2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-11841MEDIUM5.9A message-forgery issue was discovered in crypto/openpgp/clearsign/clearsign.go in supplementary Go cryptography librari...
CVE-2019-9892MEDIUM6.5An issue was discovered in Open Ticket Request System (OTRS) 5.x through 5.0.34, 6.x through 6.0.17, and 7.x through 7.0...
CVE-2019-10067MEDIUM5.4An issue was discovered in Open Ticket Request System (OTRS) 7.x through 7.0.6 and Community Edition 5.0.x through 5.0.3...
CVE-2019-12252MEDIUM6.5In Zoho ManageEngine ServiceDesk Plus through 10.5, users with the lowest privileges (guest) can view an arbitrary post ...
CVE-2019-10319MEDIUM4.3A missing permission check in Jenkins PAM Authentication Plugin 1.5 and earlier, except 1.4.1 in PamSecurityRealm.Descri...
CVE-2019-4293MEDIUM5.3IBM Storwize V7000 Unified (2073) 1.6 configuration may allow an attacker to reveal the server version in default instal...
CVE-2019-4058MEDIUM6.5IBM BigFix Platform 9.2 and 9.5 could allow a low-privilege user to manipulate the UI into exposing interface elements a...
CVE-2019-4011MEDIUM5.4IBM BigFix Platform 9.2 and 9.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrar...
CVE-2019-12221MEDIUM6.5An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image...
CVE-2019-12216MEDIUM6.5An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image...
CVE-2019-12213MEDIUM6.5When FreeImage 3.18.0 reads a special TIFF file, the TIFFReadDirectory function in PluginTIFF.cpp always returns 1, lead...
CVE-2019-12163MEDIUM5.3GAT-Ship Web Module through 1.30 allows remote attackers to obtain potentially sensitive information via {} in a ws/gats...
CVE-2019-4119MEDIUM5.3IBM Cloud Private Kubernetes API server 2.1.0, 3.1.0, 3.1.1, and 3.1.2 can be used as an HTTP proxy to not only cluster ...
CVE-2019-0094MEDIUM4.3Insufficient input validation vulnerability in subsystem for Intel(R) AMT before versions 11.8.65, 11.11.65, 11.22.65, 1...
CVE-2019-0092MEDIUM6.8Insufficient input validation vulnerability in subsystem for Intel(R) AMT before versions 11.8.65, 11.11.65, 11.22.65, 1...
CVE-2019-10909MEDIUM5.4In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, validation ...
CVE-2019-0976MEDIUM5.5A tampering vulnerability exists in the NuGet Package Manager for Linux and Mac that could allow an authenticated attack...
CVE-2019-0963MEDIUM5.4A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a speciall...
CVE-2019-1780MEDIUM6.7A vulnerability in the CLI of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker ...
CVE-2019-1860MEDIUM5.9A vulnerability in the dashboard gadget rendering of Cisco Unified Intelligence Center could allow an unauthenticated, r...
CVE-2019-1853MEDIUM4.8A vulnerability in the HostScan component of Cisco AnyConnect Secure Mobility Client for Linux could allow an unauthenti...
CVE-2019-1851MEDIUM6.8A vulnerability in the External RESTful Services (ERS) API of the Cisco Identity Services Engine (ISE) could allow an au...
CVE-2019-1833MEDIUM5.8A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) protocol parser of Cisco Firepower Thre...
CVE-2019-1832MEDIUM5.8A vulnerability in the detection engine of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated,...
CVE-2019-1768MEDIUM6.7A vulnerability in the implementation of a specific CLI command for Cisco NX-OS Software could allow an authenticated, l...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now