDIUM6.1The Nine application through 4.5.3a for Android allows XSS via an event attribute and arbitrary file loading via a src a...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now