2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-14253 | MEDIUM | 6.5 | 1.1% | Sep 18, 2019 | An issue was discovered in servletcontroller in the secure portal in Publisure 2.1.2. One can bypass authentication and ... |
| CVE-2019-16216 | MEDIUM | 5.4 | 0.7% | Sep 18, 2019 | Zulip server before 2.0.5 incompletely validated the MIME types of uploaded files. A user who is logged into the server ... |
| CVE-2019-16215 | MEDIUM | 6.5 | 1.2% | Sep 18, 2019 | The Markdown parser in Zulip server before 2.0.5 used a regular expression vulnerable to exponential backtracking. A use... |
| CVE-2019-16394 | MEDIUM | 5.3 | 7.5% | Sep 17, 2019 | SPIP before 3.1.11 and 3.2 before 3.2.5 provides different error messages from the password-reminder page depending on w... |
| CVE-2019-16393 | MEDIUM | 6.1 | 1.1% | Sep 17, 2019 | SPIP before 3.1.11 and 3.2 before 3.2.5 mishandles redirect URLs in ecrire/inc/headers.php with a %0D, %0A, or %20 chara... |
| CVE-2019-16392 | MEDIUM | 6.1 | 1.2% | Sep 17, 2019 | SPIP before 3.1.11 and 3.2 before 3.2.5 allows prive/formulaires/login.php XSS via error messages. |
| CVE-2019-16391 | MEDIUM | 6.5 | 1.5% | Sep 17, 2019 | SPIP before 3.1.11 and 3.2 before 3.2.5 allows authenticated visitors to modify any published content and execute other ... |
| CVE-2019-6838 | MEDIUM | 6.5 | 0.8% | Sep 17, 2019 | A CWE-863: Incorrect Authorization vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-... |
| CVE-2019-6835 | MEDIUM | 5.4 | 0.5% | Sep 17, 2019 | A Cross-Site Scripting (XSS) CWE-79 vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501... |
| CVE-2019-6833 | MEDIUM | 6.5 | 1.0% | Sep 17, 2019 | A CWE-754 – Improper Check for Unusual or Exceptional Conditions vulnerability exists in Magelis HMI Panels (all version... |
| CVE-2019-6830 | MEDIUM | 5.9 | 1.1% | Sep 17, 2019 | A CWE-248: Uncaught Exception vulnerability exists IN Modicon M580 all versions prior to V2.80, which could cause a poss... |
| CVE-2019-4477 | MEDIUM | 6.5 | 1.3% | Sep 17, 2019 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a user with access to audit logs to obtain sensitive... |
| CVE-2019-4442 | MEDIUM | 4.3 | 2.1% | Sep 17, 2019 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9,0 could allow a remote attacker to traverse directories on the fil... |
| CVE-2019-4342 | MEDIUM | 5.4 | 1.0% | Sep 17, 2019 | IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbit... |
| CVE-2019-4270 | MEDIUM | 5.4 | 0.7% | Sep 17, 2019 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Admin Console is vulnerable to cross-site scripting. This vulner... |
| CVE-2019-4268 | MEDIUM | 5.3 | 2.7% | Sep 17, 2019 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on the sys... |
| CVE-2019-4086 | MEDIUM | 6.1 | 1.2% | Sep 17, 2019 | IBM Cloud Application Performance Management 8.1.4 could allow a remote attacker to hijack the clicking action of the vi... |
| CVE-2019-13542 | MEDIUM | 6.5 | 1.4% | Sep 17, 2019 | 3S-Smart Software Solutions GmbH CODESYS V3 OPC UA Server, all versions 3.5.11.0 to 3.5.15.0, allows an attacker to send... |
| CVE-2019-9681 | MEDIUM | 5.3 | 0.8% | Sep 17, 2019 | Online upgrade information in some firmware packages of Dahua products is not encrypted. Attackers can obtain this infor... |
| CVE-2019-14826 | MEDIUM | 4.4 | 0.3% | Sep 17, 2019 | A flaw was found in FreeIPA versions 4.5.0 and later. Session cookies were retained in the cache after logout. An attack... |
| CVE-2019-12755 | MEDIUM | 5.5 | 0.3% | Sep 17, 2019 | Norton Password Manager, prior to 6.5.0.2104, may be susceptible to an information disclosure issue, which is a type of ... |
| CVE-2019-11559 | MEDIUM | 6.1 | 1.1% | Sep 17, 2019 | A reflected Cross-site scripting (XSS) vulnerability in HRworks V 1.16.1 allows remote attackers to inject arbitrary web... |
| CVE-2019-8368 | MEDIUM | 6.1 | 46.9% | Sep 16, 2019 | OpenEMR v5.0.1-6 allows XSS. |
| CVE-2019-16370 | MEDIUM | 5.9 | 1.0% | Sep 16, 2019 | The PGP signing plugin in Gradle before 6.0 relies on the SHA-1 algorithm, which might allow an attacker to replace an a... |
| CVE-2019-15740 | MEDIUM | 5.3 | 1.6% | Sep 16, 2019 | An issue was discovered in GitLab Community and Enterprise Edition 7.9 through 12.2.1. EXIF Geolocation data was not bei... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now