2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-19612MEDIUM5.4An issue was discovered in Halvotec RaQuest 10.23.10801.0. Several features of the application allow stored Cross-site S...
CVE-2019-19610MEDIUM5.4An issue was discovered in Halvotec RaQuest 10.23.10801.0. It allows session fixation. Fixed in Release 24.2020.20608.0.
CVE-2019-19538HIGH7.2In Sangoma FreePBX 13 through 15 and sysadmin (aka System Admin) 13.0.92 through 15.0.13.6 modules have a Remote Command...
CVE-2019-19937HIGH7.2In JFrog Artifactory before 6.18, it is not possible to restrict either system or repository imports by any admin user i...
CVE-2019-19461MEDIUM5.4Post-authentication Stored XSS in Team Password Manager through 7.93.204 allows attackers to steal other users' credenti...
CVE-2019-19212CRITICAL9.8Dolibarr ERP/CRM 3.0 through 10.0.3 allows XSS via the qty parameter to product/fournisseurs.php (product price screen).
CVE-2019-18917MEDIUM6.5A potential security vulnerability has been identified for certain HP Printers and All-in-Ones that would allow bypassin...
CVE-2019-11073HIGH7.2A Remote Code Execution vulnerability exists in PRTG Network Monitor before 19.4.54.1506 that allows attackers to execut...
CVE-2019-5543HIGH7.8For VMware Horizon Client for Windows (5.x and prior before 5.3.0), VMware Remote Console for Windows (10.x before 11.0....
CVE-2019-19946MEDIUM6.5The API in Dradis Pro 3.4.1 allows any user to extract the content of a project, even if this user is not part of the pr...
CVE-2019-19945HIGH7.5uhttpd in OpenWrt through 18.06.5 and 19.x through 19.07.0-rc2 has an integer signedness error. This leads to out-of-bou...
CVE-2019-19821HIGH8.1A post-authentication privilege escalation in the web application of Combodo iTop allows regular authenticated users to ...
CVE-2019-4719MEDIUM5.5IBM MQ and IBM MQ Appliance 7.1, 7.5, 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD could allow a local attacker to obtain sensitive...
CVE-2019-4656MEDIUM6.5IBM MQ and IBM MQ Appliance 7.1, 7.5, 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD is vulnerable to a denial of service attack that...
CVE-2019-4619MEDIUM5.5IBM MQ and IBM MQ Appliance 7.1, 7.5, 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD could allow a local attacker to obtain sensitive...
CVE-2019-4617MEDIUM4.4IBM Cloud Automation Manager 3.2.1.0 does not renew a session variable after a successful authentication which could lea...
CVE-2019-19942HIGH7.5Missing output sanitation in Swisscom Centro Grande Centro Grande before 6.16.12, Centro Business 1.0 (ADB) before 7.10....
CVE-2019-19941MEDIUM5.4Missing hostname validation in Swisscom Centro Grande before 6.16.12 allows a remote attacker to inject its local IP add...
CVE-2019-19940HIGH7.2Incorrect input sanitation in text-oriented user interfaces (telnet, ssh) in Swisscom Centro Grande before 6.16.12 allow...
CVE-2019-19851MEDIUM4.8An XSS Injection vulnerability exists in Sangoma FreePBX and PBXact 13, 14, and 15 within the Debug/Test page of the Sup...
CVE-2019-19135HIGH7.4In OPC Foundation OPC UA .NET Standard codebase 1.4.357.28, servers do not create sufficiently random numbers in OPCFoun...
CVE-2019-19211MEDIUM6.1Dolibarr ERP/CRM before 10.0.3 has an Insufficient Filtering issue that can lead to user/card.php XSS.
CVE-2019-19210MEDIUM5.4Dolibarr ERP/CRM before 10.0.3 allows XSS because uploaded HTML documents are served as text/html despite being renamed ...
CVE-2019-19209HIGH7.5Dolibarr ERP/CRM before 10.0.3 allows SQL Injection.
CVE-2019-19208CRITICAL9.8Codiad Web IDE through 2.8.4 allows PHP Code injection.

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now