2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-10401 | MEDIUM | 5.4 | 1.0% | Sep 25, 2019 | In Jenkins 2.196 and earlier, LTS 2.176.3 and earlier, the f:expandableTextBox form control interpreted its content as H... |
| CVE-2019-13627 | MEDIUM | 6.3 | 0.5% | Sep 25, 2019 | It was discovered that there was a ECDSA timing attack in the libgcrypt20 cryptographic library. Version affected: 1.8.4... |
| CVE-2019-16867 | MEDIUM | 6.5 | 1.1% | Sep 25, 2019 | HongCMS 3.0.0 allows arbitrary file deletion via a ../ in the file parameter to admin/index.php/database/ajax?action=del... |
| CVE-2019-13528 | MEDIUM | 4.4 | 0.4% | Sep 24, 2019 | A specific utility may allow an attacker to gain read access to privileged files in the Niagara AX 3.8u4 (JACE 3e, JACE ... |
| CVE-2019-16725 | MEDIUM | 6.1 | 0.7% | Sep 24, 2019 | In Joomla! 3.x before 3.9.12, inadequate escaping allowed XSS attacks using the logo parameter of the default templates. |
| CVE-2019-14220 | MEDIUM | 6.5 | 0.9% | Sep 24, 2019 | An issue was discovered in BlueStacks 4.110 and below on macOS and on 4.120 and below on Windows. BlueStacks employs And... |
| CVE-2019-14239 | MEDIUM | 6.6 | 0.4% | Sep 24, 2019 | On NXP Kinetis KV1x, Kinetis KV3x, and Kinetis K8x devices, Flash Access Controls (FAC) (a software IP protection method... |
| CVE-2019-16751 | MEDIUM | 6.1 | 0.9% | Sep 24, 2019 | An issue was discovered in Devise Token Auth through 1.1.2. The omniauth failure endpoint is vulnerable to Reflected Cro... |
| CVE-2019-14238 | MEDIUM | 6.6 | 0.4% | Sep 24, 2019 | On STMicroelectronics STM32F7 devices, Proprietary Code Read Out Protection (PCROP) (a software IP protection method) ca... |
| CVE-2019-3726 | MEDIUM | 6.7 | 0.5% | Sep 24, 2019 | An Uncontrolled Search Path Vulnerability is applicable to the following: Dell Update Package (DUP) Framework file versi... |
| CVE-2019-4566 | MEDIUM | 5.5 | 0.2% | Sep 24, 2019 | IBM Security Key Lifecycle Manager 3.0 and 3.0.1 stores user credentials in plain in clear text which can be read by a l... |
| CVE-2019-4515 | MEDIUM | 6.5 | 0.5% | Sep 24, 2019 | IBM Security Key Lifecycle Manager 3.0 and 3.0.1 is vulnerable to cross-site request forgery which could allow an attack... |
| CVE-2019-16728 | MEDIUM | 6.1 | 1.7% | Sep 24, 2019 | DOMPurify before 2.0.1 allows XSS because of innerHTML mutation XSS (mXSS) for an SVG element or a MATH element, as demo... |
| CVE-2019-10755 | MEDIUM | 4.9 | 1.1% | Sep 23, 2019 | The SAML identifier generated within SAML2Utils.java was found to make use of the apache commons-lang3 RandomStringUtils... |
| CVE-2019-15635 | MEDIUM | 4.9 | 1.6% | Sep 23, 2019 | An issue was discovered in Grafana 5.4.0. Passwords for data sources used by Grafana (e.g., MySQL) are not encrypted. An... |
| CVE-2019-12407 | MEDIUM | 6.1 | 2.9% | Sep 23, 2019 | On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerabilit... |
| CVE-2019-10990 | MEDIUM | 6.5 | 1.3% | Sep 23, 2019 | Red Lion Controls Crimson, version 3.0 and prior and version 3.1 prior to release 3112.00, uses a hard-coded password to... |
| CVE-2019-10090 | MEDIUM | 6.1 | 2.9% | Sep 23, 2019 | On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerabilit... |
| CVE-2019-16723 | MEDIUM | 4.3 | 1.5% | Sep 23, 2019 | In Cacti through 1.2.6, authenticated users may bypass authorization checks (for viewing a graph) via a direct graph_jso... |
| CVE-2019-16518 | MEDIUM | 4.3 | 0.6% | Sep 23, 2019 | An issue was discovered on Swell Kit Mod devices that use the Vandy Vape platform. An attacker may be able to trigger an... |
| CVE-2019-12404 | MEDIUM | 6.1 | 2.9% | Sep 23, 2019 | On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerabilit... |
| CVE-2019-10089 | MEDIUM | 6.1 | 2.9% | Sep 23, 2019 | On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerabilit... |
| CVE-2019-10087 | MEDIUM | 6.1 | 2.9% | Sep 23, 2019 | On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerabilit... |
| CVE-2019-16721 | MEDIUM | 6.5 | 0.5% | Sep 23, 2019 | NoneCMS v1.3 has CSRF in public/index.php/admin/admin/dele.html, as demonstrated by deleting the admin user. |
| CVE-2019-16719 | MEDIUM | 6.5 | 0.5% | Sep 23, 2019 | WTCMS 1.0 allows index.php?g=admin&m=index&a=index CSRF with resultant XSS. |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now