2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-1329 | MEDIUM | 5.4 | 1.4% | Oct 10, 2019 | An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially c... |
| CVE-2019-1328 | MEDIUM | 5.4 | 1.4% | Oct 10, 2019 | A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web requ... |
| CVE-2019-1325 | MEDIUM | 5.5 | 1.3% | Oct 10, 2019 | An elevation of privilege vulnerability exists in the Windows redirected drive buffering system (rdbss.sys) when the ope... |
| CVE-2019-1318 | MEDIUM | 5.9 | 3.3% | Oct 10, 2019 | A spoofing vulnerability exists when Transport Layer Security (TLS) accesses non- Extended Master Secret (EMS) sessions,... |
| CVE-2019-1314 | MEDIUM | 6.8 | 0.9% | Oct 10, 2019 | A security feature bypass vulnerability exists in Windows 10 Mobile when Cortana allows a user to access files and folde... |
| CVE-2019-1313 | MEDIUM | 6.5 | 5.0% | Oct 10, 2019 | An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when it improperly enfor... |
| CVE-2019-1238 | MEDIUM | 6.4 | 5.5% | Oct 10, 2019 | A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScrip... |
| CVE-2019-1230 | MEDIUM | 6.8 | 5.4% | Oct 10, 2019 | An information disclosure vulnerability exists when the Windows Hyper-V Network Switch on a host operating system fails ... |
| CVE-2019-1166 | MEDIUM | 5.9 | 61.7% | Oct 10, 2019 | A tampering vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully bypass t... |
| CVE-2019-1070 | MEDIUM | 5.4 | 1.4% | Oct 10, 2019 | A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a speciall... |
| CVE-2019-13929 | MEDIUM | 6.5 | 1.3% | Oct 10, 2019 | A vulnerability has been identified in SIMATIC IT UADM (All versions < V1.3). An authenticated remote attacker with netw... |
| CVE-2019-0608 | MEDIUM | 4.3 | 2.1% | Oct 10, 2019 | A spoofing vulnerability exists when Microsoft Browsers does not properly parse HTTP content, aka 'Microsoft Browser Spo... |
| CVE-2019-17434 | MEDIUM | 5.4 | 0.6% | Oct 10, 2019 | LavaLite through 5.7 has XSS via a crafted account name that is mishandled on the Manage Clients screen. |
| CVE-2019-17433 | MEDIUM | 4.8 | 0.6% | Oct 10, 2019 | z-song laravel-admin 1.7.3 has XSS via the Slug or Name on the Roles screen, because of mishandling on the "Operation lo... |
| CVE-2019-17432 | MEDIUM | 6.5 | 0.5% | Oct 10, 2019 | An issue was discovered in fastadmin 1.0.0.20190705_beta. There is a public/admin/general.config/edit CSRF vulnerability... |
| CVE-2019-17430 | MEDIUM | 6.1 | 1.0% | Oct 10, 2019 | EyouCms through 2019-07-11 has XSS related to the login.php web_recordnum parameter. |
| CVE-2019-17071 | MEDIUM | 6.1 | 0.9% | Oct 10, 2019 | The client-dash (aka Client Dash) plugin 2.1.4 for WordPress allows XSS. |
| CVE-2019-17070 | MEDIUM | 6.1 | 0.9% | Oct 10, 2019 | The liquid-speech-balloon (aka LIQUID SPEECH BALLOON) plugin before 1.0.7 for WordPress allows XSS with Internet Explore... |
| CVE-2019-17427 | MEDIUM | 6.1 | 1.6% | Oct 10, 2019 | In Redmine before 3.4.11 and 4.0.x before 4.0.4, persistent XSS exists due to textile formatting errors. |
| CVE-2019-17420 | MEDIUM | 5.3 | 1.4% | Oct 10, 2019 | In OISF LibHTP before 0.5.31, as used in Suricata 4.1.4 and other products, an HTTP protocol parsing error causes the ht... |
| CVE-2019-17417 | MEDIUM | 4.8 | 0.6% | Oct 10, 2019 | PbootCMS 2.0.2 allows XSS via vectors involving the Pboot/admin.php?p=/Single/index/mcode/1 and Pboot/?contact/ URIs. |
| CVE-2019-17109 | MEDIUM | 6.5 | 2.8% | Oct 9, 2019 | Koji through 1.18.0 allows remote Directory Traversal, with resultant Privilege Escalation. |
| CVE-2019-15021 | MEDIUM | 5.3 | 1.0% | Oct 9, 2019 | A security vulnerability exists in the Zingbox Inspector versions 1.294 and earlier, that can allow an attacker to easil... |
| CVE-2019-17112 | MEDIUM | 4.3 | 2.1% | Oct 9, 2019 | An issue was discovered in Zoho ManageEngine DataSecurity Plus before 5.0.1 5012. An exposed service allows a basic user... |
| CVE-2019-0074 | MEDIUM | 5.5 | 0.4% | Oct 9, 2019 | A path traversal vulnerability in NFX150 Series and QFX10K Series, EX9200 Series, MX Series and PTX Series devices with ... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now