2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-4384 | MEDIUM | 4.3 | 2.3% | Jun 19, 2019 | IBM Campaign 9.1.2 and 10.1 could allow a remote attacker to traverse directories on the system. An attacker could send ... |
| CVE-2019-4303 | MEDIUM | 5.4 | 1.0% | Jun 19, 2019 | IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrar... |
| CVE-2019-12814 | MEDIUM | 5.9 | 11.0% | Jun 19, 2019 | A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x through 2.9.9. When Default Typing is enable... |
| CVE-2019-11478 | MEDIUM | 5.3 | 94.7% | Jun 19, 2019 | Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment in the Linux kernel could be... |
| CVE-2019-11038 | MEDIUM | 5.3 | 4.3% | Jun 19, 2019 | When using the gdImageCreateFromXbm() function in the GD Graphics Library (aka LibGD) 2.2.5, as used in the PHP GD exten... |
| CVE-2019-7588 | MEDIUM | 6.7 | 0.7% | Jun 18, 2019 | A vulnerability in the exacqVision Enterprise System Manager (ESM) v5.12.2 application whereby unauthorized privilege es... |
| CVE-2019-12823 | MEDIUM | 6.1 | 0.9% | Jun 18, 2019 | Craft CMS before 3.1.31 does not properly filter XML feeds and thus allowing XSS. |
| CVE-2019-5017 | MEDIUM | 5.3 | 2.1% | Jun 17, 2019 | An exploitable information disclosure vulnerability exists in the KCodes NetUSB.ko kernel module that enables the ReadyS... |
| CVE-2019-12248 | MEDIUM | 4.3 | 1.8% | Jun 17, 2019 | An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.7, Community Edition 6.0.x through 6.0.19... |
| CVE-2019-12497 | MEDIUM | 5.3 | 2.0% | Jun 17, 2019 | An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.8, Community Edition 6.0.x through 6.0.19... |
| CVE-2019-4176 | MEDIUM | 5.3 | 1.9% | Jun 17, 2019 | IBM Cognos Controller 10.2.0, 10.2.1, 10.3.0, 10.3.1, and 10.4.0 could allow a remote attacker to bypass security restri... |
| CVE-2019-4173 | MEDIUM | 6.5 | 1.8% | Jun 17, 2019 | IBM Cognos Controller 10.2.0, 10.2.1, 10.3.0, 10.3.1, and 10.4.0 could allow a remote attacker to obtain sensitive infor... |
| CVE-2019-4136 | MEDIUM | 5.4 | 0.7% | Jun 17, 2019 | IBM Cognos Controller 10.2.0, 10.2.1, 10.3.0, 10.3.1, and 10.4.0 is vulnerable to cross-site scripting. This vulnerabili... |
| CVE-2019-4403 | MEDIUM | 5.4 | 0.7% | Jun 14, 2019 | IBM Connections 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript... |
| CVE-2019-4381 | MEDIUM | 5.5 | 0.4% | Jun 14, 2019 | IBM i 7.27.3 Clustering could allow a local attacker to obtain sensitive information, caused by the use of advanced node... |
| CVE-2019-4239 | MEDIUM | 5.5 | 0.3% | Jun 14, 2019 | IBM MQ Advanced Cloud Pak (IBM Cloud Private 1.0.0 through 3.0.1) stores user credentials in plain in clear text which c... |
| CVE-2019-10159 | MEDIUM | 4.3 | 0.7% | Jun 14, 2019 | cfme-gemset versions 5.10.4.3 and below, 5.9.9.3 and below are vulnerable to a data leak, due to an improper authorizati... |
| CVE-2019-10962 | MEDIUM | 5.3 | 1.7% | Jun 13, 2019 | BD Alaris Gateway versions, 1.0.13,1.1.3 Build 10,1.1.3 MR Build 11,1.1.5, and 1.1.6, The web browser user interface on ... |
| CVE-2019-11092 | MEDIUM | 4.4 | 0.3% | Jun 13, 2019 | Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially... |
| CVE-2019-0181 | MEDIUM | 6.7 | 0.3% | Jun 13, 2019 | Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially... |
| CVE-2019-0180 | MEDIUM | 4.4 | 0.3% | Jun 13, 2019 | Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially... |
| CVE-2019-0179 | MEDIUM | 4.4 | 0.3% | Jun 13, 2019 | Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially... |
| CVE-2019-0177 | MEDIUM | 4.4 | 0.3% | Jun 13, 2019 | Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially... |
| CVE-2019-0175 | MEDIUM | 4.4 | 0.3% | Jun 13, 2019 | Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially... |
| CVE-2019-11269 | MEDIUM | 5.4 | 8.9% | Jun 12, 2019 | Spring Security OAuth versions 2.3 prior to 2.3.6, 2.2 prior to 2.2.5, 2.1 prior to 2.1.5, and 2.0 prior to 2.0.18, as w... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now