2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-11894 | MEDIUM | 5.7 | 0.5% | May 29, 2019 | A potential improper access control vulnerability exists in the backup mechanism of the Bosch Smart Home Controller (SHC... |
| CVE-2019-12449 | MEDIUM | 5.7 | 1.8% | May 29, 2019 | An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gvfsbackendadmin.c mishandles a file's user and grou... |
| CVE-2019-4264 | MEDIUM | 5.9 | 1.0% | May 29, 2019 | IBM QRadar SIEM 7.2.8 WinCollect could allow an attacker to obtain sensitive information by spoofing a trusted entity us... |
| CVE-2019-4184 | MEDIUM | 5.4 | 1.0% | May 29, 2019 | IBM Jazz Reporting Service 6.0 through 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to... |
| CVE-2019-4139 | MEDIUM | 5.4 | 1.0% | May 29, 2019 | IBM Cognos Analytics 11.0, 11.1.0, and 11.1.1 is vulnerable to cross-site scripting. This vulnerability allows users to ... |
| CVE-2019-4138 | MEDIUM | 5.9 | 2.1% | May 29, 2019 | IBM Tivoli Storage Productivity Center 5.2.13 through 5.3.0.1 could allow a remote attacker to obtain sensitive informat... |
| CVE-2019-4137 | MEDIUM | 6.1 | 1.3% | May 29, 2019 | IBM Tivoli Storage Productivity Center 5.2.13 through 5.3.0.1 is vulnerable to cross-site scripting. This vulnerability ... |
| CVE-2019-7393 | MEDIUM | 4.3 | 2.3% | May 28, 2019 | A UI redress vulnerability in the administrative user interface of CA Technologies CA Strong Authentication 9.0.x, 8.2.x... |
| CVE-2019-12395 | MEDIUM | 5.3 | 1.6% | May 28, 2019 | In Webbukkit Dynmap 3.0-beta-3 or below, due to a missing login check in servlet/MapStorageHandler.java, an attacker can... |
| CVE-2019-12383 | MEDIUM | 4.3 | 2.2% | May 28, 2019 | Tor Browser before 8.0.1 has an information exposure vulnerability. It allows remote attackers to detect the browser's U... |
| CVE-2019-5804 | MEDIUM | 5.5 | 0.3% | May 23, 2019 | Incorrect command line processing in Chrome in Google Chrome prior to 73.0.3683.75 allowed a local attacker to perform d... |
| CVE-2019-5803 | MEDIUM | 6.5 | 1.0% | May 23, 2019 | Insufficient policy enforcement in Content Security Policy in Google Chrome prior to 73.0.3683.75 allowed a remote attac... |
| CVE-2019-5802 | MEDIUM | 6.5 | 0.9% | May 23, 2019 | Incorrect handling of download origins in Navigation in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to... |
| CVE-2019-5801 | MEDIUM | 6.5 | 1.0% | May 23, 2019 | Incorrect eliding of URLs in Omnibox in Google Chrome on iOS prior to 73.0.3683.75 allowed a remote attacker to perform ... |
| CVE-2019-5800 | MEDIUM | 6.5 | 1.0% | May 23, 2019 | Insufficient policy enforcement in Blink in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to bypass cont... |
| CVE-2019-5799 | MEDIUM | 6.5 | 1.5% | May 23, 2019 | Incorrect inheritance of a new document's policy in Content Security Policy in Google Chrome prior to 73.0.3683.75 allow... |
| CVE-2019-5798 | MEDIUM | 6.5 | 3.2% | May 23, 2019 | Lack of correct bounds checking in Skia in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform an o... |
| CVE-2019-5794 | MEDIUM | 6.5 | 1.1% | May 23, 2019 | Incorrect handling of cancelled requests in Navigation in Google Chrome prior to 73.0.3683.75 allowed a remote attacker ... |
| CVE-2019-5793 | MEDIUM | 6.5 | 1.0% | May 23, 2019 | Insufficient policy enforcement in extensions in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to initia... |
| CVE-2019-10846 | MEDIUM | 6.1 | 4.7% | May 23, 2019 | Computrols CBAS 18.0.0 allows Unauthenticated Reflected Cross-Site Scripting vulnerabilities in the login page and passw... |
| CVE-2019-4039 | MEDIUM | 5.5 | 0.3% | May 23, 2019 | IBM WebSphere MQ 8.0.0.0 through 8.0.0.9 and 9.0.0.0 through 9.1.1 could allow a local attacker to cause a denial of ser... |
| CVE-2019-0201 | MEDIUM | 5.9 | 9.6% | May 23, 2019 | An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeeper’s getACL() command does... |
| CVE-2019-6821 | MEDIUM | 6.5 | 1.9% | May 22, 2019 | CWE-330: Use of Insufficiently Random Values vulnerability, which could cause the hijacking of the TCP connection when u... |
| CVE-2019-3403 | MEDIUM | 5.3 | 52.6% | May 22, 2019 | The /rest/api/2/user/picker rest resource in Jira before version 7.13.3, from version 8.0.0 before version 8.0.4, and fr... |
| CVE-2019-3401 | MEDIUM | 5.3 | 12.7% | May 22, 2019 | The ManageFilters.jspa resource in Jira before version 7.13.3 and from version 8.0.0 before version 8.1.1 allows remote ... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now