2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-11749 | MEDIUM | 4.3 | 0.9% | Sep 27, 2019 | A vulnerability exists in WebRTC where malicious web content can use probing techniques on the getUserMedia API using co... |
| CVE-2019-11748 | MEDIUM | 6.5 | 1.0% | Sep 27, 2019 | WebRTC in Firefox will honor persisted permissions given to sites for access to microphone and camera resources even whe... |
| CVE-2019-11747 | MEDIUM | 6.5 | 1.2% | Sep 27, 2019 | The "Forget about this site" feature in the History pane is intended to remove all saved user data that indicates a user... |
| CVE-2019-11744 | MEDIUM | 6.1 | 1.5% | Sep 27, 2019 | Some HTML elements, such as <title> and <textarea>, can contain literal angle brackets without treating them... |
| CVE-2019-11742 | MEDIUM | 6.5 | 1.7% | Sep 27, 2019 | A same-origin policy violation occurs allowing the theft of cross-origin images through a combination of SVG filters and... |
| CVE-2019-11741 | MEDIUM | 6.1 | 0.6% | Sep 27, 2019 | A compromised sandboxed content process can perform a Universal Cross-site Scripting (UXSS) attack on content from any s... |
| CVE-2019-11739 | MEDIUM | 6.5 | 0.9% | Sep 27, 2019 | Encrypted S/MIME parts in a crafted multipart/alternative message can leak plaintext when included in a a HTML reply/for... |
| CVE-2019-11738 | MEDIUM | 6.3 | 1.4% | Sep 27, 2019 | If a Content Security Policy (CSP) directive is defined that uses a hash-based source that takes the empty string as inp... |
| CVE-2019-11737 | MEDIUM | 5.3 | 0.5% | Sep 27, 2019 | If a wildcard ('*') is specified for the host in Content Security Policy (CSP) directives, any port or path restriction ... |
| CVE-2019-16923 | MEDIUM | 6.1 | 0.8% | Sep 27, 2019 | kkcms 1.3 has jx.php?url= XSS. |
| CVE-2019-16922 | MEDIUM | 5.3 | 1.1% | Sep 27, 2019 | SuiteCRM 7.10.x before 7.10.20 and 7.11.x before 7.11.8 allows unintended public exposure of files. |
| CVE-2019-4141 | MEDIUM | 6.5 | 1.3% | Sep 27, 2019 | IBM MQ 7.1.0.0 - 7.1.0.9, 7.5.0.0 - 7.5.0.9, 8.0.0.0 - 8.0.0.11, 9.0.0.0 - 9.0.0.6, 9.1.0.0 - 9.1.0.2, and 9.1.1 - 9.1.2... |
| CVE-2019-13376 | MEDIUM | 6.5 | 0.7% | Sep 27, 2019 | phpBB version 3.2.7 allows the stealing of an Administration Control Panel session id by leveraging CSRF in the Remote A... |
| CVE-2019-15891 | MEDIUM | 5.3 | 1.1% | Sep 26, 2019 | An issue was discovered in CKFinder through 2.6.2.1 and 3.x through 3.5.0. The documentation has misleading information ... |
| CVE-2019-12562 | MEDIUM | 6.1 | 6.2% | Sep 26, 2019 | Stored Cross-Site Scripting in DotNetNuke (DNN) Version before 9.4.0 allows remote attackers to store and embed the mali... |
| CVE-2019-16914 | MEDIUM | 6.1 | 2.0% | Sep 26, 2019 | An XSS issue was discovered in pfSense through 2.4.4-p3. In services_captiveportal_mac.php, the username and delmac para... |
| CVE-2019-16532 | MEDIUM | 6.1 | 1.2% | Sep 26, 2019 | An HTTP Host header injection vulnerability exists in YzmCMS V5.3. A malicious user can poison a web cache or trigger re... |
| CVE-2019-16524 | MEDIUM | 4.8 | 1.0% | Sep 26, 2019 | The easy-fancybox plugin before 1.8.18 for WordPress (aka Easy FancyBox) is susceptible to Stored XSS in the Settings Me... |
| CVE-2019-16409 | MEDIUM | 5.3 | 1.2% | Sep 26, 2019 | In the Versioned Files module through 2.0.3 for SilverStripe 3.x, unpublished versions of files are publicly exposed to ... |
| CVE-2019-13523 | MEDIUM | 5.3 | 1.8% | Sep 26, 2019 | In Honeywell Performance IP Cameras and Performance NVRs, the integrated web server of the affected devices could allow ... |
| CVE-2019-10092 | MEDIUM | 6.1 | 81.5% | Sep 26, 2019 | In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page... |
| CVE-2019-4378 | MEDIUM | 6.5 | 1.6% | Sep 26, 2019 | IBM MQ 7.5.0.0 - 7.5.0.9, 7.1.0.0 - 7.1.0.9, 8.0.0.0 - 8.0.0.12, 9.0.0.0 - 9.0.0.6, 9.1.0.0 - 9.1.0.2, and 9.1.0 - 9.1.2... |
| CVE-2019-4262 | MEDIUM | 5.3 | 1.0% | Sep 26, 2019 | IBM QRadar SIEM 7.2 and 7.3 is vulnerable to Server Side Request Forgery (SSRF). This may allow an unauthenticated attac... |
| CVE-2019-16910 | MEDIUM | 5.3 | 1.8% | Sep 26, 2019 | Arm Mbed TLS before 2.19.0 and Arm Mbed Crypto before 2.0.0, when deterministic ECDSA is enabled, use an RNG with insuff... |
| CVE-2019-16904 | MEDIUM | 5.4 | 0.7% | Sep 26, 2019 | TeamPass 2.1.27.36 allows Stored XSS by setting a crafted password for an item in a common available folder or sharing t... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now