2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-14828MEDIUM4.3A vulnerability was found in Moodle affecting 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions,...
CVE-2019-10225MEDIUM6.3A flaw was found in atomic-openshift of openshift-4.2 where the basic-user RABC role in OpenShift Container Platform doe...
CVE-2019-14851MEDIUM6.5A denial of service vulnerability was discovered in nbdkit. A client issuing a certain sequence of commands could possib...
CVE-2019-3867MEDIUM4.1A vulnerability was found in the Quay web application. Sessions in the Quay web application never expire. An attacker, a...
CVE-2019-18233MEDIUM6.1In Advantech Spectre RT Industrial Routers ERT351 5.1.3 and prior, the affected product does not neutralize special char...
CVE-2019-3897MEDIUM5.3It has been discovered in redhat-certification that any unauthorized user may download any file under /var/www/rhcert, p...
CVE-2019-25025MEDIUM5.3The activerecord-session_store (aka Active Record Session Store) component through 1.1.3 for Ruby on Rails does not use ...
CVE-2019-18628MEDIUM4.9Xerox AltaLink B8045/B8055/B8065/B8075/B8090 and C8030/C8035/C8045/C8055/C8070 multifunction printers with software rele...
CVE-2019-25023MEDIUM6.5An issue was discovered in Scytl sVote 2.1. Because the IP address from an X-Forwarded-For header (which can be manipula...
CVE-2019-18946MEDIUM4.8Micro Focus Solutions Business Manager Application Repository versions prior to 11.7.1 are vulnerable to session fixatio...
CVE-2019-18944MEDIUM4.8Micro Focus Solutions Business Manager Application Repository versions prior to 11.7.1 are vulnerable to reflected XSS.
CVE-2019-18942MEDIUM4.8Micro Focus Solutions Business Manager versions prior to 11.7.1 are vulnerable to stored XSS. The application reflects p...
CVE-2019-18243MEDIUM5.5HMI/SCADA iFIX (Versions 6.1 and prior) allows a local authenticated user to modify system-wide iFIX configurations thro...
CVE-2019-18255MEDIUM5.5HMI/SCADA iFIX (Versions 6.1 and prior) allows a local authenticated user to modify system-wide iFIX configurations thro...
CVE-2019-16268MEDIUM4.8Zoho ManageEngine Remote Access Plus 10.0.259 allows HTML injection via the Description field on the Admin - User Admini...
CVE-2019-25017MEDIUM5.9An issue was discovered in rcp in MIT krb5-appl through 1.0.3. Due to the rcp implementation being derived from 1983 rcp...
CVE-2019-20473MEDIUM6.8An issue was discovered on TK-Star Q90 Junior GPS horloge 3.1042.9.8656 devices. Any SIM card used with the device canno...
CVE-2019-25014MEDIUM6.5A NULL pointer dereference was found in pkg/proxy/envoy/v2/debug.go getResourceVersion in Istio pilot before 1.5.0-alpha...
CVE-2019-25015MEDIUM5.4LuCI in OpenWrt 18.06.0 through 18.06.4 allows stored XSS via a crafted SSID.
CVE-2019-16961MEDIUM5.4SolarWinds Web Help Desk 12.7.0 allows XSS via a Schedule Name.
CVE-2019-4687MEDIUM5.3IBM Security Guardium Data Encryption (GDE) 3.0.0.2 stores sensitive information in URL parameters. This may lead to inf...
CVE-2019-3405MEDIUM5.3In the 3.1.3.64296 and lower version of 360F5, the third party can trigger the device to send a deauth frame by construc...
CVE-2019-16962MEDIUM5.4Zoho ManageEngine Desktop Central 10.0.430 allows HTML injection via a modified Report Name in a New Custom Report.
CVE-2019-16954MEDIUM5.4SolarWinds Web Help Desk 12.7.0 allows HTML injection via a Comment in a Help Request ticket.
CVE-2019-20483MEDIUM5.4An issue was discovered in Viki Vera 4.9.1.26180. An attacker could set a user's last name to an XSS Payload, and read a...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now