2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-0381MEDIUM5.5A binary planting in SAP SQL Anywhere, before version 17.0, SAP IQ, before version 16.1, and SAP Dynamic Tier, before ve...
CVE-2019-0380MEDIUM4.9Under certain conditions, SAP Landscape Management enterprise edition, before version 3.0, allows custom secure paramete...
CVE-2019-0379MEDIUM5.3SAP Process Integration, business-to-business add-on, versions 1.0, 2.0, does not perform authentication check properly ...
CVE-2019-0378MEDIUM5.4SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before version 4.2, does not suffi...
CVE-2019-0377MEDIUM5.4SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2, does not suff...
CVE-2019-0376MEDIUM5.4SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2 and 4.3, does ...
CVE-2019-0375MEDIUM5.4SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2 and 4.3, does ...
CVE-2019-0374MEDIUM5.4SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2 and 4.3, does ...
CVE-2019-0370MEDIUM6.5Due to missing input validation, SAP Financial Consolidation, before versions 10.0 and 10.1, enables an attacker to use ...
CVE-2019-0369MEDIUM5.4SAP Financial Consolidation, before versions 10.0 and 10.1, does not sufficiently encode user-controlled inputs, which a...
CVE-2019-0368MEDIUM5.4SAP Customer Relationship Management (Email Management), versions: S4CRM before 1.0 and 2.0, BBPCRM before 7.0, 7.01, 7....
CVE-2019-0367MEDIUM4.3SAP NetWeaver Process Integration (B2B Toolkit), before versions 1.0 and 2.0, does not perform necessary authorization c...
CVE-2019-14845MEDIUM5.3A vulnerability was found in OpenShift builds, versions 4.1 up to 4.3. Builds that extract source from a container image...
CVE-2019-10963MEDIUM4.3Moxa EDR 810, all versions 5.1 and prior, allows an unauthenticated attacker to be able to retrieve some log files from ...
CVE-2019-10756MEDIUM5.4It is possible to inject JavaScript within node-red-dashboard versions prior to version 2.17.0 due to the ui_notificatio...
CVE-2019-10215MEDIUM6.1Bootstrap-3-Typeahead after version 4.0.2 is vulnerable to a cross-site scripting flaw in the highlighter() function. An...
CVE-2019-17105MEDIUM5.3The token generator in index.php in Centreon Web before 2.8.27 is predictable.
CVE-2019-17271MEDIUM4.9vBulletin 5.5.4 allows SQL Injection via the ajax/api/hook/getHookList or ajax/api/widget/getWidgetList where parameter.
CVE-2019-17108MEDIUM6.1Local file inclusion in brokerPerformance.php in Centreon Web before 2.8.28 allows attackers to disclose information or ...
CVE-2019-17106MEDIUM6.5In Centreon Web through 2.8.29, disclosure of external components' passwords allows authenticated attackers to move late...
CVE-2019-16417MEDIUM5.4HRworks FLOW 3.36.9 allows XSS via the purpose of a travel-expense report.
CVE-2019-16416MEDIUM5.4HRworks 3.36.9 allows XSS via the purpose of a travel-expense report.
CVE-2019-17257MEDIUM5.5IrfanView 4.53 allows a Exception Handler Chain to be Corrupted starting at EXR!ReadEXR+0x000000000002af80.
CVE-2019-17349MEDIUM5.5An issue was discovered in Xen through 4.12.x allowing Arm domU attackers to cause a denial of service (infinite loop) i...
CVE-2019-17348MEDIUM6.5An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service because of an ...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now