2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-1693 | MEDIUM | 6.5 | 2.1% | May 3, 2019 | A vulnerability in the WebVPN service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Def... |
| CVE-2019-1692 | MEDIUM | 5.3 | 1.2% | May 3, 2019 | A vulnerability in the web-based management interface of Cisco Application Policy Infrastructure Controller (APIC) Softw... |
| CVE-2019-1589 | MEDIUM | 4.6 | 0.1% | May 3, 2019 | A vulnerability in the Trusted Platform Module (TPM) functionality of software for Cisco Nexus 9000 Series Fabric Switch... |
| CVE-2019-1587 | MEDIUM | 4.3 | 1.2% | May 3, 2019 | A vulnerability in Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow ... |
| CVE-2019-1586 | MEDIUM | 4.6 | 0.2% | May 3, 2019 | A vulnerability in Cisco Application Policy Infrastructure Controller (APIC) Software could allow an unauthenticated, lo... |
| CVE-2019-6562 | MEDIUM | 5.4 | 0.7% | May 1, 2019 | In Philips Tasy EMR, Tasy EMR Versions 3.02.1744 and prior, the software incorrectly neutralizes user-controllable input... |
| CVE-2019-4258 | MEDIUM | 5.4 | 1.0% | May 1, 2019 | IBM Sterling B2B Integrator 6.0.0.0 and 6.0.0.1 Standard Edition is vulnerable to cross-site scripting. This vulnerabili... |
| CVE-2019-3934 | MEDIUM | 5.3 | 7.7% | Apr 30, 2019 | Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 allows anyone to bypass the presentation code sen... |
| CVE-2019-3933 | MEDIUM | 5.3 | 5.9% | Apr 30, 2019 | Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 allows anyone to bypass the presentation code sim... |
| CVE-2019-3928 | MEDIUM | 5.3 | 1.8% | Apr 30, 2019 | Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 allow any user to obtain the presentation passcod... |
| CVE-2019-11193 | MEDIUM | 6.1 | 2.1% | Apr 30, 2019 | The FileManager in InfinitumIT DirectAdmin through v1.561 has XSS via CMD_FILE_MANAGER, CMD_SHOW_USER, and CMD_SHOW_RESE... |
| CVE-2019-4166 | MEDIUM | 6.1 | 1.5% | Apr 30, 2019 | IBM StoredIQ 7.6 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading... |
| CVE-2019-10312 | MEDIUM | 4.3 | 1.4% | Apr 30, 2019 | A missing permission check in Jenkins Ansible Tower Plugin 0.9.1 and earlier in the TowerInstallation.TowerInstallationD... |
| CVE-2019-10308 | MEDIUM | 6.5 | 1.5% | Apr 30, 2019 | A missing permission check in Jenkins Static Analysis Utilities Plugin 1.95 and earlier in the DefaultGraphConfiguration... |
| CVE-2019-4047 | MEDIUM | 4.3 | 1.5% | Apr 29, 2019 | IBM Jazz Reporting Service (JRS) 6.0.6 could allow an authenticated user to access the execution log files as a guest us... |
| CVE-2019-11579 | MEDIUM | 5.3 | 1.4% | Apr 28, 2019 | dhcp.c in dhcpcd before 7.2.1 contains a 1-byte read overflow with DHO_OPTSOVERLOADED. |
| CVE-2019-11578 | MEDIUM | 5.9 | 2.0% | Apr 28, 2019 | auth.c in dhcpcd before 7.2.1 allowed attackers to infer secrets by performing latency attacks. |
| CVE-2019-11543 | MEDIUM | 6.1 | 3.1% | Apr 26, 2019 | XSS exists in the admin web console in Pulse Secure Pulse Connect Secure (PCS) 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.... |
| CVE-2019-3720 | MEDIUM | 4.9 | 3.5% | Apr 25, 2019 | Dell EMC Open Manage System Administrator (OMSA) versions prior to 9.3.0 contain a Directory Traversal Vulnerability. A ... |
| CVE-2019-11537 | MEDIUM | 6.1 | 4.6% | Apr 25, 2019 | In osTicket before 1.12, XSS exists via /upload/file.php, /upload/scp/users.php?do=import-users, and /upload/scp/ajax.ph... |
| CVE-2019-10955 | MEDIUM | 6.1 | 3.0% | Apr 25, 2019 | In Rockwell Automation MicroLogix 1400 Controllers Series A, All Versions Series B, v15.002 and earlier, MicroLogix 1100... |
| CVE-2019-9901 | MEDIUM | 6.5 | 2.7% | Apr 25, 2019 | Envoy 1.9.0 and before does not normalize HTTP URL paths. A remote attacker may craft a relative path, e.g., something/.... |
| CVE-2019-4238 | MEDIUM | 5.4 | 0.7% | Apr 25, 2019 | IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site scripting. This vulnerability allows ... |
| CVE-2019-4222 | MEDIUM | 4.3 | 1.2% | Apr 25, 2019 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 and 6.0.0.1 could allow an authenticated user to view process defin... |
| CVE-2019-4148 | MEDIUM | 5.4 | 0.6% | Apr 25, 2019 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 and 6.0.0.1 is vulnerable to cross-site scripting. This vulnerabili... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now