2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-11894MEDIUM5.7A potential improper access control vulnerability exists in the backup mechanism of the Bosch Smart Home Controller (SHC...
CVE-2019-12449MEDIUM5.7An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gvfsbackendadmin.c mishandles a file's user and grou...
CVE-2019-4264MEDIUM5.9IBM QRadar SIEM 7.2.8 WinCollect could allow an attacker to obtain sensitive information by spoofing a trusted entity us...
CVE-2019-4184MEDIUM5.4IBM Jazz Reporting Service 6.0 through 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to...
CVE-2019-4139MEDIUM5.4IBM Cognos Analytics 11.0, 11.1.0, and 11.1.1 is vulnerable to cross-site scripting. This vulnerability allows users to ...
CVE-2019-4138MEDIUM5.9IBM Tivoli Storage Productivity Center 5.2.13 through 5.3.0.1 could allow a remote attacker to obtain sensitive informat...
CVE-2019-4137MEDIUM6.1IBM Tivoli Storage Productivity Center 5.2.13 through 5.3.0.1 is vulnerable to cross-site scripting. This vulnerability ...
CVE-2019-7393MEDIUM4.3A UI redress vulnerability in the administrative user interface of CA Technologies CA Strong Authentication 9.0.x, 8.2.x...
CVE-2019-12395MEDIUM5.3In Webbukkit Dynmap 3.0-beta-3 or below, due to a missing login check in servlet/MapStorageHandler.java, an attacker can...
CVE-2019-12383MEDIUM4.3Tor Browser before 8.0.1 has an information exposure vulnerability. It allows remote attackers to detect the browser's U...
CVE-2019-5804MEDIUM5.5Incorrect command line processing in Chrome in Google Chrome prior to 73.0.3683.75 allowed a local attacker to perform d...
CVE-2019-5803MEDIUM6.5Insufficient policy enforcement in Content Security Policy in Google Chrome prior to 73.0.3683.75 allowed a remote attac...
CVE-2019-5802MEDIUM6.5Incorrect handling of download origins in Navigation in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to...
CVE-2019-5801MEDIUM6.5Incorrect eliding of URLs in Omnibox in Google Chrome on iOS prior to 73.0.3683.75 allowed a remote attacker to perform ...
CVE-2019-5800MEDIUM6.5Insufficient policy enforcement in Blink in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to bypass cont...
CVE-2019-5799MEDIUM6.5Incorrect inheritance of a new document's policy in Content Security Policy in Google Chrome prior to 73.0.3683.75 allow...
CVE-2019-5798MEDIUM6.5Lack of correct bounds checking in Skia in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform an o...
CVE-2019-5794MEDIUM6.5Incorrect handling of cancelled requests in Navigation in Google Chrome prior to 73.0.3683.75 allowed a remote attacker ...
CVE-2019-5793MEDIUM6.5Insufficient policy enforcement in extensions in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to initia...
CVE-2019-10846MEDIUM6.1Computrols CBAS 18.0.0 allows Unauthenticated Reflected Cross-Site Scripting vulnerabilities in the login page and passw...
CVE-2019-4039MEDIUM5.5IBM WebSphere MQ 8.0.0.0 through 8.0.0.9 and 9.0.0.0 through 9.1.1 could allow a local attacker to cause a denial of ser...
CVE-2019-0201MEDIUM5.9An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeeper’s getACL() command does...
CVE-2019-6821MEDIUM6.5CWE-330: Use of Insufficiently Random Values vulnerability, which could cause the hijacking of the TCP connection when u...
CVE-2019-3403MEDIUM5.3The /rest/api/2/user/picker rest resource in Jira before version 7.13.3, from version 8.0.0 before version 8.0.4, and fr...
CVE-2019-3401MEDIUM5.3The ManageFilters.jspa resource in Jira before version 7.13.3 and from version 8.0.0 before version 8.1.1 allows remote ...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now