2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-17587Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not as...
CVE-2019-17586Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not as...
CVE-2019-17585Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not as...
CVE-2019-19800MEDIUM5.3Zoho ManageEngine Applications Manager 14 before 14520 allows a remote unauthenticated attacker to disclose OS file name...
CVE-2019-12426MEDIUM5.3an unauthenticated user could get access to information of some backend screens by invoking setSessionLocale in Apache O...
CVE-2019-17652MEDIUM6.5A stack buffer overflow vulnerability in FortiClient for Linux 6.2.1 and below may allow a user with low privilege to ca...
CVE-2019-16152MEDIUM6.5A Denial of service (DoS) vulnerability in FortiClient for Linux 6.2.1 and below may allow an user with low privilege to...
CVE-2019-15711HIGH7.8A privilege escalation vulnerability in FortiClient for Linux 6.2.1 and below may allow an user with low privilege to ru...
CVE-2019-10789CRITICAL9.8All versions of curling.js are vulnerable to Command Injection via the run function. The command argument can be control...
CVE-2019-20406HIGH7.8The usage of Tomcat in Confluence on the Microsoft Windows operating system before version 7.0.5, and from version 7.1.0...
CVE-2019-20405MEDIUM4.3The JMX monitoring flag in Atlassian Jira Server and Data Center before version 8.6.0 allows remote attackers to turn th...
CVE-2019-20404MEDIUM4.3The API in Atlassian Jira Server and Data Center before version 8.6.0 allows authenticated remote attackers to determine...
CVE-2019-20403MEDIUM5.3The API in Atlassian Jira Server and Data Center before version 8.6.0 allows remote attackers to determine if a Jira pro...
CVE-2019-20402MEDIUM4.9Support zip files in Atlassian Jira Server and Data Center before version 8.6.0 could be downloaded by a System Administ...
CVE-2019-20401MEDIUM6.5Various installation setup resources in Jira before version 8.5.2 allow remote attackers to configure a Jira instance, w...
CVE-2019-20400HIGH7.8The usage of Tomcat in Jira before version 8.5.2 allows local attackers with permission to write a dll file to a directo...
CVE-2019-20106MEDIUM4.3Comment properties in Atlassian Jira Server and Data Center before version 7.13.12, from 8.0.0 before version 8.5.4, and...
CVE-2019-20104HIGH7.5The OpenID client application in Atlassian Crowd before version 3.6.2, and from version 3.7.0 before 3.7.1 allows remote...
CVE-2019-20447CRITICAL9.8Jobberbase 2.0 has SQL injection via the PATH_INFO to the jobs-in endpoint.
CVE-2019-20173MEDIUM6.1The Auth0 wp-auth0 plugin 3.11.x before 3.11.3 for WordPress allows XSS via a wle parameter associated with wp-login.php...
CVE-2019-15253MEDIUM4.8A vulnerability in the web-based management interface of Cisco Digital Network Architecture (DNA) Center could allow an ...
CVE-2019-15126LOW3.1An issue was discovered on Broadcom Wi-Fi client devices. Specifically timed and handcrafted traffic can cause internal ...
CVE-2019-12180HIGH7.8An issue was discovered in SmartBear ReadyAPI through 2.8.2 and 3.0.0 and SoapUI through 5.5. When opening a project, th...
CVE-2019-11516HIGH8.1An issue was discovered in the Bluetooth component of the Cypress (formerly owned by Broadcom) Wireless IoT codebase. Ex...
CVE-2019-4670MEDIUM6.5IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to obtain sensitive information ca...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now