2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-17345MEDIUM6.5An issue was discovered in Xen 4.8.x through 4.11.x allowing x86 PV guest OS users to cause a denial of service because ...
CVE-2019-17344MEDIUM6.5An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service by leveraging ...
CVE-2019-17343MEDIUM6.8An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privil...
CVE-2019-17351MEDIUM6.5An issue was discovered in drivers/xen/balloon.c in the Linux kernel before 5.2.3, as used in Xen through 4.12.x, allowi...
CVE-2019-17350MEDIUM5.5An issue was discovered in Xen through 4.12.x allowing Arm domU attackers to cause a denial of service (infinite loop) i...
CVE-2019-17233MEDIUM6.1Functions/EWD_UFAQ_Import.php in the ultimate-faqs plugin through 1.8.24 for WordPress allows HTML content injection.
CVE-2019-17239MEDIUM6.1includes/settings/class-alg-download-plugins-settings.php in the download-plugins-dashboard plugin through 1.5.0 for Wor...
CVE-2019-15894MEDIUM6.8An issue was discovered in Espressif ESP-IDF 2.x, 3.0.x through 3.0.9, 3.1.x through 3.1.6, 3.2.x through 3.2.3, and 3.3...
CVE-2019-15750MEDIUM6.1A Cross-Site Scripting (XSS) vulnerability in the blog function in SITOS six Build v6.2.1 allows remote attackers to inj...
CVE-2019-15749MEDIUM6.5SITOS six Build v6.2.1 allows a user to change their password and recovery email address without requiring them to confi...
CVE-2019-17226MEDIUM4.8CMS Made Simple (CMSMS) 2.2.11 allows XSS via the Site Admin > Module Manager > Search Term field.
CVE-2019-17225MEDIUM5.4Subrion 4.2.1 allows XSS via the panel/members/ Username, Full Name, or Email field, aka an "Admin Member JSON Update" i...
CVE-2019-17213MEDIUM6.1The WebARX plugin 1.3.0 for WordPress has unauthenticated stored XSS via the URI or the X-Forwarded-For HTTP header.
CVE-2019-17205MEDIUM6.1TeamPass 2.1.27.36 allows Stored XSS by placing a payload in the username field during a login attempt. When an administ...
CVE-2019-17204MEDIUM5.4TeamPass 2.1.27.36 allows Stored XSS by setting a crafted Knowledge Base label and adding any available item.
CVE-2019-17203MEDIUM5.4TeamPass 2.1.27.36 allows Stored XSS at the Search page by setting a crafted password for an item in any folder.
CVE-2019-11656MEDIUM5.4Stored XSS vulnerability in Micro Focus ArcSight Logger, affects versions prior to Logger 6.7.1 HotFix 6.7.1.8262.0. Thi...
CVE-2019-17179MEDIUM6.14.1.0, 4.1.1, 4.1.2, 4.1.2.3, 4.1.2.6, 4.1.2.7, 4.2.0, 4.2.1, 4.2.2, 5.0.0, 5.0.0.5, 5.0.0.6, 5.0.1, 5.0.1.1, 5.0.1.2, 5...
CVE-2019-13318MEDIUM5.5This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Reader 9...
CVE-2019-4564MEDIUM6.1IBM Security Key Lifecycle Manager 2.6, 2.7, 3.0, and 3.0.1 is vulnerable to cross-site scripting. This vulnerability al...
CVE-2019-4514MEDIUM5.3IBM Security Key Lifecycle Manager 2.6, 2.7, 3.0, and 3.0.1 discloses sensitive information to unauthorized users. The i...
CVE-2019-17131MEDIUM4.3vBulletin before 5.5.4 allows clickjacking.
CVE-2019-17130MEDIUM6.5vBulletin through 5.5.4 mishandles external URLs within the /core/vb/vurl.php file and the /core/vb/vurl directories.
CVE-2019-17121MEDIUM5.4REDCap before 9.3.4 has XSS on the Customize & Manage Locking/E-signatures page via Lock Record Custom Text values.
CVE-2019-16198MEDIUM6.5KSLabs KSWEB 3.93 allows ../ directory traversal, as demonstrated by the hostFile parameter.

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now