2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-4579 | MEDIUM | 4.3 | 0.7% | Aug 28, 2020 | IBM Resilient SOAR 38 uses incomplete blacklisting for input validation which allows attackers to bypass application con... |
| CVE-2019-4533 | MEDIUM | 4.3 | 1.0% | Aug 28, 2020 | IBM Resilient SOAR V38.0 users may experience a denial of service of the SOAR Platform due to a insufficient input valid... |
| CVE-2019-19499 | MEDIUM | 6.5 | 3.6% | Aug 28, 2020 | Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could be exploited by an authenticated attacker that ha... |
| CVE-2019-5320 | MEDIUM | 6.1 | 0.8% | Aug 26, 2020 | Aruba Intelligent Edge Switch Series 2540, 2530, 2930F, 2930M, 2920, 5400R, and 3810M with firmware 16.08.* before 16.08... |
| CVE-2019-4701 | MEDIUM | 5.3 | 0.7% | Aug 26, 2020 | IBM Security Guardium Data Encryption (GDE) 3.0.0.2 is deployed with active debugging code that can create unintended en... |
| CVE-2019-4697 | MEDIUM | 6.5 | 0.5% | Aug 26, 2020 | IBM Security Guardium Data Encryption (GDE) 3.0.0.2 stores user credentials in plain in clear text which can be read by ... |
| CVE-2019-4693 | MEDIUM | 4.4 | 0.2% | Aug 26, 2020 | IBM Security Guardium Data Encryption (GDE) 3.0.0.2 stores user credentials in plain in clear text which can be read by ... |
| CVE-2019-4692 | MEDIUM | 5.3 | 0.7% | Aug 26, 2020 | IBM Security Guardium Data Encryption (GDE) 3.0.0.2 discloses sensitive information to unauthorized users. The informati... |
| CVE-2019-4691 | MEDIUM | 5.4 | 0.4% | Aug 26, 2020 | IBM Security Guardium Data Encryption (GDE) 3.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows use... |
| CVE-2019-4688 | MEDIUM | 4.3 | 0.6% | Aug 26, 2020 | IBM Security Guardium Data Encryption (GDE) 3.0.0.2 does not set the secure attribute on authorization tokens or session... |
| CVE-2019-4686 | MEDIUM | 5.3 | 0.4% | Aug 26, 2020 | IBM Security Guardium Data Encryption (GDE) 3.0.0.2 does not set the secure attribute on authorization tokens or session... |
| CVE-2019-11857 | MEDIUM | 4.9 | 2.1% | Aug 21, 2020 | Lack of input sanitization in AceManager of ALEOS before 4.12.0, 4.9.5 and 4.4.9 allows disclosure of sensitive system i... |
| CVE-2019-11850 | MEDIUM | 6.7 | 0.4% | Aug 21, 2020 | A stack overflow vulnerabiltity exist in the AT command interface of ALEOS before 4.11.0. The vulnerability may allow co... |
| CVE-2019-11849 | MEDIUM | 6.7 | 0.4% | Aug 21, 2020 | A stack overflow vulnerabiltity exists in the AT command APIs of ALEOS before 4.11.0. The vulnerability may allow code e... |
| CVE-2019-20152 | MEDIUM | 6.1 | 0.7% | Aug 20, 2020 | An XSS issue was discovered in TreasuryXpress 19191105. Due to the lack of filtering and sanitization of user input, mal... |
| CVE-2019-20151 | MEDIUM | 6.1 | 0.7% | Aug 20, 2020 | An XSS issue was discovered in TreasuryXpress 19191105. Due to the lack of filtering and sanitization of user input, mal... |
| CVE-2019-20150 | MEDIUM | 6.5 | 0.9% | Aug 20, 2020 | In TreasuryXpress 19191105, a logged-in user can discover saved credentials, even though the UI hides them. Using functi... |
| CVE-2019-5591 | MEDIUM | 6.5 | 18.6% | Aug 14, 2020 | A Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept s... |
| CVE-2019-7410 | MEDIUM | 6.1 | 1.2% | Aug 14, 2020 | There is stored cross site scripting (XSS) in Galileo CMS v0.042. Remote authenticated users could inject arbitrary web ... |
| CVE-2019-6112 | MEDIUM | 6.1 | 8.9% | Aug 14, 2020 | A Cross-site scripting (XSS) vulnerability in /inc/class-search.php in the Sell Media plugin v2.4.1 for WordPress allows... |
| CVE-2019-4582 | MEDIUM | 4.3 | 1.4% | Aug 13, 2020 | IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote attacker to traverse directories on the system. An atta... |
| CVE-2019-14620 | MEDIUM | 6.5 | 0.5% | Aug 13, 2020 | Insufficient control flow management for some Intel(R) Wireless Bluetooth(R) products may allow an unprivileged user to ... |
| CVE-2019-14630 | MEDIUM | 4.6 | 0.3% | Aug 13, 2020 | Reliance on untrusted inputs in a security decision in some Intel(R) Thunderbolt(TM) controllers may allow unauthenticat... |
| CVE-2019-19453 | MEDIUM | 5.4 | 0.8% | Aug 3, 2020 | Wowza Streaming Engine before 4.8.5 allows XSS (issue 1 of 2). An authenticated user, with access to the proxy license e... |
| CVE-2019-4589 | MEDIUM | 4.3 | 0.7% | Aug 3, 2020 | IBM Cognos Analytics 11.0 and 11.1 is vulnerable to privlege escalation where the "My schedules and subscriptions" page ... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now