2019 CVE Vulnerabilities
17,624 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-20491 | MEDIUM | 5.4 | 0.7% | Mar 16, 2020 | cPanel before 82.0.18 allows attackers to leverage virtual mail accounts in order to bypass account suspensions (SEC-508... |
| CVE-2019-19852 | MEDIUM | 4.8 | 0.6% | Mar 16, 2020 | An XSS Injection vulnerability exists in Sangoma FreePBX and PBXact 13, 14, and 15 within the Call Event Logging report ... |
| CVE-2019-19615 | MEDIUM | 4.8 | 0.6% | Mar 16, 2020 | Multiple XSS vulnerabilities exist in the Backup & Restore module \ v14.0.10.2 through v14.0.10.7 for FreePBX, as shown ... |
| CVE-2019-19613 | MEDIUM | 5.2 | 0.5% | Mar 16, 2020 | An issue was discovered in Halvotec RaQuest 10.23.10801.0. The login page of the admin application is vulnerable to an O... |
| CVE-2019-19612 | MEDIUM | 5.4 | 0.7% | Mar 16, 2020 | An issue was discovered in Halvotec RaQuest 10.23.10801.0. Several features of the application allow stored Cross-site S... |
| CVE-2019-19610 | MEDIUM | 5.4 | 0.9% | Mar 16, 2020 | An issue was discovered in Halvotec RaQuest 10.23.10801.0. It allows session fixation. Fixed in Release 24.2020.20608.0. |
| CVE-2019-19538 | HIGH | 7.2 | 3.1% | Mar 16, 2020 | In Sangoma FreePBX 13 through 15 and sysadmin (aka System Admin) 13.0.92 through 15.0.13.6 modules have a Remote Command... |
| CVE-2019-19937 | HIGH | 7.2 | 1.5% | Mar 16, 2020 | In JFrog Artifactory before 6.18, it is not possible to restrict either system or repository imports by any admin user i... |
| CVE-2019-19461 | MEDIUM | 5.4 | 0.5% | Mar 16, 2020 | Post-authentication Stored XSS in Team Password Manager through 7.93.204 allows attackers to steal other users' credenti... |
| CVE-2019-19212 | CRITICAL | 9.8 | 3.9% | Mar 16, 2020 | Dolibarr ERP/CRM 3.0 through 10.0.3 allows XSS via the qty parameter to product/fournisseurs.php (product price screen). |
| CVE-2019-18917 | MEDIUM | 6.5 | 1.5% | Mar 16, 2020 | A potential security vulnerability has been identified for certain HP Printers and All-in-Ones that would allow bypassin... |
| CVE-2019-11073 | HIGH | 7.2 | 6.3% | Mar 16, 2020 | A Remote Code Execution vulnerability exists in PRTG Network Monitor before 19.4.54.1506 that allows attackers to execut... |
| CVE-2019-5543 | HIGH | 7.8 | 0.4% | Mar 16, 2020 | For VMware Horizon Client for Windows (5.x and prior before 5.3.0), VMware Remote Console for Windows (10.x before 11.0.... |
| CVE-2019-19946 | MEDIUM | 6.5 | 1.2% | Mar 16, 2020 | The API in Dradis Pro 3.4.1 allows any user to extract the content of a project, even if this user is not part of the pr... |
| CVE-2019-19945 | HIGH | 7.5 | 1.6% | Mar 16, 2020 | uhttpd in OpenWrt through 18.06.5 and 19.x through 19.07.0-rc2 has an integer signedness error. This leads to out-of-bou... |
| CVE-2019-19821 | HIGH | 8.1 | 1.4% | Mar 16, 2020 | A post-authentication privilege escalation in the web application of Combodo iTop allows regular authenticated users to ... |
| CVE-2019-4719 | MEDIUM | 5.5 | 0.3% | Mar 16, 2020 | IBM MQ and IBM MQ Appliance 7.1, 7.5, 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD could allow a local attacker to obtain sensitive... |
| CVE-2019-4656 | MEDIUM | 6.5 | 1.6% | Mar 16, 2020 | IBM MQ and IBM MQ Appliance 7.1, 7.5, 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD is vulnerable to a denial of service attack that... |
| CVE-2019-4619 | MEDIUM | 5.5 | 0.3% | Mar 16, 2020 | IBM MQ and IBM MQ Appliance 7.1, 7.5, 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD could allow a local attacker to obtain sensitive... |
| CVE-2019-4617 | MEDIUM | 4.4 | 0.3% | Mar 16, 2020 | IBM Cloud Automation Manager 3.2.1.0 does not renew a session variable after a successful authentication which could lea... |
| CVE-2019-19942 | HIGH | 7.5 | 1.6% | Mar 16, 2020 | Missing output sanitation in Swisscom Centro Grande Centro Grande before 6.16.12, Centro Business 1.0 (ADB) before 7.10.... |
| CVE-2019-19941 | MEDIUM | 5.4 | 0.7% | Mar 16, 2020 | Missing hostname validation in Swisscom Centro Grande before 6.16.12 allows a remote attacker to inject its local IP add... |
| CVE-2019-19940 | HIGH | 7.2 | 4.9% | Mar 16, 2020 | Incorrect input sanitation in text-oriented user interfaces (telnet, ssh) in Swisscom Centro Grande before 6.16.12 allow... |
| CVE-2019-19851 | MEDIUM | 4.8 | 0.5% | Mar 16, 2020 | An XSS Injection vulnerability exists in Sangoma FreePBX and PBXact 13, 14, and 15 within the Debug/Test page of the Sup... |
| CVE-2019-19135 | HIGH | 7.4 | 1.0% | Mar 16, 2020 | In OPC Foundation OPC UA .NET Standard codebase 1.4.357.28, servers do not create sufficiently random numbers in OPCFoun... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now