2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-11749MEDIUM4.3A vulnerability exists in WebRTC where malicious web content can use probing techniques on the getUserMedia API using co...
CVE-2019-11748MEDIUM6.5WebRTC in Firefox will honor persisted permissions given to sites for access to microphone and camera resources even whe...
CVE-2019-11747MEDIUM6.5The "Forget about this site" feature in the History pane is intended to remove all saved user data that indicates a user...
CVE-2019-11744MEDIUM6.1Some HTML elements, such as <title> and <textarea>, can contain literal angle brackets without treating them...
CVE-2019-11742MEDIUM6.5A same-origin policy violation occurs allowing the theft of cross-origin images through a combination of SVG filters and...
CVE-2019-11741MEDIUM6.1A compromised sandboxed content process can perform a Universal Cross-site Scripting (UXSS) attack on content from any s...
CVE-2019-11739MEDIUM6.5Encrypted S/MIME parts in a crafted multipart/alternative message can leak plaintext when included in a a HTML reply/for...
CVE-2019-11738MEDIUM6.3If a Content Security Policy (CSP) directive is defined that uses a hash-based source that takes the empty string as inp...
CVE-2019-11737MEDIUM5.3If a wildcard ('*') is specified for the host in Content Security Policy (CSP) directives, any port or path restriction ...
CVE-2019-16923MEDIUM6.1kkcms 1.3 has jx.php?url= XSS.
CVE-2019-16922MEDIUM5.3SuiteCRM 7.10.x before 7.10.20 and 7.11.x before 7.11.8 allows unintended public exposure of files.
CVE-2019-4141MEDIUM6.5IBM MQ 7.1.0.0 - 7.1.0.9, 7.5.0.0 - 7.5.0.9, 8.0.0.0 - 8.0.0.11, 9.0.0.0 - 9.0.0.6, 9.1.0.0 - 9.1.0.2, and 9.1.1 - 9.1.2...
CVE-2019-13376MEDIUM6.5phpBB version 3.2.7 allows the stealing of an Administration Control Panel session id by leveraging CSRF in the Remote A...
CVE-2019-15891MEDIUM5.3An issue was discovered in CKFinder through 2.6.2.1 and 3.x through 3.5.0. The documentation has misleading information ...
CVE-2019-12562MEDIUM6.1Stored Cross-Site Scripting in DotNetNuke (DNN) Version before 9.4.0 allows remote attackers to store and embed the mali...
CVE-2019-16914MEDIUM6.1An XSS issue was discovered in pfSense through 2.4.4-p3. In services_captiveportal_mac.php, the username and delmac para...
CVE-2019-16532MEDIUM6.1An HTTP Host header injection vulnerability exists in YzmCMS V5.3. A malicious user can poison a web cache or trigger re...
CVE-2019-16524MEDIUM4.8The easy-fancybox plugin before 1.8.18 for WordPress (aka Easy FancyBox) is susceptible to Stored XSS in the Settings Me...
CVE-2019-16409MEDIUM5.3In the Versioned Files module through 2.0.3 for SilverStripe 3.x, unpublished versions of files are publicly exposed to ...
CVE-2019-13523MEDIUM5.3In Honeywell Performance IP Cameras and Performance NVRs, the integrated web server of the affected devices could allow ...
CVE-2019-10092MEDIUM6.1In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page...
CVE-2019-4378MEDIUM6.5IBM MQ 7.5.0.0 - 7.5.0.9, 7.1.0.0 - 7.1.0.9, 8.0.0.0 - 8.0.0.12, 9.0.0.0 - 9.0.0.6, 9.1.0.0 - 9.1.0.2, and 9.1.0 - 9.1.2...
CVE-2019-4262MEDIUM5.3IBM QRadar SIEM 7.2 and 7.3 is vulnerable to Server Side Request Forgery (SSRF). This may allow an unauthenticated attac...
CVE-2019-16910MEDIUM5.3Arm Mbed TLS before 2.19.0 and Arm Mbed Crypto before 2.0.0, when deterministic ECDSA is enabled, use an RNG with insuff...
CVE-2019-16904MEDIUM5.4TeamPass 2.1.27.36 allows Stored XSS by setting a crafted password for an item in a common available folder or sharing t...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now