2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-12707MEDIUM6.1A vulnerability in the web-based interface of multiple Cisco Unified Communications products could allow an unauthentica...
CVE-2019-12701MEDIUM5.8A vulnerability in the file and malware inspection feature of Cisco Firepower Management Center (FMC) Software could all...
CVE-2019-12700MEDIUM6.5A vulnerability in the configuration of the Pluggable Authentication Module (PAM) used in Cisco Firepower Threat Defense...
CVE-2019-12695MEDIUM6.1A vulnerability in the Clientless SSL VPN (WebVPN) portal of Cisco Adaptive Security Appliance (ASA) and Cisco Firepower...
CVE-2019-12694MEDIUM6.7A vulnerability in the command line interface (CLI) of Cisco Firepower Threat Defense (FTD) Software could allow an auth...
CVE-2019-12693MEDIUM4.9A vulnerability in the Secure Copy (SCP) feature of Cisco Adaptive Security Appliance (ASA) Software could allow an auth...
CVE-2019-12691MEDIUM4.9A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an...
CVE-2019-12677MEDIUM6.5A vulnerability in the Secure Sockets Layer (SSL) VPN feature of Cisco Adaptive Security Appliance (ASA) Software could ...
CVE-2019-12631MEDIUM6.1A vulnerability in the web-based guest portal of Cisco Identity Services Engine (ISE) could allow an unauthenticated, re...
CVE-2019-12156MEDIUM5.3Server metadata could be exposed because one of the error messages reflected the whole response back to the client in Je...
CVE-2019-16116MEDIUM4.3EnterpriseDT CompleteFTP Server prior to version 12.1.3 is vulnerable to information exposure in the Bootstrap.log file....
CVE-2019-4549MEDIUM5.3IBM Security Directory Server 6.4.0 discloses sensitive information to unauthorized users. The information can be used t...
CVE-2019-4542MEDIUM6.1IBM Security Directory Server 6.4.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbi...
CVE-2019-17091MEDIUM6.1faces/context/PartialViewContextImpl.java in Eclipse Mojarra, as used in Mojarra for Eclipse EE4J before 2.3.10 and Moja...
CVE-2019-8292MEDIUM5.3Online Store System v1.0 delete_product.php doesn't check to see if a user authtenticated or has administrative rights a...
CVE-2019-8290MEDIUM6.1Vulnerability in Online Store v1.0, The registration form requirements for the member email format can be bypassed by po...
CVE-2019-8289MEDIUM5.4Vulnerability in Online Store v1.0, stored XSS in admin/user_view.php adidas_member_email variable
CVE-2019-8288MEDIUM5.4Vulnerability in Online Store v1.0, Stored XSS in user_view.php where adidas_member_user variable is not sanitized.
CVE-2019-17074MEDIUM5.4An issue was discovered in XunRuiCMS 4.3.1. There is a stored XSS in the module_category area.
CVE-2019-17073MEDIUM6.5emlog through 6.0.0beta allows remote authenticated users to delete arbitrary files via admin/template.php?action=del&tp...
CVE-2019-15041MEDIUM6.1JetBrains YouTrack versions before 2019.1.52545 allowed unbounded URL whitelisting because of Inclusion of Functionality...
CVE-2019-15035MEDIUM4.9An issue was discovered in JetBrains TeamCity 2018.2.4. A TeamCity Project administrator could get access to potentially...
CVE-2019-7618MEDIUM6.5A local file disclosure flaw was found in Elastic Code versions 7.3.0, 7.3.1, and 7.3.2. If a malicious code repository ...
CVE-2019-14961MEDIUM6.1JetBrains Upsource before 2019.1.1412 was not properly escaping HTML tags in a code block comments, leading to XSS.
CVE-2019-17064MEDIUM5.5Catalog.cc in Xpdf 4.02 has a NULL pointer dereference because Catalog.pageLabels is initialized too late in the Catalog...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now