2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-14828 | MEDIUM | 4.3 | 0.6% | Mar 19, 2021 | A vulnerability was found in Moodle affecting 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions,... |
| CVE-2019-10225 | MEDIUM | 6.3 | 0.6% | Mar 19, 2021 | A flaw was found in atomic-openshift of openshift-4.2 where the basic-user RABC role in OpenShift Container Platform doe... |
| CVE-2019-14851 | MEDIUM | 6.5 | 1.0% | Mar 18, 2021 | A denial of service vulnerability was discovered in nbdkit. A client issuing a certain sequence of commands could possib... |
| CVE-2019-3867 | MEDIUM | 4.1 | 0.3% | Mar 18, 2021 | A vulnerability was found in the Quay web application. Sessions in the Quay web application never expire. An attacker, a... |
| CVE-2019-18233 | MEDIUM | 6.1 | 0.7% | Mar 17, 2021 | In Advantech Spectre RT Industrial Routers ERT351 5.1.3 and prior, the affected product does not neutralize special char... |
| CVE-2019-3897 | MEDIUM | 5.3 | 0.9% | Mar 16, 2021 | It has been discovered in redhat-certification that any unauthorized user may download any file under /var/www/rhcert, p... |
| CVE-2019-25025 | MEDIUM | 5.3 | 1.8% | Mar 5, 2021 | The activerecord-session_store (aka Active Record Session Store) component through 1.1.3 for Ruby on Rails does not use ... |
| CVE-2019-18628 | MEDIUM | 4.9 | 0.6% | Mar 4, 2021 | Xerox AltaLink B8045/B8055/B8065/B8075/B8090 and C8030/C8035/C8045/C8055/C8070 multifunction printers with software rele... |
| CVE-2019-25023 | MEDIUM | 6.5 | 0.9% | Feb 27, 2021 | An issue was discovered in Scytl sVote 2.1. Because the IP address from an X-Forwarded-For header (which can be manipula... |
| CVE-2019-18946 | MEDIUM | 4.8 | 0.3% | Feb 26, 2021 | Micro Focus Solutions Business Manager Application Repository versions prior to 11.7.1 are vulnerable to session fixatio... |
| CVE-2019-18944 | MEDIUM | 4.8 | 0.3% | Feb 26, 2021 | Micro Focus Solutions Business Manager Application Repository versions prior to 11.7.1 are vulnerable to reflected XSS. |
| CVE-2019-18942 | MEDIUM | 4.8 | 0.3% | Feb 26, 2021 | Micro Focus Solutions Business Manager versions prior to 11.7.1 are vulnerable to stored XSS. The application reflects p... |
| CVE-2019-18243 | MEDIUM | 5.5 | 0.2% | Feb 18, 2021 | HMI/SCADA iFIX (Versions 6.1 and prior) allows a local authenticated user to modify system-wide iFIX configurations thro... |
| CVE-2019-18255 | MEDIUM | 5.5 | 0.2% | Feb 18, 2021 | HMI/SCADA iFIX (Versions 6.1 and prior) allows a local authenticated user to modify system-wide iFIX configurations thro... |
| CVE-2019-16268 | MEDIUM | 4.8 | 1.8% | Feb 3, 2021 | Zoho ManageEngine Remote Access Plus 10.0.259 allows HTML injection via the Description field on the Admin - User Admini... |
| CVE-2019-25017 | MEDIUM | 5.9 | 1.4% | Feb 2, 2021 | An issue was discovered in rcp in MIT krb5-appl through 1.0.3. Due to the rcp implementation being derived from 1983 rcp... |
| CVE-2019-20473 | MEDIUM | 6.8 | 0.4% | Feb 1, 2021 | An issue was discovered on TK-Star Q90 Junior GPS horloge 3.1042.9.8656 devices. Any SIM card used with the device canno... |
| CVE-2019-25014 | MEDIUM | 6.5 | 1.4% | Jan 29, 2021 | A NULL pointer dereference was found in pkg/proxy/envoy/v2/debug.go getResourceVersion in Istio pilot before 1.5.0-alpha... |
| CVE-2019-25015 | MEDIUM | 5.4 | 0.6% | Jan 26, 2021 | LuCI in OpenWrt 18.06.0 through 18.06.4 allows stored XSS via a crafted SSID. |
| CVE-2019-16961 | MEDIUM | 5.4 | 1.5% | Jan 15, 2021 | SolarWinds Web Help Desk 12.7.0 allows XSS via a Schedule Name. |
| CVE-2019-4687 | MEDIUM | 5.3 | 0.4% | Jan 13, 2021 | IBM Security Guardium Data Encryption (GDE) 3.0.0.2 stores sensitive information in URL parameters. This may lead to inf... |
| CVE-2019-3405 | MEDIUM | 5.3 | 1.0% | Jan 11, 2021 | In the 3.1.3.64296 and lower version of 360F5, the third party can trigger the device to send a deauth frame by construc... |
| CVE-2019-16962 | MEDIUM | 5.4 | 2.3% | Jan 6, 2021 | Zoho ManageEngine Desktop Central 10.0.430 allows HTML injection via a modified Report Name in a New Custom Report. |
| CVE-2019-16954 | MEDIUM | 5.4 | 1.3% | Jan 6, 2021 | SolarWinds Web Help Desk 12.7.0 allows HTML injection via a Comment in a Help Request ticket. |
| CVE-2019-20483 | MEDIUM | 5.4 | 0.5% | Jan 5, 2021 | An issue was discovered in Viki Vera 4.9.1.26180. An attacker could set a user's last name to an XSS Payload, and read a... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now