2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-4616 | LOW | 3.5 | 0.3% | Feb 5, 2020 | IBM Cloud Automation Manager 3.2.1.0 does not set the secure attribute on authorization tokens or session cookies. Attac... |
| CVE-2019-4613 | HIGH | 8.8 | 0.5% | Feb 5, 2020 | IBM Planning Analytics 2.0 is vulnerable to cross-site request forgery which could allow an attacker to execute maliciou... |
| CVE-2019-16204 | HIGH | 7.5 | 1.5% | Feb 5, 2020 | Brocade Fabric OS Versions before v7.4.2f, v8.2.2a, v8.1.2j and v8.2.1d could expose external passwords, common secrets ... |
| CVE-2019-16203 | HIGH | 7.5 | 1.4% | Feb 5, 2020 | Brocade Fabric OS Versions before v8.2.2a and v8.2.1d could expose the credentials of the remote ESRS server when these ... |
| CVE-2019-12528 | HIGH | 7.5 | 10.5% | Feb 4, 2020 | An issue was discovered in Squid before 4.10. It allows a crafted FTP server to trigger disclosure of sensitive informat... |
| CVE-2019-10788 | CRITICAL | 9.8 | 2.4% | Feb 4, 2020 | im-metadata through 3.0.1 allows remote attackers to execute arbitrary commands via the "exec" argument. It is possible ... |
| CVE-2019-10787 | CRITICAL | 9.8 | 3.8% | Feb 4, 2020 | im-resize through 2.3.2 allows remote attackers to execute arbitrary commands via the "exec" argument. The cmd argument ... |
| CVE-2019-10786 | CRITICAL | 9.8 | 2.1% | Feb 4, 2020 | network-manager through 1.0.2 allows remote attackers to execute arbitrary commands via the "execSync()" argument. |
| CVE-2019-15624 | MEDIUM | 4.9 | 1.5% | Feb 4, 2020 | Improper Input Validation in Nextcloud Server 15.0.7 allows group admins to create users with IDs of system folders. |
| CVE-2019-15623 | MEDIUM | 5.3 | 1.9% | Feb 4, 2020 | Exposure of Private Information in Nextcloud Server 16.0.1 causes the server to send it's domain and user IDs to the Nex... |
| CVE-2019-15622 | LOW | 2.4 | 0.5% | Feb 4, 2020 | Not strictly enough sanitization in the Nextcloud Android app 3.6.0 allowed an attacker to get content information from ... |
| CVE-2019-15621 | MEDIUM | 6.5 | 1.1% | Feb 4, 2020 | Improper permissions preservation in Nextcloud Server 16.0.1 causes sharees to be able to reshare with write permissions... |
| CVE-2019-15620 | LOW | 2.7 | 0.8% | Feb 4, 2020 | Improper access control in Nextcloud Talk 6.0.3 leaks the existance and the name of private conversations when linked th... |
| CVE-2019-15619 | MEDIUM | 4.8 | 0.8% | Feb 4, 2020 | Improper neutralization of file names, conversation names and board names in Nextcloud Server 16.0.3, Nextcloud Talk 6.0... |
| CVE-2019-15618 | MEDIUM | 4.8 | 0.7% | Feb 4, 2020 | Missing escaping of HTML in the Updater of Nextcloud 15.0.5 allowed a reflected XSS when starting the updater from a mal... |
| CVE-2019-15617 | MEDIUM | 5.4 | 0.6% | Feb 4, 2020 | A missing check in Nextcloud Server 17.0.0 allowed an attacker to set up a new second factor when trying to login. |
| CVE-2019-15616 | MEDIUM | 4.3 | 0.8% | Feb 4, 2020 | Dangling remote share attempts in Nextcloud 16 allow a DNS pollution when running long. |
| CVE-2019-15615 | MEDIUM | 6.1 | 0.4% | Feb 4, 2020 | A wrong check for the system time in the Android App 3.9.0 causes a bypass of the lock protection when changing the time... |
| CVE-2019-15614 | MEDIUM | 5.4 | 0.8% | Feb 4, 2020 | Missing sanitization in the iOS App 2.24.4 causes an XSS when opening malicious HTML files. |
| CVE-2019-15613 | HIGH | 8 | 1.1% | Feb 4, 2020 | A bug in Nextcloud Server 17.0.1 causes the workflow rules to depend their behaviour on the file extension when checking... |
| CVE-2019-15612 | MEDIUM | 5.9 | 0.3% | Feb 4, 2020 | A bug in Nextcloud Server 15.0.2 causes pending 2FA logins to not be correctly expired when the password of the user is ... |
| CVE-2019-15611 | MEDIUM | 4.9 | 1.1% | Feb 4, 2020 | Violation of Secure Design Principles in the iOS App 2.23.0 causes the app to leak its login and token to other Nextclou... |
| CVE-2019-15610 | MEDIUM | 4.3 | 0.8% | Feb 4, 2020 | Improper authorization in the Circles app 0.17.7 causes retaining access when an email address was removed from a circle... |
| CVE-2019-10784 | CRITICAL | 9.6 | 3.6% | Feb 4, 2020 | phppgadmin through 7.12.1 allows sensitive actions to be performed without validating that the request originated from t... |
| CVE-2019-4675 | CRITICAL | 9.8 | 1.3% | Feb 4, 2020 | IBM Security Identity Manager 7.0.1 contains hard-coded credentials, such as a password or cryptographic key, which it u... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now