2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-12766 | MEDIUM | 6.1 | 0.9% | Jun 11, 2019 | An issue was discovered in Joomla! before 3.9.7. The subform fieldtype does not sufficiently filter or validate input of... |
| CVE-2019-12764 | MEDIUM | 6.5 | 1.1% | Jun 11, 2019 | An issue was discovered in Joomla! before 3.9.7. The update server URL of com_joomlaupdate can be manipulated by non Sup... |
| CVE-2019-10333 | MEDIUM | 4.3 | 1.4% | Jun 11, 2019 | Missing permission checks in Jenkins ElectricFlow Plugin 1.1.5 and earlier in various HTTP endpoints allowed users with ... |
| CVE-2019-10332 | MEDIUM | 4.3 | 1.8% | Jun 11, 2019 | A missing permission check in Jenkins ElectricFlow Plugin 1.1.5 and earlier in Configuration#doTestConnection allowed us... |
| CVE-2019-12387 | MEDIUM | 6.1 | 2.5% | Jun 10, 2019 | In Twisted before 19.2.1, twisted.web did not validate or sanitize URIs or HTTP methods, allowing an attacker to inject ... |
| CVE-2019-2101 | MEDIUM | 5.5 | 0.4% | Jun 7, 2019 | In uvc_parse_standard_control of uvc_driver.c, there is a possible out-of-bound read due to improper input validation. T... |
| CVE-2019-8283 | MEDIUM | 6.5 | 1.2% | Jun 7, 2019 | Hasplm cookie in Gemalto Admin Control Center, all versions prior to 7.92, does not have 'HttpOnly' flag. This allows ma... |
| CVE-2019-8282 | MEDIUM | 5.3 | 0.4% | Jun 7, 2019 | Gemalto Admin Control Center, all versions prior to 7.92, uses cleartext HTTP to communicate with www3.safenet-inc.com t... |
| CVE-2019-4070 | MEDIUM | 5.4 | 0.7% | Jun 7, 2019 | IBM Intelligent Operations Center (IOC) 5.1.0 through 5.2.0 is vulnerable to cross-site scripting. This vulnerability al... |
| CVE-2019-4257 | MEDIUM | 4.3 | 1.0% | Jun 6, 2019 | IBM InfoSphere Information Server 11.5 and 11.7 is affected by an information disclosure vulnerability. Sensitive inform... |
| CVE-2019-4219 | MEDIUM | 5.3 | 1.3% | Jun 6, 2019 | IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, and 1.0.2 generates an error message that includes sensitive informa... |
| CVE-2019-4217 | MEDIUM | 6.1 | 1.2% | Jun 6, 2019 | IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, and 1.0.2 could allow a remote attacker to hijack the clicking actio... |
| CVE-2019-12762 | MEDIUM | 4.2 | 0.2% | Jun 6, 2019 | Xiaomi Mi 5s Plus devices allow attackers to trigger touchscreen anomalies via a radio signal between 198 kHz and 203 kH... |
| CVE-2019-3790 | MEDIUM | 6.1 | 0.7% | Jun 6, 2019 | The Pivotal Ops Manager, 2.2.x versions prior to 2.2.23, 2.3.x versions prior to 2.3.16, 2.4.x versions prior to 2.4.11,... |
| CVE-2019-3579 | MEDIUM | 5.3 | 1.6% | Jun 6, 2019 | MyBB 1.8.19 allows remote attackers to obtain sensitive information because it discloses the username upon receiving a p... |
| CVE-2019-3578 | MEDIUM | 6.1 | 0.8% | Jun 6, 2019 | MyBB 1.8.19 has XSS in the resetpassword function. |
| CVE-2019-7553 | MEDIUM | 5.4 | 0.7% | Jun 6, 2019 | PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has Stored XSS in the Profile Update page via the My Name ... |
| CVE-2019-7552 | MEDIUM | 5.4 | 0.7% | Jun 6, 2019 | An issue was discovered in PHP Scripts Mall Investment MLM Software 2.0.2. Stored XSS was found in the the My Profile Se... |
| CVE-2019-4220 | MEDIUM | 5.5 | 0.2% | Jun 6, 2019 | IBM InfoSphere Information Server 11.7.1.0 stores a common hard coded encryption key that could be used to decrypt sensi... |
| CVE-2019-4201 | MEDIUM | 6.1 | 1.0% | Jun 6, 2019 | IBM Jazz for Service Management 1.1.3, 1.1.3.1, and 1.1.3.2 could allow a remote attacker to conduct phishing attacks, u... |
| CVE-2019-4056 | MEDIUM | 4.3 | 0.9% | Jun 6, 2019 | IBM Maximo Asset Management 7.6 Work Centers' application does not validate file type upon upload, allowing attackers to... |
| CVE-2019-1882 | MEDIUM | 5.4 | 0.9% | Jun 5, 2019 | A vulnerability in Cisco Industrial Network Director could allow an authenticated, remote attacker to conduct stored cro... |
| CVE-2019-1881 | MEDIUM | 4.7 | 1.3% | Jun 5, 2019 | A vulnerability in the web-based management interface of Cisco Industrial Network Director (IND) could allow an unauthen... |
| CVE-2019-1880 | MEDIUM | 4.4 | 0.2% | Jun 5, 2019 | A vulnerability in the BIOS upgrade utility of Cisco Unified Computing System (UCS) C-Series Rack Servers could allow an... |
| CVE-2019-1872 | MEDIUM | 5.3 | 1.5% | Jun 5, 2019 | A vulnerability in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway Series software could allow ... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now