2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-17345 | MEDIUM | 6.5 | 0.4% | Oct 8, 2019 | An issue was discovered in Xen 4.8.x through 4.11.x allowing x86 PV guest OS users to cause a denial of service because ... |
| CVE-2019-17344 | MEDIUM | 6.5 | 0.4% | Oct 8, 2019 | An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service by leveraging ... |
| CVE-2019-17343 | MEDIUM | 6.8 | 0.3% | Oct 8, 2019 | An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privil... |
| CVE-2019-17351 | MEDIUM | 6.5 | 0.4% | Oct 8, 2019 | An issue was discovered in drivers/xen/balloon.c in the Linux kernel before 5.2.3, as used in Xen through 4.12.x, allowi... |
| CVE-2019-17350 | MEDIUM | 5.5 | 0.4% | Oct 8, 2019 | An issue was discovered in Xen through 4.12.x allowing Arm domU attackers to cause a denial of service (infinite loop) i... |
| CVE-2019-17233 | MEDIUM | 6.1 | 1.8% | Oct 7, 2019 | Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows HTML content injection. |
| CVE-2019-17239 | MEDIUM | 6.1 | 0.9% | Oct 7, 2019 | includes/settings/class-alg-download-plugins-settings.php in the download-plugins-dashboard plugin through 1.5.0 for Wor... |
| CVE-2019-15894 | MEDIUM | 6.8 | 0.5% | Oct 7, 2019 | An issue was discovered in Espressif ESP-IDF 2.x, 3.0.x through 3.0.9, 3.1.x through 3.1.6, 3.2.x through 3.2.3, and 3.3... |
| CVE-2019-15750 | MEDIUM | 6.1 | 1.0% | Oct 7, 2019 | A Cross-Site Scripting (XSS) vulnerability in the blog function in SITOS six Build v6.2.1 allows remote attackers to inj... |
| CVE-2019-15749 | MEDIUM | 6.5 | 1.0% | Oct 7, 2019 | SITOS six Build v6.2.1 allows a user to change their password and recovery email address without requiring them to confi... |
| CVE-2019-17226 | MEDIUM | 4.8 | 0.6% | Oct 6, 2019 | CMS Made Simple (CMSMS) 2.2.11 allows XSS via the Site Admin > Module Manager > Search Term field. |
| CVE-2019-17225 | MEDIUM | 5.4 | 1.9% | Oct 6, 2019 | Subrion 4.2.1 allows XSS via the panel/members/ Username, Full Name, or Email field, aka an "Admin Member JSON Update" i... |
| CVE-2019-17213 | MEDIUM | 6.1 | 1.2% | Oct 6, 2019 | The WebARX plugin 1.3.0 for WordPress has unauthenticated stored XSS via the URI or the X-Forwarded-For HTTP header. |
| CVE-2019-17205 | MEDIUM | 6.1 | 1.0% | Oct 5, 2019 | TeamPass 2.1.27.36 allows Stored XSS by placing a payload in the username field during a login attempt. When an administ... |
| CVE-2019-17204 | MEDIUM | 5.4 | 0.6% | Oct 5, 2019 | TeamPass 2.1.27.36 allows Stored XSS by setting a crafted Knowledge Base label and adding any available item. |
| CVE-2019-17203 | MEDIUM | 5.4 | 0.6% | Oct 5, 2019 | TeamPass 2.1.27.36 allows Stored XSS at the Search page by setting a crafted password for an item in any folder. |
| CVE-2019-11656 | MEDIUM | 5.4 | 0.6% | Oct 4, 2019 | Stored XSS vulnerability in Micro Focus ArcSight Logger, affects versions prior to Logger 6.7.1 HotFix 6.7.1.8262.0. Thi... |
| CVE-2019-17179 | MEDIUM | 6.1 | 0.9% | Oct 4, 2019 | 4.1.0, 4.1.1, 4.1.2, 4.1.2.3, 4.1.2.6, 4.1.2.7, 4.2.0, 4.2.1, 4.2.2, 5.0.0, 5.0.0.5, 5.0.0.6, 5.0.1, 5.0.1.1, 5.0.1.2, 5... |
| CVE-2019-13318 | MEDIUM | 5.5 | 5.8% | Oct 4, 2019 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Reader 9... |
| CVE-2019-4564 | MEDIUM | 6.1 | 0.9% | Oct 4, 2019 | IBM Security Key Lifecycle Manager 2.6, 2.7, 3.0, and 3.0.1 is vulnerable to cross-site scripting. This vulnerability al... |
| CVE-2019-4514 | MEDIUM | 5.3 | 1.3% | Oct 4, 2019 | IBM Security Key Lifecycle Manager 2.6, 2.7, 3.0, and 3.0.1 discloses sensitive information to unauthorized users. The i... |
| CVE-2019-17131 | MEDIUM | 4.3 | 0.8% | Oct 4, 2019 | vBulletin before 5.5.4 allows clickjacking. |
| CVE-2019-17130 | MEDIUM | 6.5 | 1.0% | Oct 4, 2019 | vBulletin through 5.5.4 mishandles external URLs within the /core/vb/vurl.php file and the /core/vb/vurl directories. |
| CVE-2019-17121 | MEDIUM | 5.4 | 0.6% | Oct 4, 2019 | REDCap before 9.3.4 has XSS on the Customize & Manage Locking/E-signatures page via Lock Record Custom Text values. |
| CVE-2019-16198 | MEDIUM | 6.5 | 1.6% | Oct 3, 2019 | KSLabs KSWEB 3.93 allows ../ directory traversal, as demonstrated by the hostFile parameter. |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now