2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-7654 | MEDIUM | 6.5 | 0.9% | Jan 29, 2020 | Wowza Streaming Engine 4.8.0 and earlier suffers from multiple CSRF vulnerabilities. For example, an administrator, by f... |
| CVE-2019-20217 | CRITICAL | 9.8 | 3.6% | Jan 29, 2020 | D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via the urn: to t... |
| CVE-2019-20216 | CRITICAL | 9.8 | 3.7% | Jan 29, 2020 | D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via the urn: to t... |
| CVE-2019-20215 | CRITICAL | 9.8 | 75.1% | Jan 29, 2020 | D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via a urn: to the... |
| CVE-2019-4707 | HIGH | 7.1 | 1.4% | Jan 28, 2020 | IBM Security Access Manager Appliance 9.0.7.0 is vulnerable to an XML External Entity Injection (XXE) attack when proces... |
| CVE-2019-4679 | MEDIUM | 4.3 | 0.8% | Jan 28, 2020 | IBM Content Navigator 3.0CD could allow an authenticated user to gain information about the hosting operating system and... |
| CVE-2019-4639 | HIGH | 7.5 | 0.8% | Jan 28, 2020 | IBM Security Secret Server 10.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decry... |
| CVE-2019-4638 | LOW | 3.7 | 0.8% | Jan 28, 2020 | IBM Security Secret Server 10.7 does not set the secure attribute on authorization tokens or session cookies. This could... |
| CVE-2019-4637 | MEDIUM | 4.3 | 0.7% | Jan 28, 2020 | IBM Security Secret Server 10.7 uses incomplete blacklisting for input validation which allows attackers to bypass appli... |
| CVE-2019-4636 | LOW | 2.7 | 0.8% | Jan 28, 2020 | IBM Security Secret Server 10.7 could disclose sensitive information to an authenticated user from generated error messa... |
| CVE-2019-4635 | LOW | 2.7 | 0.9% | Jan 28, 2020 | IBM Security Secret Server 10.7 could allow a privileged user to perform unauthorized command injection due to imporoper... |
| CVE-2019-4633 | MEDIUM | 4.3 | 0.9% | Jan 28, 2020 | IBM Security Secret Server 10.7 could allow an attacker to obtain sensitive information due to an overly permissive CORS... |
| CVE-2019-4632 | MEDIUM | 6.1 | 0.7% | Jan 28, 2020 | IBM Security Secret Server 10.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrar... |
| CVE-2019-4631 | MEDIUM | 6.1 | 0.8% | Jan 28, 2020 | IBM Security Secret Server 10.7 could allow a remote attacker to conduct phishing attacks, using an open redirect attack... |
| CVE-2019-4620 | HIGH | 7.8 | 0.4% | Jan 28, 2020 | IBM MQ Appliance 8.0 and 9.0 LTS could allow a local attacker to bypass security restrictions caused by improper validat... |
| CVE-2019-4614 | MEDIUM | 6.5 | 1.5% | Jan 28, 2020 | IBM MQ and IBM MQ Appliance 8.0 and 9.0 LTS client connecting to a Queue Manager could cause a SIGSEGV denial of service... |
| CVE-2019-4568 | MEDIUM | 5.9 | 1.3% | Jan 28, 2020 | IBM MQ and IBM MQ Appliance 8.0 and 9.0 LTS could allow a remote attacker with intimate knowledge of the server to cause... |
| CVE-2019-17338 | MEDIUM | 5.4 | 0.6% | Jan 28, 2020 | The user interface component of TIBCO Software Inc.'s TIBCO Patterns - Search contains multiple vulnerabilities that the... |
| CVE-2019-5474 | MEDIUM | 6.5 | 1.1% | Jan 28, 2020 | An authorization issue was discovered in GitLab EE < 12.1.2, < 12.0.4, and < 11.11.6 allowing the merge request approval... |
| CVE-2019-5472 | HIGH | 7.5 | 1.9% | Jan 28, 2020 | An authorization issue was discovered in Gitlab versions < 12.1.2, < 12.0.4, and < 11.11.6 that prevented owners and mai... |
| CVE-2019-5470 | HIGH | 7.5 | 1.6% | Jan 28, 2020 | An information disclosure issue was discovered GitLab versions < 12.1.2, < 12.0.4, and < 11.11.6 in the security dashboa... |
| CVE-2019-5468 | HIGH | 8.8 | 2.1% | Jan 28, 2020 | An privilege escalation issue was discovered in Gitlab versions < 12.1.2, < 12.0.4, and < 11.11.6 when Mattermost slash ... |
| CVE-2019-5466 | MEDIUM | 4.3 | 1.0% | Jan 28, 2020 | An IDOR was discovered in GitLab CE/EE 11.5 and later that allowed new merge requests endpoint to disclose label names. |
| CVE-2019-5465 | MEDIUM | 4.3 | 1.1% | Jan 28, 2020 | An information disclosure issue was discovered in GitLab CE/EE 8.14 and later, by using the move issue feature which cou... |
| CVE-2019-5464 | CRITICAL | 9.8 | 2.8% | Jan 28, 2020 | A flawed DNS rebinding protection issue was discovered in GitLab CE/EE 10.2 and later in the `url_blocker.rb` which coul... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now