2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-20101MEDIUM5.3Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view whitelist rules via ...
CVE-2019-5318MEDIUM6.5A remote cross-site request forgery (csrf) vulnerability was discovered in Aruba Operating System Software version(s): 6...
CVE-2019-11098MEDIUM6.8Insufficient input validation in MdeModulePkg in EDKII may allow an unauthenticated user to potentially enable escalatio...
CVE-2019-25047MEDIUM6.1Greenbone Security Assistant (GSA) before 8.0.2 and Greenbone OS (GOS) before 5.0.10 allow XSS during 404 URL handling i...
CVE-2019-9475MEDIUM5.5In /proc/net of the kernel filesystem, there is a possible information leak due to a permissions bypass. This could lead...
CVE-2019-25046MEDIUM6.1The Web Client in Cerberus FTP Server Enterprise before 10.0.19 and 11.x before 11.0.4 allows XSS via an SVG document.
CVE-2019-17567MEDIUM5.3Apache HTTP Server versions 2.4.6 to 2.4.46 mod_proxy_wstunnel configured on an URL that is not necessarily Upgraded by ...
CVE-2019-12067MEDIUM6.5The ahci_commit_buf function in ide/ahci.c in QEMU allows attackers to cause a denial of service (NULL dereference) when...
CVE-2019-4722MEDIUM4.3IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain sensitive information via a stack trace due t...
CVE-2019-4653MEDIUM5.4IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbit...
CVE-2019-4471MEDIUM6.5IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain sensitive information, caused by the failure ...
CVE-2019-25030MEDIUM5.5In Versa Director, Versa Analytics and VOS, Passwords are not hashed using an adaptive cryptographic hash function or ke...
CVE-2019-14827MEDIUM6.1A vulnerability was found in Moodle where javaScript injection was possible in some Mustache templates via recursive ren...
CVE-2019-10062MEDIUM6.1The HTMLSanitizer class in html-sanitizer.ts in all released versions of the Aurelia framework 1.x repository is vulnera...
CVE-2019-19276MEDIUM5.3A vulnerability has been identified in SIMATIC HMI Comfort Panels 1st Generation (incl. SIPLUS variants) (All versions <...
CVE-2019-25043MEDIUM5.3ModSecurity 3.x before 3.0.4 mishandles key-value pair parsing, as demonstrated by a "string index out of range" error a...
CVE-2019-25031MEDIUM5.9Unbound before 1.9.5 allows configuration injection in create_unbound_ad_servers.sh upon a successful man-in-the-middle ...
CVE-2019-25028MEDIUM6.1Missing variable sanitization in Grid component in com.vaadin:vaadin-server versions 7.4.0 through 7.7.19 (Vaadin 7.4.0 ...
CVE-2019-25027MEDIUM6.1Missing output sanitization in default RouteNotFoundError view in com.vaadin:flow-server versions 1.0.0 through 1.0.10 (...
CVE-2019-17656MEDIUM6.5A Stack-based Buffer Overflow vulnerability in the HTTPD daemon of FortiOS 6.0.10 and below, 6.2.2 and below and FortiPr...
CVE-2019-25026MEDIUM5.3Redmine before 3.4.13 and 4.x before 4.0.6 mishandles markup data during Textile formatting.
CVE-2019-5317MEDIUM6.8A local authentication bypass vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(...
CVE-2019-14831MEDIUM6.1A vulnerability was found in Moodle 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions, where for...
CVE-2019-14830MEDIUM6.1A vulnerability was found in Moodle 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions, where the...
CVE-2019-14829MEDIUM4.3A vulnerability was found in Moodle affection 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions ...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now