2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-10401MEDIUM5.4In Jenkins 2.196 and earlier, LTS 2.176.3 and earlier, the f:expandableTextBox form control interpreted its content as H...
CVE-2019-13627MEDIUM6.3It was discovered that there was a ECDSA timing attack in the libgcrypt20 cryptographic library. Version affected: 1.8.4...
CVE-2019-16867MEDIUM6.5HongCMS 3.0.0 allows arbitrary file deletion via a ../ in the file parameter to admin/index.php/database/ajax?action=del...
CVE-2019-13528MEDIUM4.4A specific utility may allow an attacker to gain read access to privileged files in the Niagara AX 3.8u4 (JACE 3e, JACE ...
CVE-2019-16725MEDIUM6.1In Joomla! 3.x before 3.9.12, inadequate escaping allowed XSS attacks using the logo parameter of the default templates.
CVE-2019-14220MEDIUM6.5An issue was discovered in BlueStacks 4.110 and below on macOS and on 4.120 and below on Windows. BlueStacks employs And...
CVE-2019-14239MEDIUM6.6On NXP Kinetis KV1x, Kinetis KV3x, and Kinetis K8x devices, Flash Access Controls (FAC) (a software IP protection method...
CVE-2019-16751MEDIUM6.1An issue was discovered in Devise Token Auth through 1.1.2. The omniauth failure endpoint is vulnerable to Reflected Cro...
CVE-2019-14238MEDIUM6.6On STMicroelectronics STM32F7 devices, Proprietary Code Read Out Protection (PCROP) (a software IP protection method) ca...
CVE-2019-3726MEDIUM6.7An Uncontrolled Search Path Vulnerability is applicable to the following: Dell Update Package (DUP) Framework file versi...
CVE-2019-4566MEDIUM5.5IBM Security Key Lifecycle Manager 3.0 and 3.0.1 stores user credentials in plain in clear text which can be read by a l...
CVE-2019-4515MEDIUM6.5IBM Security Key Lifecycle Manager 3.0 and 3.0.1 is vulnerable to cross-site request forgery which could allow an attack...
CVE-2019-16728MEDIUM6.1DOMPurify before 2.0.1 allows XSS because of innerHTML mutation XSS (mXSS) for an SVG element or a MATH element, as demo...
CVE-2019-10755MEDIUM4.9The SAML identifier generated within SAML2Utils.java was found to make use of the apache commons-lang3 RandomStringUtils...
CVE-2019-15635MEDIUM4.9An issue was discovered in Grafana 5.4.0. Passwords for data sources used by Grafana (e.g., MySQL) are not encrypted. An...
CVE-2019-12407MEDIUM6.1On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerabilit...
CVE-2019-10990MEDIUM6.5Red Lion Controls Crimson, version 3.0 and prior and version 3.1 prior to release 3112.00, uses a hard-coded password to...
CVE-2019-10090MEDIUM6.1On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerabilit...
CVE-2019-16723MEDIUM4.3In Cacti through 1.2.6, authenticated users may bypass authorization checks (for viewing a graph) via a direct graph_jso...
CVE-2019-16518MEDIUM4.3An issue was discovered on Swell Kit Mod devices that use the Vandy Vape platform. An attacker may be able to trigger an...
CVE-2019-12404MEDIUM6.1On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerabilit...
CVE-2019-10089MEDIUM6.1On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerabilit...
CVE-2019-10087MEDIUM6.1On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerabilit...
CVE-2019-16721MEDIUM6.5NoneCMS v1.3 has CSRF in public/index.php/admin/admin/dele.html, as demonstrated by deleting the admin user.
CVE-2019-16719MEDIUM6.5WTCMS 1.0 allows index.php?g=admin&m=index&a=index CSRF with resultant XSS.

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now