2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-19612 | MEDIUM | 5.4 | 0.7% | Mar 16, 2020 | An issue was discovered in Halvotec RaQuest 10.23.10801.0. Several features of the application allow stored Cross-site S... |
| CVE-2019-19610 | MEDIUM | 5.4 | 0.9% | Mar 16, 2020 | An issue was discovered in Halvotec RaQuest 10.23.10801.0. It allows session fixation. Fixed in Release 24.2020.20608.0. |
| CVE-2019-19538 | HIGH | 7.2 | 3.1% | Mar 16, 2020 | In Sangoma FreePBX 13 through 15 and sysadmin (aka System Admin) 13.0.92 through 15.0.13.6 modules have a Remote Command... |
| CVE-2019-19937 | HIGH | 7.2 | 1.5% | Mar 16, 2020 | In JFrog Artifactory before 6.18, it is not possible to restrict either system or repository imports by any admin user i... |
| CVE-2019-19461 | MEDIUM | 5.4 | 0.5% | Mar 16, 2020 | Post-authentication Stored XSS in Team Password Manager through 7.93.204 allows attackers to steal other users' credenti... |
| CVE-2019-19212 | CRITICAL | 9.8 | 3.9% | Mar 16, 2020 | Dolibarr ERP/CRM 3.0 through 10.0.3 allows XSS via the qty parameter to product/fournisseurs.php (product price screen). |
| CVE-2019-18917 | MEDIUM | 6.5 | 1.5% | Mar 16, 2020 | A potential security vulnerability has been identified for certain HP Printers and All-in-Ones that would allow bypassin... |
| CVE-2019-11073 | HIGH | 7.2 | 6.3% | Mar 16, 2020 | A Remote Code Execution vulnerability exists in PRTG Network Monitor before 19.4.54.1506 that allows attackers to execut... |
| CVE-2019-5543 | HIGH | 7.8 | 0.4% | Mar 16, 2020 | For VMware Horizon Client for Windows (5.x and prior before 5.3.0), VMware Remote Console for Windows (10.x before 11.0.... |
| CVE-2019-19946 | MEDIUM | 6.5 | 1.2% | Mar 16, 2020 | The API in Dradis Pro 3.4.1 allows any user to extract the content of a project, even if this user is not part of the pr... |
| CVE-2019-19945 | HIGH | 7.5 | 1.6% | Mar 16, 2020 | uhttpd in OpenWrt through 18.06.5 and 19.x through 19.07.0-rc2 has an integer signedness error. This leads to out-of-bou... |
| CVE-2019-19821 | HIGH | 8.1 | 1.4% | Mar 16, 2020 | A post-authentication privilege escalation in the web application of Combodo iTop allows regular authenticated users to ... |
| CVE-2019-4719 | MEDIUM | 5.5 | 0.3% | Mar 16, 2020 | IBM MQ and IBM MQ Appliance 7.1, 7.5, 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD could allow a local attacker to obtain sensitive... |
| CVE-2019-4656 | MEDIUM | 6.5 | 1.6% | Mar 16, 2020 | IBM MQ and IBM MQ Appliance 7.1, 7.5, 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD is vulnerable to a denial of service attack that... |
| CVE-2019-4619 | MEDIUM | 5.5 | 0.3% | Mar 16, 2020 | IBM MQ and IBM MQ Appliance 7.1, 7.5, 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD could allow a local attacker to obtain sensitive... |
| CVE-2019-4617 | MEDIUM | 4.4 | 0.3% | Mar 16, 2020 | IBM Cloud Automation Manager 3.2.1.0 does not renew a session variable after a successful authentication which could lea... |
| CVE-2019-19942 | HIGH | 7.5 | 1.6% | Mar 16, 2020 | Missing output sanitation in Swisscom Centro Grande Centro Grande before 6.16.12, Centro Business 1.0 (ADB) before 7.10.... |
| CVE-2019-19941 | MEDIUM | 5.4 | 0.7% | Mar 16, 2020 | Missing hostname validation in Swisscom Centro Grande before 6.16.12 allows a remote attacker to inject its local IP add... |
| CVE-2019-19940 | HIGH | 7.2 | 4.9% | Mar 16, 2020 | Incorrect input sanitation in text-oriented user interfaces (telnet, ssh) in Swisscom Centro Grande before 6.16.12 allow... |
| CVE-2019-19851 | MEDIUM | 4.8 | 0.5% | Mar 16, 2020 | An XSS Injection vulnerability exists in Sangoma FreePBX and PBXact 13, 14, and 15 within the Debug/Test page of the Sup... |
| CVE-2019-19135 | HIGH | 7.4 | 1.0% | Mar 16, 2020 | In OPC Foundation OPC UA .NET Standard codebase 1.4.357.28, servers do not create sufficiently random numbers in OPCFoun... |
| CVE-2019-19211 | MEDIUM | 6.1 | 1.7% | Mar 16, 2020 | Dolibarr ERP/CRM before 10.0.3 has an Insufficient Filtering issue that can lead to user/card.php XSS. |
| CVE-2019-19210 | MEDIUM | 5.4 | 0.9% | Mar 16, 2020 | Dolibarr ERP/CRM before 10.0.3 allows XSS because uploaded HTML documents are served as text/html despite being renamed ... |
| CVE-2019-19209 | HIGH | 7.5 | 2.1% | Mar 16, 2020 | Dolibarr ERP/CRM before 10.0.3 allows SQL Injection. |
| CVE-2019-19208 | CRITICAL | 9.8 | 19.2% | Mar 16, 2020 | Codiad Web IDE through 2.8.4 allows PHP Code injection. |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now