2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-0291 | — | — | 0.4% | May 14, 2019 | Under certain conditions Solution Manager, version 7.2, allows an attacker to access information which would otherwise b... |
| CVE-2019-0289 | — | — | 1.1% | May 14, 2019 | Under certain conditions SAP BusinessObjects Business Intelligence platform (Analysis for OLAP), versions 4.2 and 4.3, a... |
| CVE-2019-0287 | — | — | 1.7% | May 14, 2019 | Under certain conditions SAP BusinessObjects Business Intelligence platform (Central Management Server), versions 4.2 an... |
| CVE-2019-0280 | — | — | 1.1% | May 14, 2019 | SAP Treasury and Risk Management (EA-FINSERV 6.0, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18 and 8.0; S4CORE 1.01, 1.02 an... |
| CVE-2019-6577 | — | — | 0.9% | May 14, 2019 | A vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V15.1 Update 1), SIMATIC HMI ... |
| CVE-2019-8978 | — | — | 5.9% | May 14, 2019 | An improper authentication vulnerability can be exploited through a race condition that occurs in Ellucian Banner Web Ta... |
| CVE-2019-11846 | — | — | 1.0% | May 14, 2019 | /servlets/ajax_file_upload?fieldName=binary3 in dotCMS 5.1.1 allows XSS and HTML Injection. |
| CVE-2019-11845 | — | — | 1.0% | May 14, 2019 | An HTML Injection vulnerability has been discovered on the RICOH SP 4510DN via the /web/entry/en/address/adrsSetUserWiza... |
| CVE-2019-11844 | — | — | 1.0% | May 14, 2019 | An HTML Injection vulnerability has been discovered on the RICOH SP 4520DN via the /web/entry/en/address/adrsSetUserWiza... |
| CVE-2019-9861 | — | — | 1.6% | May 14, 2019 | Due to the use of an insecure RFID technology (MIFARE Classic), ABUS proximity chip keys (RFID tokens) of the ABUS Secve... |
| CVE-2019-8923 | — | — | 3.9% | May 14, 2019 | XAMPP through 5.6.8 and previous allows SQL injection via the cds-fpdf.php jahr parameter. NOTE: This product is discont... |
| CVE-2019-8404 | — | — | 8.0% | May 14, 2019 | An issue was discovered in Webiness Inventory 2.3. The ProductModel component allows Arbitrary File Upload via a crafted... |
| CVE-2019-8391 | — | — | 3.3% | May 14, 2019 | qdPM 9.1 suffers from Cross-site Scripting (XSS) via configuration?type=[XSS] parameter. |
| CVE-2019-8390 | — | — | 8.9% | May 14, 2019 | qdPM 9.1 suffers from Cross-site Scripting (XSS) in the search[keywords] parameter. |
| CVE-2019-6516 | — | — | 1.4% | May 14, 2019 | An issue was discovered in WSO2 Dashboard Server 2.0.0. It is possible to force the application to perform requests to t... |
| CVE-2019-6515 | — | — | 1.5% | May 14, 2019 | An issue was discovered in WSO2 API Manager 2.6.0. Uploaded documents for API documentation are available to an unauthen... |
| CVE-2019-6514 | — | — | 0.9% | May 14, 2019 | An issue was discovered in WSO2 Dashboard Server 2.0.0. It is possible to inject a JavaScript payload that will be store... |
| CVE-2019-6512 | — | — | 1.1% | May 14, 2019 | An issue was discovered in WSO2 API Manager 2.6.0. It is possible to force the application to perform requests to the in... |
| CVE-2019-11336 | — | — | 3.2% | May 14, 2019 | Sony Bravia Smart TV devices allow remote attackers to retrieve the static Wi-Fi password (used when the TV is acting as... |
| CVE-2019-12087 | — | — | 0.4% | May 14, 2019 | Samsung S9+, S10, and XCover 4 P(9.0) devices can become temporarily inoperable because of an unprotected intent in the ... |
| CVE-2019-9618 | — | — | 40.8% | May 13, 2019 | The GraceMedia Media Player plugin 1.0 for WordPress allows Local File Inclusion via the "cfg" parameter. |
| CVE-2019-8952 | — | — | 1.4% | May 13, 2019 | A Path Traversal vulnerability located in the webserver affects several Bosch hardware and software products. The vulner... |
| CVE-2019-8951 | — | — | 1.1% | May 13, 2019 | An Open Redirect vulnerability located in the webserver affects several Bosch hardware and software products. The vulner... |
| CVE-2019-10053 | — | — | 1.7% | May 13, 2019 | An issue was discovered in Suricata 4.1.x before 4.1.4. If the input of the function SSHParseBanner is composed only of ... |
| CVE-2019-11600 | — | — | 80.0% | May 13, 2019 | A SQL injection vulnerability in the activities API in OpenProject before 8.3.2 allows a remote attacker to execute arbi... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now