2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-16931 | MEDIUM | 6.1 | 3.3% | Oct 3, 2019 | A stored XSS vulnerability in the Visualizer plugin 3.3.0 for WordPress allows an unauthenticated attacker to execute ar... |
| CVE-2019-15165 | MEDIUM | 5.3 | 2.8% | Oct 3, 2019 | sf-pcapng.c in libpcap before 1.9.1 does not properly validate the PHB header length before allocating memory. |
| CVE-2019-15164 | MEDIUM | 5.3 | 2.9% | Oct 3, 2019 | rpcapd/daemon.c in libpcap before 1.9.1 allows SSRF because a URL may be provided as a capture source. |
| CVE-2019-15162 | MEDIUM | 5.3 | 1.8% | Oct 3, 2019 | rpcapd/daemon.c in libpcap before 1.9.1 on non-Windows platforms provides details about why authentication failed, which... |
| CVE-2019-15161 | MEDIUM | 5.3 | 2.8% | Oct 3, 2019 | rpcapd/daemon.c in libpcap before 1.9.1 mishandles certain length values because of reuse of a variable. This may open u... |
| CVE-2019-4441 | MEDIUM | 5.3 | 1.8% | Oct 3, 2019 | IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0, and Liberty could allow a remote attacker to obtain sensitive infor... |
| CVE-2019-15809 | MEDIUM | 4.7 | 0.5% | Oct 3, 2019 | Smart cards from the Athena SCS manufacturer, based on the Atmel Toolbox 00.03.11.05 and the AT90SC chip, contain a timi... |
| CVE-2019-13629 | MEDIUM | 5.9 | 1.2% | Oct 3, 2019 | MatrixSSL 4.2.1 and earlier contains a timing side channel in ECDSA signature generation. This allows a local or a remot... |
| CVE-2019-13628 | MEDIUM | 4.7 | 0.4% | Oct 3, 2019 | wolfSSL and wolfCrypt 4.0.0 and earlier (when configured without --enable-fpecc, --enable-sp, or --enable-sp-math) conta... |
| CVE-2019-11651 | MEDIUM | 6.1 | 0.8% | Oct 2, 2019 | Reflected XSS on Micro Focus Enterprise Developer and Enterprise Server, all versions prior to version 3.0 Patch Update ... |
| CVE-2019-1915 | MEDIUM | 6.5 | 0.7% | Oct 2, 2019 | A vulnerability in the web-based interface of Cisco Unified Communications Manager, Cisco Unified Communications Manager... |
| CVE-2019-16171 | MEDIUM | 6.1 | 1.1% | Oct 2, 2019 | In JetBrains YouTrack through 2019.2.56594, stored XSS was found on the issue page. |
| CVE-2019-15272 | MEDIUM | 6.5 | 1.3% | Oct 2, 2019 | A vulnerability in the web-based interface of Cisco Unified Communications Manager and Cisco Unified Communications Mana... |
| CVE-2019-15259 | MEDIUM | 6.1 | 1.1% | Oct 2, 2019 | A vulnerability in Cisco Unified Contact Center Express (UCCX) Software could allow an unauthenticated, remote attacker ... |
| CVE-2019-15037 | MEDIUM | 6.1 | 0.8% | Oct 2, 2019 | An issue was discovered in JetBrains TeamCity 2018.2.4. It had several XSS vulnerabilities on the settings pages. The is... |
| CVE-2019-14959 | MEDIUM | 5.9 | 0.7% | Oct 2, 2019 | JetBrains Toolbox before 1.15.5605 was resolving an internal URL via a cleartext http connection. |
| CVE-2019-14956 | MEDIUM | 4.3 | 1.0% | Oct 2, 2019 | JetBrains YouTrack before 2019.2.53938 was using incorrect settings, allowing a user without necessary permissions to ge... |
| CVE-2019-12737 | MEDIUM | 5.3 | 0.7% | Oct 2, 2019 | UserHashedTableAuth in JetBrains Ktor framework before 1.2.0-rc uses a One-Way Hash with a Predictable Salt for storing ... |
| CVE-2019-12716 | MEDIUM | 6.1 | 1.1% | Oct 2, 2019 | A vulnerability in the web-based interface of Cisco Unified Communications Manager and Cisco Unified Communications Mana... |
| CVE-2019-12715 | MEDIUM | 6.1 | 1.1% | Oct 2, 2019 | A vulnerability in the web-based interface of Cisco Unified Communications Manager and Cisco Unified Communications Mana... |
| CVE-2019-12714 | MEDIUM | 6.5 | 1.5% | Oct 2, 2019 | A vulnerability in the web-based management interface of Cisco IC3000 Industrial Compute Gateway could allow an authenti... |
| CVE-2019-12713 | MEDIUM | 6.1 | 1.1% | Oct 2, 2019 | A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an unauthenticated, remo... |
| CVE-2019-12712 | MEDIUM | 6.1 | 1.1% | Oct 2, 2019 | A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an unauthenticated, remo... |
| CVE-2019-12711 | MEDIUM | 6.5 | 1.1% | Oct 2, 2019 | A vulnerability in the web-based interface of Cisco Unified Communications Manager and Cisco Unified Communications Mana... |
| CVE-2019-12710 | MEDIUM | 4.9 | 1.5% | Oct 2, 2019 | A vulnerability in the web-based interface of Cisco Unified Communications Manager and Cisco Unified Communications Mana... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now