2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-4744 | MEDIUM | 6.1 | 0.8% | Dec 20, 2019 | IBM Financial Transaction Manager 3.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed ar... |
| CVE-2019-4743 | MEDIUM | 4.3 | 0.6% | Dec 20, 2019 | IBM Financial Transaction Manager 3.0 does not set the secure attribute on authorization tokens or session cookies. Atta... |
| CVE-2019-4742 | MEDIUM | 6.1 | 0.9% | Dec 20, 2019 | IBM Financial Transaction Manager 3.0 could allow a remote attacker to hijack the clicking action of the victim. By pers... |
| CVE-2019-4736 | MEDIUM | 4.3 | 0.4% | Dec 20, 2019 | IBM Financial Transaction Manager 3.0 is vulnerable to cross-site request forgery which could allow an attacker to execu... |
| CVE-2019-4555 | MEDIUM | 5.4 | 0.8% | Dec 20, 2019 | IBM Cognos Analytics 11.0 and 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbit... |
| CVE-2019-4231 | MEDIUM | 4.3 | 0.7% | Dec 20, 2019 | IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute ... |
| CVE-2019-19747 | CRITICAL | 9.8 | 1.4% | Dec 20, 2019 | NeuVector 3.1 when configured to allow authentication via Active Directory, does not enforce non-empty passwords which a... |
| CVE-2019-17571 | CRITICAL | 9.8 | 69.1% | Dec 20, 2019 | Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be explo... |
| CVE-2019-15915 | HIGH | 7.5 | 1.2% | Dec 20, 2019 | An issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, RTCGQ01LM devices. Attackers can utilize the "discover... |
| CVE-2019-15914 | HIGH | 7.5 | 1.3% | Dec 20, 2019 | An issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, WSDCGQ01LM, RTCGQ01LM devices. Attackers can use the Z... |
| CVE-2019-15913 | CRITICAL | 9.8 | 1.3% | Dec 20, 2019 | An issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, WSDCGQ01LM, RTCGQ01LM devices. Because of insecure key... |
| CVE-2019-15912 | HIGH | 7.5 | 1.3% | Dec 20, 2019 | An issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO. Attackers... |
| CVE-2019-15911 | CRITICAL | 9.8 | 0.8% | Dec 20, 2019 | An issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO. Because o... |
| CVE-2019-15910 | HIGH | 7.5 | 1.3% | Dec 20, 2019 | An issue was discovered on ASUS HG100, MW100, WS-101, TS-101, AS-101, MS-101, DL-101 devices using ZigBee PRO. Attackers... |
| CVE-2019-19916 | MEDIUM | 6.1 | 1.6% | Dec 20, 2019 | In Midori Browser 0.5.11 (on Windows 10), Content Security Policy (CSP) is not applied correctly to all parts of multipa... |
| CVE-2019-19693 | HIGH | 7.1 | 0.6% | Dec 20, 2019 | The Trend Micro Security 2020 consumer family of products contains a vulnerability that could allow a local attacker to ... |
| CVE-2019-19692 | MEDIUM | 6.1 | 0.7% | Dec 20, 2019 | Trend Micro Apex One (2019) is affected by a cross-site scripting (XSS) vulnerability on the product console. Note that ... |
| CVE-2019-19691 | MEDIUM | 4.9 | 1.2% | Dec 20, 2019 | A vulnerability in Trend Micro Apex One and OfficeScan XG could allow an attacker to expose a masked credential key by m... |
| CVE-2019-18263 | MEDIUM | 6.5 | 0.2% | Dec 20, 2019 | An issue was found in Philips Veradius Unity, Pulsera, and Endura Dual WAN Router, Veradius Unity (718132) with wireless... |
| CVE-2019-17440 | CRITICAL | 9.8 | 1.7% | Dec 20, 2019 | Improper restriction of communications to Log Forwarding Card (LFC) on PA-7000 Series devices with second-generation Swi... |
| CVE-2019-19908 | MEDIUM | 6.1 | 21.2% | Dec 20, 2019 | phpMyChat-Plus 1.98 is vulnerable to reflected XSS via JavaScript injection into the password reset URL. In the URL, the... |
| CVE-2019-19789 | MEDIUM | 6.5 | 1.2% | Dec 20, 2019 | 3S-Smart CODESYS SP Realtime NT before V2.3.7.28, CODESYS Runtime Toolkit 32 bit full before V2.4.7.54, and CODESYS PLCW... |
| CVE-2019-19141 | HIGH | 8.8 | 4.4% | Dec 19, 2019 | The Camera Upload functionality in Plex Media Server through 1.18.2.2029 allows remote authenticated users to write file... |
| CVE-2019-19915 | CRITICAL | 9 | 0.9% | Dec 19, 2019 | The "301 Redirects - Easy Redirect Manager" plugin before 2.45 for WordPress allows users (with subscriber or greater ac... |
| CVE-2019-19342 | MEDIUM | 5.3 | 1.1% | Dec 19, 2019 | A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2 and 3.5.x before 3.5.4, when /websocket is requested and ... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now