2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-4674MEDIUM4.9IBM Security Identity Manager 7.0.1 could allow a remote attacker to traverse directories on the system. An attacker cou...
CVE-2019-4562MEDIUM5.3IBM Security Directory Server 6.4.0 stores sensitive information in URLs. This may lead to information disclosure if una...
CVE-2019-4551MEDIUM5.3IBM Security Directory Server 6.4.0 does not perform an authentication check for a critical resource or functionality al...
CVE-2019-4550MEDIUM5.3IBM Security Directory Server 6.4.0 is deployed with active debugging code that can create unintended entry points. IBM ...
CVE-2019-4548MEDIUM6.1IBM Security Directory Server 6.4.0 could allow a remote attacker to hijack the clicking action of the victim. By persua...
CVE-2019-4541HIGH7.2IBM Security Directory Server 6.4.0 uses incomplete blacklisting for input validation which allows attackers to bypass a...
CVE-2019-4540HIGH7.5IBM Security Directory Server 6.4.0 uses weaker than expected cryptographic algorithms that could allow an attacker to d...
CVE-2019-4451MEDIUM5.4IBM Security Identity Manager 6.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbi...
CVE-2019-19273HIGH7.8On Samsung mobile devices with O(8.0) and P(9.0) software and an Exynos 8895 chipset, RKP (aka the Samsung Hypervisor EL...
CVE-2019-9674HIGH7.5Lib/zipfile.py in Python through 3.7.2 allows remote attackers to cause a denial of service (resource consumption) via a...
CVE-2019-19968MEDIUM5.4PandoraFMS 742 suffers from multiple XSS vulnerabilities, affecting the Agent Management, Report Builder, and Graph Buil...
CVE-2019-9502HIGH8.8The Broadcom wl WiFi driver is vulnerable to a heap buffer overflow. If the vendor information element data length is la...
CVE-2019-9501HIGH8.8The Broadcom wl WiFi driver is vulnerable to a heap buffer overflow. By supplying a vendor information element with a da...
CVE-2019-20174MEDIUM6.1Auth0 Lock before 11.21.0 allows XSS when additionalSignUpFields is used with an untrusted placeholder.
CVE-2019-18567MEDIUM6.3Bromium client version 4.0.3.2060 and prior to 4.1.7 Update 1 has an out of bound read results in race condition causing...
CVE-2019-4732MEDIUM6.5IBM SDK, Java Technology Edition Version 7.0.0.0 through 7.0.10.55, 7.1.0.0 through 7.1.4.55, and 8.0.0.0 through 8.0.6....
CVE-2019-16893HIGH7.5The Web Management of TP-Link TP-SG105E V4 1.0.0 Build 20181120 devices allows an unauthenticated attacker to reboot the...
CVE-2019-11251MEDIUM5.7The Kubernetes kubectl cp command in versions 1.1-1.12, and versions prior to 1.13.11, 1.14.7, and 1.15.4 allows a combi...
CVE-2019-19119MEDIUM5.5An issue was discovered in PRTG 7.x through 19.4.53. Due to insufficient access control on local registry keys for the C...
CVE-2019-11267Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not as...
CVE-2019-11266Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not as...
CVE-2019-11265Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not as...
CVE-2019-11264Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not as...
CVE-2019-11263Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not as...
CVE-2019-11262Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not as...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now