2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-17587 | — | — | — | Feb 6, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not as... |
| CVE-2019-17586 | — | — | — | Feb 6, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not as... |
| CVE-2019-17585 | — | — | — | Feb 6, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not as... |
| CVE-2019-19800 | MEDIUM | 5.3 | 3.9% | Feb 6, 2020 | Zoho ManageEngine Applications Manager 14 before 14520 allows a remote unauthenticated attacker to disclose OS file name... |
| CVE-2019-12426 | MEDIUM | 5.3 | 4.9% | Feb 6, 2020 | an unauthenticated user could get access to information of some backend screens by invoking setSessionLocale in Apache O... |
| CVE-2019-17652 | MEDIUM | 6.5 | 1.4% | Feb 6, 2020 | A stack buffer overflow vulnerability in FortiClient for Linux 6.2.1 and below may allow a user with low privilege to ca... |
| CVE-2019-16152 | MEDIUM | 6.5 | 1.4% | Feb 6, 2020 | A Denial of service (DoS) vulnerability in FortiClient for Linux 6.2.1 and below may allow an user with low privilege to... |
| CVE-2019-15711 | HIGH | 7.8 | 0.5% | Feb 6, 2020 | A privilege escalation vulnerability in FortiClient for Linux 6.2.1 and below may allow an user with low privilege to ru... |
| CVE-2019-10789 | CRITICAL | 9.8 | 4.9% | Feb 6, 2020 | All versions of curling.js are vulnerable to Command Injection via the run function. The command argument can be control... |
| CVE-2019-20406 | HIGH | 7.8 | 0.5% | Feb 6, 2020 | The usage of Tomcat in Confluence on the Microsoft Windows operating system before version 7.0.5, and from version 7.1.0... |
| CVE-2019-20405 | MEDIUM | 4.3 | 0.6% | Feb 6, 2020 | The JMX monitoring flag in Atlassian Jira Server and Data Center before version 8.6.0 allows remote attackers to turn th... |
| CVE-2019-20404 | MEDIUM | 4.3 | 1.3% | Feb 6, 2020 | The API in Atlassian Jira Server and Data Center before version 8.6.0 allows authenticated remote attackers to determine... |
| CVE-2019-20403 | MEDIUM | 5.3 | 1.5% | Feb 6, 2020 | The API in Atlassian Jira Server and Data Center before version 8.6.0 allows remote attackers to determine if a Jira pro... |
| CVE-2019-20402 | MEDIUM | 4.9 | 0.8% | Feb 6, 2020 | Support zip files in Atlassian Jira Server and Data Center before version 8.6.0 could be downloaded by a System Administ... |
| CVE-2019-20401 | MEDIUM | 6.5 | 0.8% | Feb 6, 2020 | Various installation setup resources in Jira before version 8.5.2 allow remote attackers to configure a Jira instance, w... |
| CVE-2019-20400 | HIGH | 7.8 | 0.4% | Feb 6, 2020 | The usage of Tomcat in Jira before version 8.5.2 allows local attackers with permission to write a dll file to a directo... |
| CVE-2019-20106 | MEDIUM | 4.3 | 1.2% | Feb 6, 2020 | Comment properties in Atlassian Jira Server and Data Center before version 7.13.12, from 8.0.0 before version 8.5.4, and... |
| CVE-2019-20104 | HIGH | 7.5 | 2.4% | Feb 6, 2020 | The OpenID client application in Atlassian Crowd before version 3.6.2, and from version 3.7.0 before 3.7.1 allows remote... |
| CVE-2019-20447 | CRITICAL | 9.8 | 2.0% | Feb 5, 2020 | Jobberbase 2.0 has SQL injection via the PATH_INFO to the jobs-in endpoint. |
| CVE-2019-20173 | MEDIUM | 6.1 | 2.5% | Feb 5, 2020 | The Auth0 wp-auth0 plugin 3.11.x before 3.11.3 for WordPress allows XSS via a wle parameter associated with wp-login.php... |
| CVE-2019-15253 | MEDIUM | 4.8 | 3.1% | Feb 5, 2020 | A vulnerability in the web-based management interface of Cisco Digital Network Architecture (DNA) Center could allow an ... |
| CVE-2019-15126 | LOW | 3.1 | 7.7% | Feb 5, 2020 | An issue was discovered on Broadcom Wi-Fi client devices. Specifically timed and handcrafted traffic can cause internal ... |
| CVE-2019-12180 | HIGH | 7.8 | 4.6% | Feb 5, 2020 | An issue was discovered in SmartBear ReadyAPI through 2.8.2 and 3.0.0 and SoapUI through 5.5. When opening a project, th... |
| CVE-2019-11516 | HIGH | 8.1 | 0.9% | Feb 5, 2020 | An issue was discovered in the Bluetooth component of the Cypress (formerly owned by Broadcom) Wireless IoT codebase. Ex... |
| CVE-2019-4670 | MEDIUM | 6.5 | 1.8% | Feb 5, 2020 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to obtain sensitive information ca... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now