2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-7654MEDIUM6.5Wowza Streaming Engine 4.8.0 and earlier suffers from multiple CSRF vulnerabilities. For example, an administrator, by f...
CVE-2019-20217CRITICAL9.8D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via the urn: to t...
CVE-2019-20216CRITICAL9.8D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via the urn: to t...
CVE-2019-20215CRITICAL9.8D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via a urn: to the...
CVE-2019-4707HIGH7.1IBM Security Access Manager Appliance 9.0.7.0 is vulnerable to an XML External Entity Injection (XXE) attack when proces...
CVE-2019-4679MEDIUM4.3IBM Content Navigator 3.0CD could allow an authenticated user to gain information about the hosting operating system and...
CVE-2019-4639HIGH7.5IBM Security Secret Server 10.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decry...
CVE-2019-4638LOW3.7IBM Security Secret Server 10.7 does not set the secure attribute on authorization tokens or session cookies. This could...
CVE-2019-4637MEDIUM4.3IBM Security Secret Server 10.7 uses incomplete blacklisting for input validation which allows attackers to bypass appli...
CVE-2019-4636LOW2.7IBM Security Secret Server 10.7 could disclose sensitive information to an authenticated user from generated error messa...
CVE-2019-4635LOW2.7IBM Security Secret Server 10.7 could allow a privileged user to perform unauthorized command injection due to imporoper...
CVE-2019-4633MEDIUM4.3IBM Security Secret Server 10.7 could allow an attacker to obtain sensitive information due to an overly permissive CORS...
CVE-2019-4632MEDIUM6.1IBM Security Secret Server 10.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrar...
CVE-2019-4631MEDIUM6.1IBM Security Secret Server 10.7 could allow a remote attacker to conduct phishing attacks, using an open redirect attack...
CVE-2019-4620HIGH7.8IBM MQ Appliance 8.0 and 9.0 LTS could allow a local attacker to bypass security restrictions caused by improper validat...
CVE-2019-4614MEDIUM6.5IBM MQ and IBM MQ Appliance 8.0 and 9.0 LTS client connecting to a Queue Manager could cause a SIGSEGV denial of service...
CVE-2019-4568MEDIUM5.9IBM MQ and IBM MQ Appliance 8.0 and 9.0 LTS could allow a remote attacker with intimate knowledge of the server to cause...
CVE-2019-17338MEDIUM5.4The user interface component of TIBCO Software Inc.'s TIBCO Patterns - Search contains multiple vulnerabilities that the...
CVE-2019-5474MEDIUM6.5An authorization issue was discovered in GitLab EE < 12.1.2, < 12.0.4, and < 11.11.6 allowing the merge request approval...
CVE-2019-5472HIGH7.5An authorization issue was discovered in Gitlab versions < 12.1.2, < 12.0.4, and < 11.11.6 that prevented owners and mai...
CVE-2019-5470HIGH7.5An information disclosure issue was discovered GitLab versions < 12.1.2, < 12.0.4, and < 11.11.6 in the security dashboa...
CVE-2019-5468HIGH8.8An privilege escalation issue was discovered in Gitlab versions < 12.1.2, < 12.0.4, and < 11.11.6 when Mattermost slash ...
CVE-2019-5466MEDIUM4.3An IDOR was discovered in GitLab CE/EE 11.5 and later that allowed new merge requests endpoint to disclose label names.
CVE-2019-5465MEDIUM4.3An information disclosure issue was discovered in GitLab CE/EE 8.14 and later, by using the move issue feature which cou...
CVE-2019-5464CRITICAL9.8A flawed DNS rebinding protection issue was discovered in GitLab CE/EE 10.2 and later in the `url_blocker.rb` which coul...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now