2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-14884 | MEDIUM | 6.1 | 0.9% | Mar 18, 2020 | A vulnerability was found in Moodle 3.7 before 3.73, 3.6 before 3.6.7 and 3.5 before 3.5.9, where a reflected XSS possib... |
| CVE-2019-14883 | MEDIUM | 5.3 | 1.1% | Mar 18, 2020 | A vulnerability was found in Moodle 3.6 before 3.6.7 and 3.7 before 3.7.3, where tokens used to fetch inline atachments ... |
| CVE-2019-14882 | MEDIUM | 6.1 | 1.1% | Mar 18, 2020 | A vulnerability was found in Moodle 3.7 to 3.7.3, 3.6 to 3.6.7, 3.5 to 3.5.9 and earlier where an open redirect existed ... |
| CVE-2019-14881 | MEDIUM | 6.1 | 1.1% | Mar 18, 2020 | A vulnerability was found in moodle 3.7 before 3.7.3, where there is blind XSS reflected in some locations where user em... |
| CVE-2019-20510 | — | — | — | Mar 18, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-13456. Reason: This candidate is a duplicate of ... |
| CVE-2019-11939 | HIGH | 7.5 | 1.5% | Mar 18, 2020 | Golang Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the pay... |
| CVE-2019-20498 | CRITICAL | 9.8 | 1.6% | Mar 17, 2020 | cPanel before 82.0.18 allows WebDAV authentication bypass because the connection-sharing logic is incorrect (SEC-534). |
| CVE-2019-20497 | MEDIUM | 5.4 | 0.6% | Mar 17, 2020 | cPanel before 82.0.18 allows stored XSS via WHM Backup Restoration (SEC-533). |
| CVE-2019-20496 | MEDIUM | 5.5 | 0.3% | Mar 17, 2020 | cPanel before 82.0.18 allows attackers to conduct arbitrary chown operations as root during log processing (SEC-532). |
| CVE-2019-20495 | MEDIUM | 6.5 | 1.0% | Mar 17, 2020 | cPanel before 82.0.18 allows attackers to read an arbitrary database via MySQL dump streaming (SEC-531). |
| CVE-2019-20494 | LOW | 3.3 | 0.3% | Mar 17, 2020 | In cPanel before 82.0.18, Cpanel::Rand::Get can produce a predictable series of numbers (SEC-525). |
| CVE-2019-20493 | MEDIUM | 6.1 | 0.7% | Mar 17, 2020 | cPanel before 82.0.18 allows self-XSS because JSON string escaping is mishandled (SEC-520). |
| CVE-2019-20492 | HIGH | 8.8 | 1.3% | Mar 17, 2020 | cPanel before 82.0.18 allows authentication bypass because of misparsing of the format of the password file (SEC-516). |
| CVE-2019-20490 | HIGH | 8.8 | 1.1% | Mar 17, 2020 | cPanel before 82.0.18 allows authentication bypass because webmail usernames are processed inconsistently (SEC-499). |
| CVE-2019-11074 | HIGH | 7.2 | 4.5% | Mar 17, 2020 | A Write to Arbitrary Location in Disk vulnerability exists in PRTG Network Monitor 19.1.49 and below that allows attacke... |
| CVE-2019-20453 | HIGH | 8.8 | 2.1% | Mar 17, 2020 | A problem was found in Pydio Core before 8.2.4 and Pydio Enterprise before 8.2.4. A PHP object injection is present in t... |
| CVE-2019-20452 | HIGH | 8.8 | 2.1% | Mar 17, 2020 | A problem was found in Pydio Core before 8.2.4 and Pydio Enterprise before 8.2.4. A PHP object injection is present in t... |
| CVE-2019-20407 | MEDIUM | 4.3 | 1.2% | Mar 17, 2020 | The ConfigureBambooRelease resource in Jira Software and Jira Software Data Center before version 8.6.1 allows authentic... |
| CVE-2019-20105 | MEDIUM | 4.9 | 1.5% | Mar 17, 2020 | The EditApplinkServlet resource in the Atlassian Application Links plugin before version 5.4.20, from version 6.0.0 befo... |
| CVE-2019-20326 | HIGH | 7.8 | 2.1% | Mar 16, 2020 | A heap-based buffer overflow in _cairo_image_surface_create_from_jpeg() in extensions/cairo_io/cairo-image-surface-jpeg.... |
| CVE-2019-20191 | HIGH | 7.5 | 1.1% | Mar 16, 2020 | Oxygen XML Editor 21.1.1 allows XXE to read any file. |
| CVE-2019-20491 | MEDIUM | 5.4 | 0.7% | Mar 16, 2020 | cPanel before 82.0.18 allows attackers to leverage virtual mail accounts in order to bypass account suspensions (SEC-508... |
| CVE-2019-19852 | MEDIUM | 4.8 | 0.6% | Mar 16, 2020 | An XSS Injection vulnerability exists in Sangoma FreePBX and PBXact 13, 14, and 15 within the Call Event Logging report ... |
| CVE-2019-19615 | MEDIUM | 4.8 | 0.6% | Mar 16, 2020 | Multiple XSS vulnerabilities exist in the Backup & Restore module \ v14.0.10.2 through v14.0.10.7 for FreePBX, as shown ... |
| CVE-2019-19613 | MEDIUM | 5.2 | 0.5% | Mar 16, 2020 | An issue was discovered in Halvotec RaQuest 10.23.10801.0. The login page of the admin application is vulnerable to an O... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now