2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-4674 | MEDIUM | 4.9 | 1.9% | Feb 4, 2020 | IBM Security Identity Manager 7.0.1 could allow a remote attacker to traverse directories on the system. An attacker cou... |
| CVE-2019-4562 | MEDIUM | 5.3 | 1.0% | Feb 4, 2020 | IBM Security Directory Server 6.4.0 stores sensitive information in URLs. This may lead to information disclosure if una... |
| CVE-2019-4551 | MEDIUM | 5.3 | 1.3% | Feb 4, 2020 | IBM Security Directory Server 6.4.0 does not perform an authentication check for a critical resource or functionality al... |
| CVE-2019-4550 | MEDIUM | 5.3 | 1.1% | Feb 4, 2020 | IBM Security Directory Server 6.4.0 is deployed with active debugging code that can create unintended entry points. IBM ... |
| CVE-2019-4548 | MEDIUM | 6.1 | 0.9% | Feb 4, 2020 | IBM Security Directory Server 6.4.0 could allow a remote attacker to hijack the clicking action of the victim. By persua... |
| CVE-2019-4541 | HIGH | 7.2 | 1.3% | Feb 4, 2020 | IBM Security Directory Server 6.4.0 uses incomplete blacklisting for input validation which allows attackers to bypass a... |
| CVE-2019-4540 | HIGH | 7.5 | 0.8% | Feb 4, 2020 | IBM Security Directory Server 6.4.0 uses weaker than expected cryptographic algorithms that could allow an attacker to d... |
| CVE-2019-4451 | MEDIUM | 5.4 | 0.6% | Feb 4, 2020 | IBM Security Identity Manager 6.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbi... |
| CVE-2019-19273 | HIGH | 7.8 | 0.2% | Feb 4, 2020 | On Samsung mobile devices with O(8.0) and P(9.0) software and an Exynos 8895 chipset, RKP (aka the Samsung Hypervisor EL... |
| CVE-2019-9674 | HIGH | 7.5 | 5.5% | Feb 4, 2020 | Lib/zipfile.py in Python through 3.7.2 allows remote attackers to cause a denial of service (resource consumption) via a... |
| CVE-2019-19968 | MEDIUM | 5.4 | 0.8% | Feb 4, 2020 | PandoraFMS 742 suffers from multiple XSS vulnerabilities, affecting the Agent Management, Report Builder, and Graph Buil... |
| CVE-2019-9502 | HIGH | 8.8 | 2.4% | Feb 3, 2020 | The Broadcom wl WiFi driver is vulnerable to a heap buffer overflow. If the vendor information element data length is la... |
| CVE-2019-9501 | HIGH | 8.8 | 2.9% | Feb 3, 2020 | The Broadcom wl WiFi driver is vulnerable to a heap buffer overflow. By supplying a vendor information element with a da... |
| CVE-2019-20174 | MEDIUM | 6.1 | 0.7% | Feb 3, 2020 | Auth0 Lock before 11.21.0 allows XSS when additionalSignUpFields is used with an untrusted placeholder. |
| CVE-2019-18567 | MEDIUM | 6.3 | 0.5% | Feb 3, 2020 | Bromium client version 4.0.3.2060 and prior to 4.1.7 Update 1 has an out of bound read results in race condition causing... |
| CVE-2019-4732 | MEDIUM | 6.5 | 0.6% | Feb 3, 2020 | IBM SDK, Java Technology Edition Version 7.0.0.0 through 7.0.10.55, 7.1.0.0 through 7.1.4.55, and 8.0.0.0 through 8.0.6.... |
| CVE-2019-16893 | HIGH | 7.5 | 37.8% | Feb 3, 2020 | The Web Management of TP-Link TP-SG105E V4 1.0.0 Build 20181120 devices allows an unauthenticated attacker to reboot the... |
| CVE-2019-11251 | MEDIUM | 5.7 | 2.3% | Feb 3, 2020 | The Kubernetes kubectl cp command in versions 1.1-1.12, and versions prior to 1.13.11, 1.14.7, and 1.15.4 allows a combi... |
| CVE-2019-19119 | MEDIUM | 5.5 | 0.3% | Feb 3, 2020 | An issue was discovered in PRTG 7.x through 19.4.53. Due to insufficient access control on local registry keys for the C... |
| CVE-2019-11267 | — | — | — | Feb 3, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not as... |
| CVE-2019-11266 | — | — | — | Feb 3, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not as... |
| CVE-2019-11265 | — | — | — | Feb 3, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not as... |
| CVE-2019-11264 | — | — | — | Feb 3, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not as... |
| CVE-2019-11263 | — | — | — | Feb 3, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not as... |
| CVE-2019-11262 | — | — | — | Feb 3, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not as... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now