2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-0072MEDIUM5.5An Unprotected Storage of Credentials vulnerability in the identity and access management certificate generation procedu...
CVE-2019-0069MEDIUM5.5On EX4600, QFX5100 Series, NFX Series, QFX10K Series, QFX5110, QFX5200 Series, QFX5110, QFX5200, QFX10K Series, vSRX, SR...
CVE-2019-0067MEDIUM6.5Receipt of a specific link-local IPv6 packet destined to the RE may cause the system to crash and restart (vmcore). By c...
CVE-2019-5507MEDIUM5.5SnapManager for Oracle prior to version 3.4.2P1 are susceptible to a vulnerability which when successfully exploited cou...
CVE-2019-5506MEDIUM5.9Clustered Data ONTAP versions 9.0 and higher do not enforce hostname verification under certain circumstances making the...
CVE-2019-17402MEDIUM6.5Exiv2 0.27.2 allows attackers to trigger a crash in Exiv2::getULong in types.cpp when called from Exiv2::Internal::CiffD...
CVE-2019-17092MEDIUM6.1An XSS vulnerability in project list in OpenProject before 9.0.4 and 10.x before 10.0.2 allows remote attackers to injec...
CVE-2019-6471MEDIUM5.9A race condition which may occur when discarding malformed packets can result in BIND exiting due to a REQUIRE assertion...
CVE-2019-6465MEDIUM5.3Controls for zone transfers may not be properly applied to Dynamically Loadable Zones (DLZs) if the zones are writable V...
CVE-2019-4512MEDIUM4.3IBM Maximo Asset Management 7.6.1.1 generates an error message that includes sensitive information that could be used in...
CVE-2019-3653MEDIUM5.5Improper access control vulnerability in Configuration tool in McAfee Endpoint Security (ENS) Prior to 10.6.1 October 20...
CVE-2019-3652MEDIUM5.3Code Injection vulnerability in EPSetup.exe in McAfee Endpoint Security (ENS) Prior to 10.6.1 October 2019 Update allows...
CVE-2019-17385MEDIUM6.1The animate-it plugin before 2.3.5 for WordPress has XSS.
CVE-2019-17384MEDIUM6.1The animate-it plugin before 2.3.4 for WordPress has XSS.
CVE-2019-17380MEDIUM6.1cPanel before 82.0.15 allows self XSS in the WHM Update Preferences interface (SEC-528).
CVE-2019-17379MEDIUM6.1cPanel before 82.0.15 allows self stored XSS in the WHM SSL Storage Manager interface (SEC-527).
CVE-2019-17378MEDIUM6.1cPanel before 82.0.15 allows self XSS in the SSL Key Delete interface (SEC-526).
CVE-2019-17377MEDIUM6.1cPanel before 82.0.15 allows self XSS in LiveAPI example scripts (SEC-524).
CVE-2019-17376MEDIUM6.1cPanel before 82.0.15 allows self XSS in the SSL Certificate Upload interface (SEC-521).
CVE-2019-14808MEDIUM6.8An issue was discovered in the RENPHO application 3.0.0 for iOS. It transmits JSON data unencrypted to a server without ...
CVE-2019-11341MEDIUM4.6On certain Samsung P(9.0) phones, an attacker with physical access can start a TCP Dump capture without the user's knowl...
CVE-2019-11212MEDIUM5.4The MDM server component of TIBCO Software Inc's TIBCO MDM contains multiple vulnerabilities that theoretically allow an...
CVE-2019-17371MEDIUM6.5gif2png 2.5.13 has a memory leak in the writefile function.
CVE-2019-17369MEDIUM6.5OTCMS v3.85 has CSRF in the admin/member_deal.php Admin Panel page, leading to creation of a new management group accoun...
CVE-2019-17368MEDIUM6.1S-CMS v1.5 has XSS in tpl.php via the member/member_login.php from parameter.

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now