2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-8451MEDIUM6.5The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.4.0 allows remote attackers to access the con...
CVE-2019-8450MEDIUM4.8Various templates of the Optimization plugin in Jira before version 7.13.6, and from version 8.0.0 before version 8.4.0 ...
CVE-2019-8449MEDIUM5.3The /rest/api/latest/groupuserpicker resource in Jira before version 8.4.0 allows remote attackers to enumerate username...
CVE-2019-16223MEDIUM5.4WordPress before 5.2.3 allows XSS in post previews by authenticated users.
CVE-2019-16222MEDIUM6.1WordPress before 5.2.3 has an issue with URL sanitization in wp_kses_bad_protocol_once in wp-includes/kses.php that can ...
CVE-2019-16221MEDIUM6.1WordPress before 5.2.3 allows reflected XSS in the dashboard.
CVE-2019-16220MEDIUM6.1In WordPress before 5.2.3, validation and sanitization of a URL in wp_validate_redirect in wp-includes/pluggable.php cou...
CVE-2019-16219MEDIUM6.1WordPress before 5.2.3 allows XSS in shortcode previews.
CVE-2019-16218MEDIUM6.1WordPress before 5.2.3 allows XSS in stored comments.
CVE-2019-16217MEDIUM6.1WordPress before 5.2.3 allows XSS in media uploads because wp_ajax_upload_attachment is mishandled.
CVE-2019-14998MEDIUM6.5The Webwork action Cross-Site Request Forgery (CSRF) protection implementation in Jira before version 8.4.0 allows remot...
CVE-2019-14997MEDIUM4.3The AccessLogFilter class in Jira before version 8.4.0 allows remote anonymous attackers to learn details about other us...
CVE-2019-14996MEDIUM6.1The FilterPickerPopup.jspa resource in Jira before version 7.13.7, and from version 8.0.0 before version 8.3.3 allows re...
CVE-2019-14995MEDIUM5.3The /rest/api/1.0/render resource in Jira before version 8.4.0 allows remote anonymous attackers to determine if an atta...
CVE-2019-16193MEDIUM5.4In ArcGIS Enterprise 10.6.1, a crafted IFRAME element can be used to trigger a Cross Frame Scripting (XFS) attack throug...
CVE-2019-14725MEDIUM4.3In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to change t...
CVE-2019-16214MEDIUM5.7Libra Core before 2019-09-03 has an erroneous regular expression for inline comments, which makes it easier for attacker...
CVE-2019-12942MEDIUM6.5TTLock devices do not properly block guest access in certain situations where the network connection to the cloud is una...
CVE-2019-12996MEDIUM5.3In Mendix 7.23.5 and earlier, issue in XML import mappings allow DOCTYPE declarations in the XML input that is potential...
CVE-2019-11466MEDIUM5.3In Couchbase Server 6.0.0 and 5.5.0, the eventing service exposes system diagnostic profile via an HTTP endpoint that do...
CVE-2019-1549MEDIUM5.3OpenSSL 1.1.1 introduced a rewritten random number generator (RNG). This was intended to include protection in the event...
CVE-2019-1547MEDIUM4.7Normally in OpenSSL EC groups always have a co-factor present and this is used in side channel resistant code paths. How...
CVE-2019-11465MEDIUM5.3An issue was discovered in Couchbase Server 5.5.x through 5.5.3 and 6.0.0. The Memcached "connections" stat block comman...
CVE-2019-11464MEDIUM6.1Some enterprises require that REST API endpoints include security-related headers in REST responses. Headers such as X-F...
CVE-2019-0364MEDIUM4.3Attackers may misuse an HTTP/REST endpoint of SAP HANA Extended Application Services (Advanced model), before version 1....

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now