2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-19265MEDIUM6.1IceWarp WebMail Server 12.2.0 and 12.1.x before 12.2.1.1 (and probably earlier versions) allows XSS (issue 1 of 2) in no...
CVE-2019-19266MEDIUM5.4IceWarp WebMail Server 12.2.0 and 12.1.x before 12.2.1.1 (and probably earlier versions) allows XSS (issue 2 of 2) in no...
CVE-2019-20155HIGH8.8An issue was discovered in report_edit.jsp in Determine (formerly Selectica) Contract Lifecycle Management (CLM) v5.4. A...
CVE-2019-20154MEDIUM6.1An issue was discovered in Determine (formerly Selectica) Contract Lifecycle Management (CLM) v5.4. A cross-site scripti...
CVE-2019-20153MEDIUM4.9An issue was discovered in Determine (formerly Selectica) Contract Lifecycle Management (CLM) in v5.4. An XML external e...
CVE-2019-20077MEDIUM4.3The Typesetter CMS 5.1 logout functionality is affected by a CSRF vulnerability. The logout function of the admin panel ...
CVE-2019-20004HIGH8.8An issue was discovered on Intelbras IWR 3000N 1.8.7 devices. When the administrator password is changed from a certain ...
CVE-2019-20337HIGH7.2In PHP Scripts Mall advanced-real-estate-script 4.0.9, the news_edit.php news_id parameter is vulnerable to SQL Injectio...
CVE-2019-20336MEDIUM6.1In PHP Scripts Mall advanced-real-estate-script 4.0.9, the search-results.php searchtext parameter is vulnerable to XSS.
CVE-2019-19911HIGH7.5There is a DoS vulnerability in Pillow before 6.2.2 caused by FpxImagePlugin.py calling the range function on an unvalid...
CVE-2019-19629HIGH7.5In GitLab EE 10.5 through 12.5.3, 12.4.5, and 12.3.8, when transferring a public project to a private group, private cod...
CVE-2019-19628CRITICAL9.8In GitLab EE 11.3 through 12.5.3, 12.4.5, and 12.3.8, insufficient parameter sanitization for the Maven package registry...
CVE-2019-19314HIGH7.5GitLab EE 8.4 through 12.5, 12.4.3, and 12.3.6 stored several tokens in plaintext.
CVE-2019-19313HIGH7.5GitLab EE 12.3 through 12.5, 12.4.3, and 12.3.6 allows Denial of Service. Certain characters were making it impossible t...
CVE-2019-19312MEDIUM5.8GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 has Incorrect Access Control. After a project changed to private, previo...
CVE-2019-20334MEDIUM5.5In Netwide Assembler (NASM) 2.14.02, stack consumption occurs in expr# functions in asm/eval.c. This potentially affects...
CVE-2019-5846MEDIUM6.5Out of bounds access in SwiftShader in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially expl...
CVE-2019-5845MEDIUM6.5Out of bounds access in SwiftShader in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially expl...
CVE-2019-5844MEDIUM6.5Out of bounds access in SwiftShader in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially expl...
CVE-2019-3768MEDIUM6.5RSA Authentication Manager versions prior to 8.4 P7 contain an XML Entity Injection Vulnerability. A remote authenticate...
CVE-2019-13766MEDIUM6.5Use-after-free in accessibility in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially exploit ...
CVE-2019-13765MEDIUM6.5Use-after-free in content delivery manager in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to potential...
CVE-2019-9542MEDIUM6.1: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in itemlookup.asp o...
CVE-2019-9541MEDIUM6.1: Information Exposure vulnerability in itemlookup.asp of Telos Automated Message Handling System allows a remote attack...
CVE-2019-9540MEDIUM6.1: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in prefs.asp of Tel...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now