2019 CVE Vulnerabilities

17,624 CVEs published in 2019.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2019-12943HIGH8.1TTLock devices do not properly restrict password-reset attempts, leading to incorrect access control and disclosure of s...
CVE-2019-11669HIGH7.5Modifiable read only check box In Micro Focus Service Manager, versions 9.60p1, 9.61, 9.62. This vulnerability could be ...
CVE-2019-11668HIGH7.5HTTP cookie in Micro Focus Service manager, Versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9...
CVE-2019-11497HIGH7.5In Couchbase Server 5.0.0, when an invalid Remote Cluster Certificate was entered as part of the reference creation, XDC...
CVE-2019-11467HIGH7.5In Couchbase Server 4.6.3 and 5.5.0, secondary indexing encodes the entries to be indexed using collatejson. When index ...
CVE-2019-12105HIGH8.2In Supervisor through 4.0.2, an unauthenticated user can read log files or restart a service. Note: The maintainer respo...
CVE-2019-0365HIGH7.5SAP Kernel (RFC), KRNL32NUC, KRNL32UC and KRNL64NUC before versions 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64UC, before versi...
CVE-2019-0363HIGH7.1Attackers may misuse an HTTP/REST endpoint of SAP HANA Extended Application Services (Advanced model), before version 1....
CVE-2019-0355HIGH7.2SAP NetWeaver Application Server Java Web Container, ENGINEAPI (before versions 7.10, 7.20, 7.30, 7.31, 7.40, 7.50) and ...
CVE-2019-0352HIGH7.5In SAP Business Objects Business Intelligence Platform, before versions 4.1, 4.2 and 4.3, some dynamic pages (like jsp) ...
CVE-2019-16106HIGH7.5The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to change the p...
CVE-2019-12401HIGH7.5Solr versions 1.3.0 to 1.4.1, 3.1.0 to 3.6.2 and 4.0.0 to 4.10.4 are vulnerable to an XML resource consumption attack (a...
CVE-2019-16187HIGH7.5Limesurvey before 3.17.14 uses an anti-CSRF cookie without the HttpOnly flag, which allows attackers to access a cookie ...
CVE-2019-16186HIGH7.2In Limesurvey before 3.17.14, admin users can access the plugin manager without proper permissions.
CVE-2019-16185HIGH7.2In Limesurvey before 3.17.14, admin users can view, update, or delete reserved menu entries without proper permissions.
CVE-2019-16177HIGH7.5In Limesurvey before 3.17.14, the entire database is exposed through browser caching.
CVE-2019-16174HIGH8.8An XML injection vulnerability was found in Limesurvey before 3.17.14 that allows remote attackers to import specially c...
CVE-2019-6793HIGH7An issue was discovered in GitLab Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. The ...
CVE-2019-6788HIGH7.5An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x befor...
CVE-2019-6783HIGH8.8An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x befor...
CVE-2019-6782HIGH7.5An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x befor...
CVE-2019-11605HIGH7.5An issue was discovered in GitLab Community and Enterprise Edition 11.8.x before 11.8.10, 11.9.x before 11.9.11, and 11....
CVE-2019-5473HIGH7.2An authentication issue was discovered in GitLab that allowed a bypass of email verification. This was addressed in GitL...
CVE-2019-16163HIGH7.5Oniguruma before 6.9.3 allows Stack Exhaustion in regcomp.c because of recursion in regparse.c.
CVE-2019-16162HIGH7.5Onigmo through 6.2.0 has an out-of-bounds read in parse_char_class because of missing codepoint validation in regenc.c.

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now