2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-4596MEDIUM5.4IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 is vulnerable to cross-site scripting. This vulnera...
CVE-2019-4537MEDIUM5.3IBM WebSphere Service Registry and Repository 8.5 could allow a user to obtain sensitive version information that could ...
CVE-2019-19994CRITICAL9.8An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. It allows blind Command Injection. A...
CVE-2019-19993MEDIUM5.3An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. Several full path disclosure vulnera...
CVE-2019-19992MEDIUM6.5An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. A user with valid credentials is abl...
CVE-2019-19991MEDIUM5.4An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. Multiple Reflected Cross-site script...
CVE-2019-19990MEDIUM5.4An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. Multiple Stored Cross-site scripting...
CVE-2019-19989HIGH7.5An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. Several PHP pages, and other type of...
CVE-2019-19988HIGH8.8An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. A user with valid credentials is abl...
CVE-2019-19987MEDIUM6.5An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. It allows Cross-Site Request Forgery...
CVE-2019-19986HIGH7.5An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. An attacker without authentication i...
CVE-2019-3796Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2019-19134MEDIUM6.1The Hero Maps Premium plugin 2.2.1 and prior for WordPress is prone to unauthenticated XSS via the views/dashboard/index...
CVE-2019-4000HIGH7.8Improper neutralization of directives in dynamically evaluated code in Druva inSync Mac OS Client 6.5.0 allows a local, ...
CVE-2019-3999HIGH7.8Improper neutralization of special elements used in an OS command in Druva inSync Windows Client 6.5.0 allows a local, u...
CVE-2019-12863MEDIUM4.8SolarWinds Orion Platform 2018.4 HF3 (NPM 12.4, NetPath 1.1.4) allows Stored HTML Injection by administrators via the We...
CVE-2019-5165HIGH7.2An exploitable authentication bypass vulnerability exists in the hostname processing of the Moxa AWK-3131A firmware vers...
CVE-2019-5162HIGH8.8An exploitable improper access control vulnerability exists in the iw_webs account settings functionality of the Moxa AW...
CVE-2019-5153HIGH8.8An exploitable remote code execution vulnerability exists in the iw_webs configuration parsing functionality of the Moxa...
CVE-2019-5148HIGH7.5An exploitable denial-of-service vulnerability exists in ServiceAgent functionality of the Moxa AWK-3131A, firmware vers...
CVE-2019-5143HIGH8.8An exploitable format string vulnerability exists in the iw_console conio_writestr functionality of the Moxa AWK-3131A f...
CVE-2019-5142HIGH7.2An exploitable command injection vulnerability exists in the hostname functionality of the Moxa AWK-3131A firmware versi...
CVE-2019-5141HIGH8.8An exploitable command injection vulnerability exists in the iw_webs functionality of the Moxa AWK-3131A firmware versio...
CVE-2019-5140HIGH8.8An exploitable command injection vulnerability exists in the iwwebs functionality of the Moxa AWK-3131A firmware version...
CVE-2019-5139HIGH7.1An exploitable use of hard-coded credentials vulnerability exists in multiple iw_* utilities of the Moxa AWK-3131A firmw...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now