2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-12365MEDIUM6.1The Newton application through 10.0.23 for Android allows XSS via an event attribute and arbitrary file loading via a sr...
CVE-2019-12132CRITICAL9.8An issue was discovered in ONAP SDNC before Dublin. By executing sla/dgUpload with a crafted filename parameter, an unau...
CVE-2019-12131CRITICAL9.1An issue was detected in ONAP APPC through Dublin and SDC through Dublin. By setting a USER_ID parameter in an HTTP head...
CVE-2019-12124CRITICAL9.1An issue was discovered in ONAP APPC before Dublin. By using an exposed unprotected Jolokia interface, an unauthenticate...
CVE-2019-12123HIGH8.8An issue was discovered in ONAP SDNC before Dublin. By executing sla/printAsXml with a crafted module parameter, an auth...
CVE-2019-12122MEDIUM6.5An issue was discovered in ONAP Portal through Dublin. By executing a call to ONAPPORTAL/portalApi/loggedinUser, an atta...
CVE-2019-12121HIGH7.5An issue was detected in ONAP Portal through Dublin. By executing a padding oracle attack using the ONAPPORTAL/processSi...
CVE-2019-12120CRITICAL9.8An issue was discovered in ONAP VNFSDK through Dublin. By accessing port 8000 of demo-vnfsdk-vnfsdk, an unauthenticated ...
CVE-2019-12119CRITICAL9.8An issue was discovered in ONAP SDC through Dublin. By accessing port 7000 of demo-sdc-sdc-wfd-fe pod, an unauthenticate...
CVE-2019-12118CRITICAL9.8An issue was discovered in ONAP SDC through Dublin. By accessing port 7001 of demo-sdc-sdc-wfd-be pod, an unauthenticate...
CVE-2019-12117CRITICAL9.8An issue was discovered in ONAP SDC through Dublin. By accessing port 4001 of demo-sdc-sdc-onboarding-be pod, an unauthe...
CVE-2019-12116CRITICAL9.8An issue was discovered in ONAP SDC through Dublin. By accessing port 6000 of demo-sdc-sdc-fe pod, an unauthenticated at...
CVE-2019-12115CRITICAL9.8An issue was discovered in ONAP SDC through Dublin. By accessing port 4000 of demo-sdc-sdc-be pod, an unauthenticated at...
CVE-2019-12114CRITICAL9.8An issue was discovered in ONAP HOLMES before Dublin. By accessing port 9202 of dep-holmes-engine-mgmt pod, an unauthent...
CVE-2019-12113HIGH8.8An issue was discovered in ONAP SDNC before Dublin. By executing sla/printAsGv with a crafted module parameter, an authe...
CVE-2019-12112CRITICAL9.8An issue was discovered in ONAP SDNC before Dublin. By executing sla/upload with a crafted filename parameter, an unauth...
CVE-2019-19355HIGH7An insecure modification vulnerability in the /etc/passwd file was found in the openshift/ocp-release-operator-sdk. An a...
CVE-2019-19351HIGH7An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/jenkins. An attacker...
CVE-2019-19335MEDIUM4.4During installation of an OpenShift 4 cluster, the `openshift-install` command line tool creates an `auth` directory, wi...
CVE-2019-14871MEDIUM6.5The REENT_CHECK macro (see newlib/libc/include/sys/reent.h) as used by REENT_CHECK_TM, REENT_CHECK_MISC, REENT_CHECK_MP ...
CVE-2019-10178MEDIUM6.1It was found that the Token Processing Service (TPS) did not properly sanitize the Token IDs from the "Activity" page, e...
CVE-2019-11689HIGH8.1An issue was discovered in ASUSTOR exFAT Driver through 1.0.0.r20. When conducting license validation, exfat.cgi and exf...
CVE-2019-11688HIGH7.4An issue was discovered in ASUSTOR exFAT Driver through 1.0.0.r20. When conducting license validation, exfat.cgi and exf...
CVE-2019-10682HIGH7.5django-nopassword before 5.0.0 stores cleartext secrets in the database.
CVE-2019-10146MEDIUM4.7A Reflected Cross Site Scripting flaw was found in all pki-core 10.x.x versions module from the pki-core server due to t...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now