2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-1329MEDIUM5.4An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially c...
CVE-2019-1328MEDIUM5.4A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web requ...
CVE-2019-1325MEDIUM5.5An elevation of privilege vulnerability exists in the Windows redirected drive buffering system (rdbss.sys) when the ope...
CVE-2019-1318MEDIUM5.9A spoofing vulnerability exists when Transport Layer Security (TLS) accesses non- Extended Master Secret (EMS) sessions,...
CVE-2019-1314MEDIUM6.8A security feature bypass vulnerability exists in Windows 10 Mobile when Cortana allows a user to access files and folde...
CVE-2019-1313MEDIUM6.5An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when it improperly enfor...
CVE-2019-1238MEDIUM6.4A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScrip...
CVE-2019-1230MEDIUM6.8An information disclosure vulnerability exists when the Windows Hyper-V Network Switch on a host operating system fails ...
CVE-2019-1166MEDIUM5.9A tampering vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully bypass t...
CVE-2019-1070MEDIUM5.4A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a speciall...
CVE-2019-13929MEDIUM6.5A vulnerability has been identified in SIMATIC IT UADM (All versions < V1.3). An authenticated remote attacker with netw...
CVE-2019-0608MEDIUM4.3A spoofing vulnerability exists when Microsoft Browsers does not properly parse HTTP content, aka 'Microsoft Browser Spo...
CVE-2019-17434MEDIUM5.4LavaLite through 5.7 has XSS via a crafted account name that is mishandled on the Manage Clients screen.
CVE-2019-17433MEDIUM4.8z-song laravel-admin 1.7.3 has XSS via the Slug or Name on the Roles screen, because of mishandling on the "Operation lo...
CVE-2019-17432MEDIUM6.5An issue was discovered in fastadmin 1.0.0.20190705_beta. There is a public/admin/general.config/edit CSRF vulnerability...
CVE-2019-17430MEDIUM6.1EyouCms through 2019-07-11 has XSS related to the login.php web_recordnum parameter.
CVE-2019-17071MEDIUM6.1The client-dash (aka Client Dash) plugin 2.1.4 for WordPress allows XSS.
CVE-2019-17070MEDIUM6.1The liquid-speech-balloon (aka LIQUID SPEECH BALLOON) plugin before 1.0.7 for WordPress allows XSS with Internet Explore...
CVE-2019-17427MEDIUM6.1In Redmine before 3.4.11 and 4.0.x before 4.0.4, persistent XSS exists due to textile formatting errors.
CVE-2019-17420MEDIUM5.3In OISF LibHTP before 0.5.31, as used in Suricata 4.1.4 and other products, an HTTP protocol parsing error causes the ht...
CVE-2019-17417MEDIUM4.8PbootCMS 2.0.2 allows XSS via vectors involving the Pboot/admin.php?p=/Single/index/mcode/1 and Pboot/?contact/ URIs.
CVE-2019-17109MEDIUM6.5Koji through 1.18.0 allows remote Directory Traversal, with resultant Privilege Escalation.
CVE-2019-15021MEDIUM5.3A security vulnerability exists in the Zingbox Inspector versions 1.294 and earlier, that can allow an attacker to easil...
CVE-2019-17112MEDIUM4.3An issue was discovered in Zoho ManageEngine DataSecurity Plus before 5.0.1 5012. An exposed service allows a basic user...
CVE-2019-0074MEDIUM5.5A path traversal vulnerability in NFX150 Series and QFX10K Series, EX9200 Series, MX Series and PTX Series devices with ...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now