2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-20101 | MEDIUM | 5.3 | 1.3% | Sep 14, 2021 | Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view whitelist rules via ... |
| CVE-2019-5318 | MEDIUM | 6.5 | 0.4% | Sep 7, 2021 | A remote cross-site request forgery (csrf) vulnerability was discovered in Aruba Operating System Software version(s): 6... |
| CVE-2019-11098 | MEDIUM | 6.8 | 0.3% | Jul 14, 2021 | Insufficient input validation in MdeModulePkg in EDKII may allow an unauthenticated user to potentially enable escalatio... |
| CVE-2019-25047 | MEDIUM | 6.1 | 1.1% | Jun 21, 2021 | Greenbone Security Assistant (GSA) before 8.0.2 and Greenbone OS (GOS) before 5.0.10 allow XSS during 404 URL handling i... |
| CVE-2019-9475 | MEDIUM | 5.5 | 0.1% | Jun 11, 2021 | In /proc/net of the kernel filesystem, there is a possible information leak due to a permissions bypass. This could lead... |
| CVE-2019-25046 | MEDIUM | 6.1 | 1.8% | Jun 10, 2021 | The Web Client in Cerberus FTP Server Enterprise before 10.0.19 and 11.x before 11.0.4 allows XSS via an SVG document. |
| CVE-2019-17567 | MEDIUM | 5.3 | 60.3% | Jun 10, 2021 | Apache HTTP Server versions 2.4.6 to 2.4.46 mod_proxy_wstunnel configured on an URL that is not necessarily Upgraded by ... |
| CVE-2019-12067 | MEDIUM | 6.5 | 0.3% | Jun 2, 2021 | The ahci_commit_buf function in ide/ahci.c in QEMU allows attackers to cause a denial of service (NULL dereference) when... |
| CVE-2019-4722 | MEDIUM | 4.3 | 1.4% | Jun 1, 2021 | IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain sensitive information via a stack trace due t... |
| CVE-2019-4653 | MEDIUM | 5.4 | 0.8% | Jun 1, 2021 | IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbit... |
| CVE-2019-4471 | MEDIUM | 6.5 | 1.0% | Jun 1, 2021 | IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain sensitive information, caused by the failure ... |
| CVE-2019-25030 | MEDIUM | 5.5 | 0.2% | May 26, 2021 | In Versa Director, Versa Analytics and VOS, Passwords are not hashed using an adaptive cryptographic hash function or ke... |
| CVE-2019-14827 | MEDIUM | 6.1 | 0.7% | May 17, 2021 | A vulnerability was found in Moodle where javaScript injection was possible in some Mustache templates via recursive ren... |
| CVE-2019-10062 | MEDIUM | 6.1 | 1.4% | May 13, 2021 | The HTMLSanitizer class in html-sanitizer.ts in all released versions of the Aurelia framework 1.x repository is vulnera... |
| CVE-2019-19276 | MEDIUM | 5.3 | 1.0% | May 12, 2021 | A vulnerability has been identified in SIMATIC HMI Comfort Panels 1st Generation (incl. SIPLUS variants) (All versions <... |
| CVE-2019-25043 | MEDIUM | 5.3 | 1.2% | May 6, 2021 | ModSecurity 3.x before 3.0.4 mishandles key-value pair parsing, as demonstrated by a "string index out of range" error a... |
| CVE-2019-25031 | MEDIUM | 5.9 | 1.3% | Apr 27, 2021 | Unbound before 1.9.5 allows configuration injection in create_unbound_ad_servers.sh upon a successful man-in-the-middle ... |
| CVE-2019-25028 | MEDIUM | 6.1 | 0.9% | Apr 23, 2021 | Missing variable sanitization in Grid component in com.vaadin:vaadin-server versions 7.4.0 through 7.7.19 (Vaadin 7.4.0 ... |
| CVE-2019-25027 | MEDIUM | 6.1 | 0.7% | Apr 23, 2021 | Missing output sanitization in default RouteNotFoundError view in com.vaadin:flow-server versions 1.0.0 through 1.0.10 (... |
| CVE-2019-17656 | MEDIUM | 6.5 | 1.6% | Apr 12, 2021 | A Stack-based Buffer Overflow vulnerability in the HTTPD daemon of FortiOS 6.0.10 and below, 6.2.2 and below and FortiPr... |
| CVE-2019-25026 | MEDIUM | 5.3 | 0.8% | Apr 6, 2021 | Redmine before 3.4.13 and 4.x before 4.0.6 mishandles markup data during Textile formatting. |
| CVE-2019-5317 | MEDIUM | 6.8 | 0.3% | Mar 29, 2021 | A local authentication bypass vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(... |
| CVE-2019-14831 | MEDIUM | 6.1 | 0.8% | Mar 19, 2021 | A vulnerability was found in Moodle 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions, where for... |
| CVE-2019-14830 | MEDIUM | 6.1 | 3.3% | Mar 19, 2021 | A vulnerability was found in Moodle 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions, where the... |
| CVE-2019-14829 | MEDIUM | 4.3 | 0.7% | Mar 19, 2021 | A vulnerability was found in Moodle affection 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions ... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now