2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-8451 | MEDIUM | 6.5 | 94.5% | Sep 11, 2019 | The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.4.0 allows remote attackers to access the con... |
| CVE-2019-8450 | MEDIUM | 4.8 | 0.9% | Sep 11, 2019 | Various templates of the Optimization plugin in Jira before version 7.13.6, and from version 8.0.0 before version 8.4.0 ... |
| CVE-2019-8449 | MEDIUM | 5.3 | 84.8% | Sep 11, 2019 | The /rest/api/latest/groupuserpicker resource in Jira before version 8.4.0 allows remote attackers to enumerate username... |
| CVE-2019-16223 | MEDIUM | 5.4 | 5.2% | Sep 11, 2019 | WordPress before 5.2.3 allows XSS in post previews by authenticated users. |
| CVE-2019-16222 | MEDIUM | 6.1 | 2.2% | Sep 11, 2019 | WordPress before 5.2.3 has an issue with URL sanitization in wp_kses_bad_protocol_once in wp-includes/kses.php that can ... |
| CVE-2019-16221 | MEDIUM | 6.1 | 1.8% | Sep 11, 2019 | WordPress before 5.2.3 allows reflected XSS in the dashboard. |
| CVE-2019-16220 | MEDIUM | 6.1 | 2.5% | Sep 11, 2019 | In WordPress before 5.2.3, validation and sanitization of a URL in wp_validate_redirect in wp-includes/pluggable.php cou... |
| CVE-2019-16219 | MEDIUM | 6.1 | 1.9% | Sep 11, 2019 | WordPress before 5.2.3 allows XSS in shortcode previews. |
| CVE-2019-16218 | MEDIUM | 6.1 | 1.8% | Sep 11, 2019 | WordPress before 5.2.3 allows XSS in stored comments. |
| CVE-2019-16217 | MEDIUM | 6.1 | 1.5% | Sep 11, 2019 | WordPress before 5.2.3 allows XSS in media uploads because wp_ajax_upload_attachment is mishandled. |
| CVE-2019-14998 | MEDIUM | 6.5 | 1.2% | Sep 11, 2019 | The Webwork action Cross-Site Request Forgery (CSRF) protection implementation in Jira before version 8.4.0 allows remot... |
| CVE-2019-14997 | MEDIUM | 4.3 | 1.2% | Sep 11, 2019 | The AccessLogFilter class in Jira before version 8.4.0 allows remote anonymous attackers to learn details about other us... |
| CVE-2019-14996 | MEDIUM | 6.1 | 1.3% | Sep 11, 2019 | The FilterPickerPopup.jspa resource in Jira before version 7.13.7, and from version 8.0.0 before version 8.3.3 allows re... |
| CVE-2019-14995 | MEDIUM | 5.3 | 3.0% | Sep 11, 2019 | The /rest/api/1.0/render resource in Jira before version 8.4.0 allows remote anonymous attackers to determine if an atta... |
| CVE-2019-16193 | MEDIUM | 5.4 | 0.6% | Sep 11, 2019 | In ArcGIS Enterprise 10.6.1, a crafted IFRAME element can be used to trigger a Cross Frame Scripting (XFS) attack throug... |
| CVE-2019-14725 | MEDIUM | 4.3 | 1.5% | Sep 11, 2019 | In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to change t... |
| CVE-2019-16214 | MEDIUM | 5.7 | 1.3% | Sep 11, 2019 | Libra Core before 2019-09-03 has an erroneous regular expression for inline comments, which makes it easier for attacker... |
| CVE-2019-12942 | MEDIUM | 6.5 | 0.8% | Sep 10, 2019 | TTLock devices do not properly block guest access in certain situations where the network connection to the cloud is una... |
| CVE-2019-12996 | MEDIUM | 5.3 | 0.8% | Sep 10, 2019 | In Mendix 7.23.5 and earlier, issue in XML import mappings allow DOCTYPE declarations in the XML input that is potential... |
| CVE-2019-11466 | MEDIUM | 5.3 | 1.1% | Sep 10, 2019 | In Couchbase Server 6.0.0 and 5.5.0, the eventing service exposes system diagnostic profile via an HTTP endpoint that do... |
| CVE-2019-1549 | MEDIUM | 5.3 | 6.2% | Sep 10, 2019 | OpenSSL 1.1.1 introduced a rewritten random number generator (RNG). This was intended to include protection in the event... |
| CVE-2019-1547 | MEDIUM | 4.7 | 1.2% | Sep 10, 2019 | Normally in OpenSSL EC groups always have a co-factor present and this is used in side channel resistant code paths. How... |
| CVE-2019-11465 | MEDIUM | 5.3 | 1.2% | Sep 10, 2019 | An issue was discovered in Couchbase Server 5.5.x through 5.5.3 and 6.0.0. The Memcached "connections" stat block comman... |
| CVE-2019-11464 | MEDIUM | 6.1 | 0.9% | Sep 10, 2019 | Some enterprises require that REST API endpoints include security-related headers in REST responses. Headers such as X-F... |
| CVE-2019-0364 | MEDIUM | 4.3 | 0.7% | Sep 10, 2019 | Attackers may misuse an HTTP/REST endpoint of SAP HANA Extended Application Services (Advanced model), before version 1.... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now