2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-14364MEDIUM6.1An XSS vulnerability in the "Email Subscribers & Newsletters" plugin 4.1.6 for WordPress allows an attacker to inject ma...
CVE-2019-14315MEDIUM6.1A cross-site scripting (XSS) vulnerability in upload.php in SunHater KCFinder 3.20-test1, 3.20-test2, 3.12, and earlier ...
CVE-2019-6002MEDIUM6.1Cross-site scripting vulnerability in Central Dogma 0.17.0 to 0.40.1 allows remote attackers to inject arbitrary web scr...
CVE-2019-13387MEDIUM6.1In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.846, Reflected XSS in filemanager2.php (parameter fm_current_dir...
CVE-2019-13385MEDIUM4.3In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.840, File and Directory Information Exposure in filemanager allo...
CVE-2019-13057MEDIUM4.9An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (databas...
CVE-2019-14275MEDIUM5.5Xfig fig2dev 3.2.7a has a stack-based buffer overflow in the calc_arrow function in bound.c.
CVE-2019-14274MEDIUM5.5MCPP 2.7.2 has a heap-based buffer overflow in the do_msg() function in support.c.
CVE-2019-5605MEDIUM6.5In FreeBSD 11.3-STABLE before r350217, 11.3-RELEASE before 11.3-RELEASE-p1, and 11.2-RELEASE before 11.2-RELEASE-p12, du...
CVE-2019-10974MEDIUM5.5NREL EnergyPlus, Versions 8.6.0 and possibly prior versions, The application fails to prevent an exception handler from ...
CVE-2019-10972MEDIUM5.5Mitsubishi Electric FR Configurator2, Version 1.16S and prior. This vulnerability can be triggered when an attacker prov...
CVE-2019-3621MEDIUM6.8Authentication protection bypass vulnerability in McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3.0 al...
CVE-2019-4439MEDIUM5.3IBM Cloud Private 3.1.0, 3.1.1, and 3.1.2 does not invalidate session after logout which could allow a local user to imp...
CVE-2019-4116MEDIUM5.5IBM Cloud Private 2.1.0, 3.1.0, and 3.1.1 could disclose highly sensitive information in installer logs that could be us...
CVE-2019-3486MEDIUM4.6Mitigates a stored cross site scripting issue in ArcSight Security Management Center versions prior to 2.9.1
CVE-2019-3485MEDIUM4.6Mitigates a stored cross site scripting issue in ArcSight Logger versions prior to 6.7.1
CVE-2019-3595MEDIUM6.5Improper Neutralization of Special Elements used in a Command ('Command Injection') in ePO extension in McAfee Data Loss...
CVE-2019-10968MEDIUM4.4Philips Holter 2010 Plus, all versions. A vulnerability has been identified that may allow system options that were not ...
CVE-2019-14250MEDIUM5.5An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32. simple_object_elf_match in simple-object-...
CVE-2019-2879MEDIUM4.9Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected...
CVE-2019-2877MEDIUM5.5Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions th...
CVE-2019-2863MEDIUM6.5Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions th...
CVE-2019-2853MEDIUM6.3Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filter...
CVE-2019-2848MEDIUM6.5Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions th...
CVE-2019-2834MEDIUM6.5Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that a...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now