2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-25013 | MEDIUM | 5.9 | 3.5% | Jan 4, 2021 | The iconv feature in the GNU C Library (aka glibc or libc6) through 2.32, when processing invalid multi-byte input seque... |
| CVE-2019-16960 | MEDIUM | 5.4 | 1.3% | Jan 4, 2021 | SolarWinds Web Help Desk 12.7.0 allows XSS via a CSV template file with a crafted Location Name field. |
| CVE-2019-16956 | MEDIUM | 5.4 | 1.7% | Jan 4, 2021 | SolarWinds Web Help Desk 12.7.0 allows XSS via the Request Type parameter of a ticket. |
| CVE-2019-25011 | MEDIUM | 5.4 | 0.6% | Dec 31, 2020 | NetBox through 2.6.2 allows an Authenticated User to conduct an XSS attack against an admin via a GFM-rendered field, as... |
| CVE-2019-20808 | MEDIUM | 6.5 | 0.3% | Dec 31, 2020 | In QEMU 4.1.0, an out-of-bounds read flaw was found in the ATI VGA implementation. It occurs in the ati_cursor_define() ... |
| CVE-2019-15523 | MEDIUM | 5.3 | 1.3% | Dec 30, 2020 | An issue was discovered in LINBIT csync2 through 2.0. It does not correctly check for the return value GNUTLS_E_WARNING_... |
| CVE-2019-12953 | MEDIUM | 5.3 | 1.2% | Dec 30, 2020 | Dropbear 2011.54 through 2018.76 has an inconsistent failure delay that may lead to revealing valid usernames, a differe... |
| CVE-2019-11786 | MEDIUM | 4.3 | 0.7% | Dec 22, 2020 | Improper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier, allows remote authentic... |
| CVE-2019-11785 | MEDIUM | 4.3 | 1.5% | Dec 22, 2020 | Improper access control in mail module (followers) in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earli... |
| CVE-2019-11784 | MEDIUM | 6.5 | 1.0% | Dec 22, 2020 | Improper access control in mail module (notifications) in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and e... |
| CVE-2019-11783 | MEDIUM | 6.5 | 1.0% | Dec 22, 2020 | Improper access control in mail module (channel partners) in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 an... |
| CVE-2019-11782 | MEDIUM | 6.5 | 1.4% | Dec 22, 2020 | Improper access control in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote authentic... |
| CVE-2019-16959 | MEDIUM | 6.5 | 1.6% | Dec 21, 2020 | SolarWinds Web Help Desk 12.7.0 allows CSV Injection, also known as Formula Injection, via a file attached to a ticket. |
| CVE-2019-16957 | MEDIUM | 5.4 | 1.5% | Dec 18, 2020 | SolarWinds Web Help Desk 12.7.0 allows XSS via the First Name field of a User Account. |
| CVE-2019-16955 | MEDIUM | 5.4 | 1.7% | Dec 18, 2020 | SolarWinds Web Help Desk 12.7.0 allows XSS via an uploaded SVG document in a request. |
| CVE-2019-14481 | MEDIUM | 5.4 | 0.4% | Dec 16, 2020 | AdRem NetCrunch 10.6.0.4587 has a Cross-Site Request Forgery (CSRF) vulnerability in the NetCrunch web client. Successfu... |
| CVE-2019-14478 | MEDIUM | 5.4 | 0.6% | Dec 16, 2020 | AdRem NetCrunch 10.6.0.4587 has a stored Cross-Site Scripting (XSS) vulnerability in the NetCrunch web client. The user'... |
| CVE-2019-14476 | MEDIUM | 6.5 | 0.8% | Dec 16, 2020 | AdRem NetCrunch 10.6.0.4587 has a Server-Side Request Forgery (SSRF) vulnerability in the NetCrunch server. Every user c... |
| CVE-2019-14477 | MEDIUM | 5.5 | 0.3% | Dec 16, 2020 | AdRem NetCrunch 10.6.0.4587 has Improper Credential Storage since the internal user database is readable by low-privileg... |
| CVE-2019-19288 | MEDIUM | 6.1 | 0.6% | Dec 14, 2020 | A vulnerability has been identified in XHQ (All Versions < 6.1). The web interface could allow Cross-Site Scripting (XSS... |
| CVE-2019-19287 | MEDIUM | 6.5 | 1.2% | Dec 14, 2020 | A vulnerability has been identified in XHQ (All Versions < 6.1). The web interface could allow attackers to traverse thr... |
| CVE-2019-19285 | MEDIUM | 5.4 | 0.5% | Dec 14, 2020 | A vulnerability has been identified in XHQ (All Versions < 6.1). The web interface could allow injections that could lea... |
| CVE-2019-19284 | MEDIUM | 5.4 | 0.5% | Dec 14, 2020 | A vulnerability has been identified in XHQ (All Versions < 6.1). The web interface could allow Cross-Site Scripting (XSS... |
| CVE-2019-19283 | MEDIUM | 5.3 | 0.9% | Dec 14, 2020 | A vulnerability has been identified in XHQ (All Versions < 6.1). The application's web server could expose non-sensitive... |
| CVE-2019-4738 | MEDIUM | 6.5 | 0.5% | Dec 10, 2020 | IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 and 6.0.0.0 through 6.0.3.1 discloses sensitive inf... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now