2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-0361MEDIUM6.1SAP Supplier Relationship Management (Master Data Management Catalog - SRM_MDM_CAT, before versions 3.73, 7.31, 7.32) do...
CVE-2019-0357MEDIUM6.7The administrator of SAP HANA database, before versions 1.0 and 2.0, can misuse HANA to execute commands with operating ...
CVE-2019-0356MEDIUM4.3Under certain conditions SAP NetWeaver Process Integration Runtime Workbench – MESSAGING and SAP_XIAF (before versions 7...
CVE-2019-5503MEDIUM5.3OnCommand Workflow Automation versions prior to 5.0 shipped without certain HTTP Security headers configured which could...
CVE-2019-14730MEDIUM4.3In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to delete a...
CVE-2019-14729MEDIUM4.3In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to delete a...
CVE-2019-14728MEDIUM4.3In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to add an e...
CVE-2019-14727MEDIUM4.3In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to change t...
CVE-2019-14726MEDIUM5.4In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to access a...
CVE-2019-14723MEDIUM4.3In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to delete a...
CVE-2019-14722MEDIUM4.3In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to delete a...
CVE-2019-14721MEDIUM6.5In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to remove a...
CVE-2019-16202MEDIUM6.5MISP before 2.4.115 allows privilege escalation in certain situations. After updating to 2.4.115, escalation attempts ar...
CVE-2019-6791MEDIUM6.5An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x befor...
CVE-2019-16182MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability was found in Limesurvey before 3.17.14 that allows remote attackers...
CVE-2019-16180MEDIUM5.3Limesurvey before 3.17.14 allows remote attackers to bruteforce the login form and enumerate usernames when the LDAP aut...
CVE-2019-16179MEDIUM5.3Limesurvey before 3.17.14 does not enforce SSL/TLS usage in the default configuration.
CVE-2019-16178MEDIUM5.4A stored cross-site scripting (XSS) vulnerability was found in Limesurvey before 3.17.14 that allows authenticated users...
CVE-2019-16176MEDIUM5.3A path disclosure vulnerability was found in Limesurvey before 3.17.14 that allows a remote attacker to discover the pat...
CVE-2019-16175MEDIUM4.3A clickjacking vulnerability was found in Limesurvey before 3.17.14.
CVE-2019-16147MEDIUM6.1Liferay Portal through 7.2.0 GA1 allows XSS via a journal article title to journal_article/page.jsp in journal/journal-t...
CVE-2019-16145MEDIUM6.1The breadcrumbs contributed module through 0.2.0 for Padrino Framework allows XSS via a caption.
CVE-2019-15297MEDIUM6.5res_pjsip_t38 in Sangoma Asterisk 15.x before 15.7.4 and 16.x before 16.5.1 allows an attacker to trigger a crash by sen...
CVE-2019-10253MEDIUM6.5A Cross-Site Request Forgery (CSRF) vulnerability exists in TeamMate+ 21.0.0.0 that allows a remote attacker to modify a...
CVE-2019-6997MEDIUM4.3An issue was discovered in GitLab Community and Enterprise Edition 10.x (starting in 10.7) and 11.x before 11.5.8, 11.6....

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now