2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-15086MEDIUM6.1An issue was discovered in PRiSE adAS 1.7.0. The newentityID parameter is not properly escaped, leading to a reflected X...
CVE-2019-14916MEDIUM6.5An issue was discovered in PRiSE adAS 1.7.0. A file's format is not properly checked, leading to an unrestricted file up...
CVE-2019-14915MEDIUM6.1An issue was discovered in PRiSE adAS 1.7.0. Certificate data are not properly escaped. This leads to XSS when submittin...
CVE-2019-14913MEDIUM5.4An issue was discovered in PRiSE adAS 1.7.0. Log data are not properly escaped, leading to persistent XSS in the adminis...
CVE-2019-14912MEDIUM6.1An issue was discovered in PRiSE adAS 1.7.0. The OPENSSO module does not properly check the goto parameter, leading to a...
CVE-2019-14911MEDIUM6.1An issue was discovered in PRiSE adAS 1.7.0. The OPENSSO module does not properly escape output on error, leading to ref...
CVE-2019-9720MEDIUM6.5A stack-based buffer overflow in the subtitle decoder in Libav 12.3 allows attackers to corrupt the stack via a crafted ...
CVE-2019-9717MEDIUM6.5In Libav 12.3, a denial of service in the subtitle decoder allows attackers to hog the CPU via a crafted video file in M...
CVE-2019-16525MEDIUM6.1An XSS issue was discovered in the checklist plugin before 1.1.9 for WordPress. The fill parameter is not correctly filt...
CVE-2019-15032MEDIUM5.3Pydio 6.0.8 mishandles error reporting when a directory allows unauthenticated uploads, and the remote-upload option is ...
CVE-2019-16511MEDIUM5.5An issue was discovered in DTF in FireGiant WiX Toolset before 3.11.2. Microsoft.Deployment.Compression.Cab.dll and Micr...
CVE-2019-16398MEDIUM6.8On Keeper K5 20.1.0.25 and 20.1.0.63 devices, remote code execution can occur by inserting an SD card containing a file ...
CVE-2019-11779MEDIUM6.5In Eclipse Mosquitto 1.5.0 to 1.6.5 inclusive, if a malicious MQTT client sends a SUBSCRIBE packet containing a topic th...
CVE-2019-3756MEDIUM6.5RSA Archer, versions prior to 6.6 P3 (6.6.0.3), contain an information disclosure vulnerability. Information relating to...
CVE-2019-3740MEDIUM6.5RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to an Information Exposure Through Timing Discrepancy vulnerab...
CVE-2019-3739MEDIUM6.5RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to Information Exposure Through Timing Discrepancy vulnerabili...
CVE-2019-3738MEDIUM6.5RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to a Missing Required Cryptographic Step vulnerability. A mali...
CVE-2019-11778MEDIUM5.4If an MQTT v5 client connects to Eclipse Mosquitto versions 1.6.0 to 1.6.4 inclusive, sets a last will and testament, se...
CVE-2019-5531MEDIUM5.4VMware vSphere ESXi (6.7 prior to ESXi670-201810101-SG, 6.5 prior to ESXi650-201811102-SG, and 6.0 prior to ESXi600-2018...
CVE-2019-11664MEDIUM6.5Clear text password in browser in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40,...
CVE-2019-11663MEDIUM6.5Clear text credentials are used to access managers app in Tomcat in Micro Focus Service Manager product versions 9.30, 9...
CVE-2019-11662MEDIUM4.3Class and method names in error message in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9....
CVE-2019-9680MEDIUM5.3Some Dahua products have information leakage issues. Attackers can obtain the IP address and device model information of...
CVE-2019-1975MEDIUM6.1A vulnerability in the web-based interface of Cisco HyperFlex Software could allow an unauthenticated, remote attacker t...
CVE-2019-12620MEDIUM5.3A vulnerability in the statistics collection service of Cisco HyperFlex Software could allow an unauthenticated, remote ...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now