2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-0361 | MEDIUM | 6.1 | 0.6% | Sep 10, 2019 | SAP Supplier Relationship Management (Master Data Management Catalog - SRM_MDM_CAT, before versions 3.73, 7.31, 7.32) do... |
| CVE-2019-0357 | MEDIUM | 6.7 | 0.4% | Sep 10, 2019 | The administrator of SAP HANA database, before versions 1.0 and 2.0, can misuse HANA to execute commands with operating ... |
| CVE-2019-0356 | MEDIUM | 4.3 | 0.7% | Sep 10, 2019 | Under certain conditions SAP NetWeaver Process Integration Runtime Workbench – MESSAGING and SAP_XIAF (before versions 7... |
| CVE-2019-5503 | MEDIUM | 5.3 | 0.7% | Sep 10, 2019 | OnCommand Workflow Automation versions prior to 5.0 shipped without certain HTTP Security headers configured which could... |
| CVE-2019-14730 | MEDIUM | 4.3 | 1.5% | Sep 10, 2019 | In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to delete a... |
| CVE-2019-14729 | MEDIUM | 4.3 | 1.5% | Sep 10, 2019 | In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to delete a... |
| CVE-2019-14728 | MEDIUM | 4.3 | 1.5% | Sep 10, 2019 | In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to add an e... |
| CVE-2019-14727 | MEDIUM | 4.3 | 1.5% | Sep 10, 2019 | In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to change t... |
| CVE-2019-14726 | MEDIUM | 5.4 | 1.3% | Sep 10, 2019 | In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to access a... |
| CVE-2019-14723 | MEDIUM | 4.3 | 1.5% | Sep 10, 2019 | In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to delete a... |
| CVE-2019-14722 | MEDIUM | 4.3 | 1.5% | Sep 10, 2019 | In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to delete a... |
| CVE-2019-14721 | MEDIUM | 6.5 | 1.8% | Sep 10, 2019 | In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to remove a... |
| CVE-2019-16202 | MEDIUM | 6.5 | 1.3% | Sep 10, 2019 | MISP before 2.4.115 allows privilege escalation in certain situations. After updating to 2.4.115, escalation attempts ar... |
| CVE-2019-6791 | MEDIUM | 6.5 | 0.8% | Sep 9, 2019 | An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x befor... |
| CVE-2019-16182 | MEDIUM | 6.1 | 1.1% | Sep 9, 2019 | A reflected cross-site scripting (XSS) vulnerability was found in Limesurvey before 3.17.14 that allows remote attackers... |
| CVE-2019-16180 | MEDIUM | 5.3 | 1.7% | Sep 9, 2019 | Limesurvey before 3.17.14 allows remote attackers to bruteforce the login form and enumerate usernames when the LDAP aut... |
| CVE-2019-16179 | MEDIUM | 5.3 | 1.0% | Sep 9, 2019 | Limesurvey before 3.17.14 does not enforce SSL/TLS usage in the default configuration. |
| CVE-2019-16178 | MEDIUM | 5.4 | 0.7% | Sep 9, 2019 | A stored cross-site scripting (XSS) vulnerability was found in Limesurvey before 3.17.14 that allows authenticated users... |
| CVE-2019-16176 | MEDIUM | 5.3 | 1.6% | Sep 9, 2019 | A path disclosure vulnerability was found in Limesurvey before 3.17.14 that allows a remote attacker to discover the pat... |
| CVE-2019-16175 | MEDIUM | 4.3 | 0.9% | Sep 9, 2019 | A clickjacking vulnerability was found in Limesurvey before 3.17.14. |
| CVE-2019-16147 | MEDIUM | 6.1 | 0.8% | Sep 9, 2019 | Liferay Portal through 7.2.0 GA1 allows XSS via a journal article title to journal_article/page.jsp in journal/journal-t... |
| CVE-2019-16145 | MEDIUM | 6.1 | 0.8% | Sep 9, 2019 | The breadcrumbs contributed module through 0.2.0 for Padrino Framework allows XSS via a caption. |
| CVE-2019-15297 | MEDIUM | 6.5 | 3.5% | Sep 9, 2019 | res_pjsip_t38 in Sangoma Asterisk 15.x before 15.7.4 and 16.x before 16.5.1 allows an attacker to trigger a crash by sen... |
| CVE-2019-10253 | MEDIUM | 6.5 | 0.7% | Sep 9, 2019 | A Cross-Site Request Forgery (CSRF) vulnerability exists in TeamMate+ 21.0.0.0 that allows a remote attacker to modify a... |
| CVE-2019-6997 | MEDIUM | 4.3 | 0.8% | Sep 9, 2019 | An issue was discovered in GitLab Community and Enterprise Edition 10.x (starting in 10.7) and 11.x before 11.5.8, 11.6.... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now