2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-4384MEDIUM4.3IBM Campaign 9.1.2 and 10.1 could allow a remote attacker to traverse directories on the system. An attacker could send ...
CVE-2019-4303MEDIUM5.4IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrar...
CVE-2019-12814MEDIUM5.9A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x through 2.9.9. When Default Typing is enable...
CVE-2019-11478MEDIUM5.3Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment in the Linux kernel could be...
CVE-2019-11038MEDIUM5.3When using the gdImageCreateFromXbm() function in the GD Graphics Library (aka LibGD) 2.2.5, as used in the PHP GD exten...
CVE-2019-7588MEDIUM6.7A vulnerability in the exacqVision Enterprise System Manager (ESM) v5.12.2 application whereby unauthorized privilege es...
CVE-2019-12823MEDIUM6.1Craft CMS before 3.1.31 does not properly filter XML feeds and thus allowing XSS.
CVE-2019-5017MEDIUM5.3An exploitable information disclosure vulnerability exists in the KCodes NetUSB.ko kernel module that enables the ReadyS...
CVE-2019-12248MEDIUM4.3An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.7, Community Edition 6.0.x through 6.0.19...
CVE-2019-12497MEDIUM5.3An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.8, Community Edition 6.0.x through 6.0.19...
CVE-2019-4176MEDIUM5.3IBM Cognos Controller 10.2.0, 10.2.1, 10.3.0, 10.3.1, and 10.4.0 could allow a remote attacker to bypass security restri...
CVE-2019-4173MEDIUM6.5IBM Cognos Controller 10.2.0, 10.2.1, 10.3.0, 10.3.1, and 10.4.0 could allow a remote attacker to obtain sensitive infor...
CVE-2019-4136MEDIUM5.4IBM Cognos Controller 10.2.0, 10.2.1, 10.3.0, 10.3.1, and 10.4.0 is vulnerable to cross-site scripting. This vulnerabili...
CVE-2019-4403MEDIUM5.4IBM Connections 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript...
CVE-2019-4381MEDIUM5.5IBM i 7.27.3 Clustering could allow a local attacker to obtain sensitive information, caused by the use of advanced node...
CVE-2019-4239MEDIUM5.5IBM MQ Advanced Cloud Pak (IBM Cloud Private 1.0.0 through 3.0.1) stores user credentials in plain in clear text which c...
CVE-2019-10159MEDIUM4.3cfme-gemset versions 5.10.4.3 and below, 5.9.9.3 and below are vulnerable to a data leak, due to an improper authorizati...
CVE-2019-10962MEDIUM5.3BD Alaris Gateway versions, 1.0.13,1.1.3 Build 10,1.1.3 MR Build 11,1.1.5, and 1.1.6, The web browser user interface on ...
CVE-2019-11092MEDIUM4.4Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially...
CVE-2019-0181MEDIUM6.7Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially...
CVE-2019-0180MEDIUM4.4Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially...
CVE-2019-0179MEDIUM4.4Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially...
CVE-2019-0177MEDIUM4.4Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially...
CVE-2019-0175MEDIUM4.4Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially...
CVE-2019-11269MEDIUM5.4Spring Security OAuth versions 2.3 prior to 2.3.6, 2.2 prior to 2.2.5, 2.1 prior to 2.1.5, and 2.0 prior to 2.0.18, as w...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now