2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-17063 | MEDIUM | 5.5 | 0.8% | Oct 1, 2019 | In Snowtide PDFxStream before 3.7.1 (for Java), a crafted PDF file can trigger an extremely long running computation bec... |
| CVE-2019-14957 | MEDIUM | 5.3 | 1.1% | Oct 1, 2019 | The JetBrains Vim plugin before version 0.52 was storing individual project data in the global vim_settings.xml file. Th... |
| CVE-2019-14955 | MEDIUM | 5.3 | 0.9% | Oct 1, 2019 | In JetBrains Hub versions earlier than 2018.4.11436, there was no option to force a user to change the password and no p... |
| CVE-2019-14953 | MEDIUM | 6.1 | 0.9% | Oct 1, 2019 | JetBrains YouTrack versions before 2019.2.53938 had a possible XSS through issue attachments when using the Firefox brow... |
| CVE-2019-4497 | MEDIUM | 5.4 | 0.7% | Oct 1, 2019 | IBM Jazz Reporting Service (JRS) 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, and 6.0.6.1 is vulnerable to cross-site ... |
| CVE-2019-4495 | MEDIUM | 5.4 | 0.7% | Oct 1, 2019 | IBM Jazz Reporting Service (JRS) 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, and 6.0.6.1 is vulnerable to cross-site ... |
| CVE-2019-4494 | MEDIUM | 5.4 | 0.7% | Oct 1, 2019 | IBM Jazz Reporting Service (JRS) 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, and 6.0.6.1 is vulnerable to cross-site ... |
| CVE-2019-4246 | MEDIUM | 5.3 | 1.2% | Oct 1, 2019 | IBM Daeja ViewONE Virtual 5.0 through 5.0.6 could expose internal parameters to ViewONE clients that could be used in fu... |
| CVE-2019-11275 | MEDIUM | 4.3 | 1.1% | Oct 1, 2019 | Pivotal Application Manager, versions 666.0.x prior to 666.0.36, versions 667.0.x prior to 667.0.22, versions 668.0.x pr... |
| CVE-2019-14954 | MEDIUM | 5.9 | 0.7% | Oct 1, 2019 | JetBrains IntelliJ IDEA before 2019.2 was resolving the markdown plantuml artifact download link via a cleartext http co... |
| CVE-2019-14952 | MEDIUM | 6.1 | 1.1% | Oct 1, 2019 | JetBrains YouTrack versions before 2019.1.52584 had a possible XSS in the issue titles. |
| CVE-2019-10432 | MEDIUM | 5.4 | 1.2% | Oct 1, 2019 | Jenkins HTML Publisher Plugin 1.20 and earlier did not escape the project and build display names in the HTML report fra... |
| CVE-2019-3733 | MEDIUM | 4.9 | 0.6% | Sep 30, 2019 | RSA BSAFE Crypto-C Micro Edition, all versions prior to 4.1.4, is vulnerable to three (3) different Improper Clearing of... |
| CVE-2019-13467 | MEDIUM | 5.9 | 1.5% | Sep 30, 2019 | Description: Western Digital SSD Dashboard before 2.5.1.0 and SanDisk SSD Dashboard before 2.5.1.0 applications are pote... |
| CVE-2019-15810 | MEDIUM | 6.1 | 0.9% | Sep 30, 2019 | Insufficient sanitization during device search in Netdisco 2.042010 allows for reflected XSS via manipulation of a URL p... |
| CVE-2019-4423 | MEDIUM | 5.3 | 2.7% | Sep 30, 2019 | IBM Sterling File Gateway 2.2.0.0 through 6.0.1.0 could allow a remote attacker to traverse directories on the system. A... |
| CVE-2019-4305 | MEDIUM | 5.3 | 1.5% | Sep 30, 2019 | IBM WebSphere Application Server Liberty could allow a remote attacker to obtain sensitive information caused by the imp... |
| CVE-2019-4304 | MEDIUM | 6.3 | 1.1% | Sep 30, 2019 | IBM WebSphere Application Server - Liberty could allow a remote attacker to bypass security restrictions caused by impro... |
| CVE-2019-4280 | MEDIUM | 5.3 | 0.8% | Sep 30, 2019 | IBM Sterling File Gateway 2.2.0.0 through 6.0.1.0 displays sensitive information in HTTP requests which could be used in... |
| CVE-2019-4115 | MEDIUM | 5.4 | 0.7% | Sep 30, 2019 | IBM WebSphere eXtreme Scale 8.6 Admin API is vulnerable to cross-site scripting. This vulnerability allows users to embe... |
| CVE-2019-4109 | MEDIUM | 6.1 | 1.3% | Sep 30, 2019 | IBM WebSphere eXtreme Scale 8.6 Admin Console could allow a remote attacker to hijack the clicking action of the victim.... |
| CVE-2019-4106 | MEDIUM | 4.8 | 0.7% | Sep 30, 2019 | IBM WebSphere eXtreme Scale 8.6 Admin Console is vulnerable to cross-site scripting. This vulnerability allows users to ... |
| CVE-2019-16684 | MEDIUM | 4.8 | 1.0% | Sep 30, 2019 | An issue was discovered in the image-manager in Xoops 2.5.10. When any image with a JavaScript payload as its name is ho... |
| CVE-2019-16683 | MEDIUM | 4.8 | 1.0% | Sep 30, 2019 | An issue was discovered in the image-manager in Xoops 2.5.10. When the breadcrumb showing the category name is hovered o... |
| CVE-2019-17045 | MEDIUM | 4.8 | 0.7% | Sep 30, 2019 | Ilch 2.1.22 allows stored XSS via the title, text, or email id to the Jobs Tab. |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now