2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-12430 | HIGH | 8.8 | 2.6% | Mar 10, 2020 | An issue was discovered in GitLab Community and Enterprise Edition 11.11. A specially crafted payload would allow an aut... |
| CVE-2019-12429 | MEDIUM | 6.5 | 0.9% | Mar 10, 2020 | An issue was discovered in GitLab Community and Enterprise Edition 11.9 through 11.11. Unprivileged users were able to a... |
| CVE-2019-12428 | CRITICAL | 9.8 | 1.4% | Mar 10, 2020 | An issue was discovered in GitLab Community and Enterprise Edition 6.8 through 11.11. Users could bypass the mandatory e... |
| CVE-2019-11345 | MEDIUM | 6.1 | 0.8% | Mar 10, 2020 | Citrix SD-WAN Center 10.2.x before 10.2.1 and NetScaler SD-WAN Center 10.0.x before 10.0.7 allow XSS. |
| CVE-2019-9859 | HIGH | 8.8 | 3.0% | Mar 10, 2020 | Vesta Control Panel (VestaCP) 0.9.7 through 0.9.8-23 is vulnerable to an authenticated command execution that can result... |
| CVE-2019-11686 | MEDIUM | 5.5 | 0.2% | Mar 10, 2020 | Western Digital SanDisk X300, X300s, X400, and X600 devices: A vulnerability in the wear-leveling algorithm of the drive... |
| CVE-2019-10706 | MEDIUM | 6.3 | 0.3% | Mar 10, 2020 | Western Digital SanDisk SanDisk X300, X300s, X400, and X600 devices: The firmware update authentication method relies on... |
| CVE-2019-10065 | MEDIUM | 4.3 | 0.8% | Mar 10, 2020 | An issue was discovered in Open Ticket Request System (OTRS) 7.0 through 7.0.6. An attacker who is logged into OTRS as a... |
| CVE-2019-4608 | MEDIUM | 5.4 | 0.7% | Mar 10, 2020 | IBM Tivoli Workload Scheduler 9.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitr... |
| CVE-2019-19614 | HIGH | 7.5 | 1.2% | Mar 9, 2020 | An issue was discovered in Halvotec RAQuest 10.23.10801.0. The login page is vulnerable to wildcard injection, allowing ... |
| CVE-2019-20226 | — | — | — | Mar 9, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2019-10806 | MEDIUM | 4.3 | 1.1% | Mar 9, 2020 | vega-util prior to 1.13.1 allows manipulation of object prototype. The 'vega.mergeConfig' method within vega-util could ... |
| CVE-2019-20504 | CRITICAL | 9.8 | 8.3% | Mar 9, 2020 | service/krashrpt.php in Quest KACE K1000 Systems Management Appliance before 6.4 SP3 (6.4.120822) allows a remote attack... |
| CVE-2019-14508 | — | — | — | Mar 7, 2020 | Rejected reason: Unused CVE for 2019 |
| CVE-2019-14507 | — | — | — | Mar 7, 2020 | Rejected reason: Unused CVE for 2019 |
| CVE-2019-14506 | — | — | — | Mar 7, 2020 | Rejected reason: Unused CVE for 2019 |
| CVE-2019-14505 | — | — | — | Mar 7, 2020 | Rejected reason: Unused CVE for 2019 |
| CVE-2019-14504 | — | — | — | Mar 7, 2020 | Rejected reason: Unused CVE for 2019 |
| CVE-2019-14503 | — | — | — | Mar 7, 2020 | Rejected reason: Unused CVE for 2019 |
| CVE-2019-14502 | — | — | — | Mar 7, 2020 | Rejected reason: Unused CVE for 2019 |
| CVE-2019-14501 | — | — | — | Mar 7, 2020 | Rejected reason: Unused CVE for 2019 |
| CVE-2019-14500 | — | — | — | Mar 7, 2020 | Rejected reason: Unused CVE for 2019 |
| CVE-2019-14499 | — | — | — | Mar 7, 2020 | Rejected reason: Unused CVE for 2019 |
| CVE-2019-19773 | MEDIUM | 5.4 | 0.7% | Mar 6, 2020 | Various Lexmark products have stored XSS in the embedded web server used in older generation Lexmark devices. Affected p... |
| CVE-2019-19772 | MEDIUM | 5.4 | 0.7% | Mar 6, 2020 | Various Lexmark products have reflected XSS in the embedded web server used in older generation Lexmark devices. Affecte... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now