2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-15086 | MEDIUM | 6.1 | 0.8% | Sep 20, 2019 | An issue was discovered in PRiSE adAS 1.7.0. The newentityID parameter is not properly escaped, leading to a reflected X... |
| CVE-2019-14916 | MEDIUM | 6.5 | 1.0% | Sep 20, 2019 | An issue was discovered in PRiSE adAS 1.7.0. A file's format is not properly checked, leading to an unrestricted file up... |
| CVE-2019-14915 | MEDIUM | 6.1 | 0.5% | Sep 20, 2019 | An issue was discovered in PRiSE adAS 1.7.0. Certificate data are not properly escaped. This leads to XSS when submittin... |
| CVE-2019-14913 | MEDIUM | 5.4 | 0.9% | Sep 20, 2019 | An issue was discovered in PRiSE adAS 1.7.0. Log data are not properly escaped, leading to persistent XSS in the adminis... |
| CVE-2019-14912 | MEDIUM | 6.1 | 1.2% | Sep 20, 2019 | An issue was discovered in PRiSE adAS 1.7.0. The OPENSSO module does not properly check the goto parameter, leading to a... |
| CVE-2019-14911 | MEDIUM | 6.1 | 1.0% | Sep 20, 2019 | An issue was discovered in PRiSE adAS 1.7.0. The OPENSSO module does not properly escape output on error, leading to ref... |
| CVE-2019-9720 | MEDIUM | 6.5 | 1.1% | Sep 19, 2019 | A stack-based buffer overflow in the subtitle decoder in Libav 12.3 allows attackers to corrupt the stack via a crafted ... |
| CVE-2019-9717 | MEDIUM | 6.5 | 1.3% | Sep 19, 2019 | In Libav 12.3, a denial of service in the subtitle decoder allows attackers to hog the CPU via a crafted video file in M... |
| CVE-2019-16525 | MEDIUM | 6.1 | 5.5% | Sep 19, 2019 | An XSS issue was discovered in the checklist plugin before 1.1.9 for WordPress. The fill parameter is not correctly filt... |
| CVE-2019-15032 | MEDIUM | 5.3 | 1.6% | Sep 19, 2019 | Pydio 6.0.8 mishandles error reporting when a directory allows unauthenticated uploads, and the remote-upload option is ... |
| CVE-2019-16511 | MEDIUM | 5.5 | 1.5% | Sep 19, 2019 | An issue was discovered in DTF in FireGiant WiX Toolset before 3.11.2. Microsoft.Deployment.Compression.Cab.dll and Micr... |
| CVE-2019-16398 | MEDIUM | 6.8 | 0.8% | Sep 19, 2019 | On Keeper K5 20.1.0.25 and 20.1.0.63 devices, remote code execution can occur by inserting an SD card containing a file ... |
| CVE-2019-11779 | MEDIUM | 6.5 | 2.7% | Sep 19, 2019 | In Eclipse Mosquitto 1.5.0 to 1.6.5 inclusive, if a malicious MQTT client sends a SUBSCRIBE packet containing a topic th... |
| CVE-2019-3756 | MEDIUM | 6.5 | 1.1% | Sep 18, 2019 | RSA Archer, versions prior to 6.6 P3 (6.6.0.3), contain an information disclosure vulnerability. Information relating to... |
| CVE-2019-3740 | MEDIUM | 6.5 | 3.8% | Sep 18, 2019 | RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to an Information Exposure Through Timing Discrepancy vulnerab... |
| CVE-2019-3739 | MEDIUM | 6.5 | 2.5% | Sep 18, 2019 | RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to Information Exposure Through Timing Discrepancy vulnerabili... |
| CVE-2019-3738 | MEDIUM | 6.5 | 1.7% | Sep 18, 2019 | RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to a Missing Required Cryptographic Step vulnerability. A mali... |
| CVE-2019-11778 | MEDIUM | 5.4 | 0.8% | Sep 18, 2019 | If an MQTT v5 client connects to Eclipse Mosquitto versions 1.6.0 to 1.6.4 inclusive, sets a last will and testament, se... |
| CVE-2019-5531 | MEDIUM | 5.4 | 1.0% | Sep 18, 2019 | VMware vSphere ESXi (6.7 prior to ESXi670-201810101-SG, 6.5 prior to ESXi650-201811102-SG, and 6.0 prior to ESXi600-2018... |
| CVE-2019-11664 | MEDIUM | 6.5 | 0.5% | Sep 18, 2019 | Clear text password in browser in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40,... |
| CVE-2019-11663 | MEDIUM | 6.5 | 0.5% | Sep 18, 2019 | Clear text credentials are used to access managers app in Tomcat in Micro Focus Service Manager product versions 9.30, 9... |
| CVE-2019-11662 | MEDIUM | 4.3 | 0.7% | Sep 18, 2019 | Class and method names in error message in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.... |
| CVE-2019-9680 | MEDIUM | 5.3 | 1.4% | Sep 18, 2019 | Some Dahua products have information leakage issues. Attackers can obtain the IP address and device model information of... |
| CVE-2019-1975 | MEDIUM | 6.1 | 1.2% | Sep 18, 2019 | A vulnerability in the web-based interface of Cisco HyperFlex Software could allow an unauthenticated, remote attacker t... |
| CVE-2019-12620 | MEDIUM | 5.3 | 0.7% | Sep 18, 2019 | A vulnerability in the statistics collection service of Cisco HyperFlex Software could allow an unauthenticated, remote ... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now