2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-4366 | MEDIUM | 5.3 | 0.7% | Aug 3, 2020 | IBM Cognos Analytics 11.0 and 11.1 is susceptible to an information disclosure vulnerability where an attacker could gai... |
| CVE-2019-20032 | MEDIUM | 6.5 | 0.7% | Jul 29, 2020 | An attacker with access to an InMail voicemail box equipped with the find me/follow me feature on Aspire-derived NEC PBX... |
| CVE-2019-4731 | MEDIUM | 5.5 | 0.3% | Jul 28, 2020 | IBM MQ Appliance 9.1.4.CD could allow a local attacker to obtain highly sensitive information by inclusion of sensitive ... |
| CVE-2019-18834 | MEDIUM | 6.1 | 1.6% | Jul 23, 2020 | Persistent XSS in the WooCommerce Subscriptions plugin before 2.6.3 for WordPress allows remote attackers to execute arb... |
| CVE-2019-11252 | MEDIUM | 6.5 | 1.1% | Jul 23, 2020 | The Kubernetes kube-controller-manager in versions v1.0-v1.17 is vulnerable to a credential leakage via error messages i... |
| CVE-2019-18618 | MEDIUM | 6 | 0.5% | Jul 22, 2020 | Incorrect access control in the firmware of Synaptics VFS75xx family fingerprint sensors that include external flash (al... |
| CVE-2019-12000 | MEDIUM | 6.6 | 1.1% | Jul 17, 2020 | HPE has found a potential Remote Access Restriction Bypass in HPE MSE Msg Gw application E-LTU prior to version 3.2 when... |
| CVE-2019-4091 | MEDIUM | 5.4 | 0.5% | Jul 17, 2020 | "HCL Marketing Platform is vulnerable to cross-site scripting during addition of new users and also while searching for ... |
| CVE-2019-4090 | MEDIUM | 5.4 | 0.5% | Jul 17, 2020 | "HCL Campaign is vulnerable to cross-site scripting when a user provides XSS scripts in Campaign Description field." |
| CVE-2019-20911 | MEDIUM | 6.5 | 1.0% | Jul 16, 2020 | An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to denial of service in bit_calc_CRC in b... |
| CVE-2019-4748 | MEDIUM | 5.4 | 0.6% | Jul 16, 2020 | IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability allows users to embed... |
| CVE-2019-4747 | MEDIUM | 5.4 | 0.6% | Jul 16, 2020 | IBM Team Concert (RTC) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScr... |
| CVE-2019-20908 | MEDIUM | 6.7 | 0.5% | Jul 15, 2020 | An issue was discovered in drivers/firmware/efi/efi.c in the Linux kernel before 5.4. Incorrect access permissions for t... |
| CVE-2019-17639 | MEDIUM | 5.3 | 1.5% | Jul 15, 2020 | In Eclipse OpenJ9 prior to version 0.21 on Power platforms, calling the System.arraycopy method with a length longer tha... |
| CVE-2019-19326 | MEDIUM | 5.9 | 0.8% | Jul 15, 2020 | Silverstripe CMS sites through 4.4.4 which have opted into HTTP Cache Headers on responses served by the framework's HTT... |
| CVE-2019-12783 | MEDIUM | 6.1 | 0.9% | Jul 14, 2020 | An issue was discovered in Verint Impact 360 15.1. At wfo/control/signin, the rd parameter can accept a URL, to which us... |
| CVE-2019-12773 | MEDIUM | 6.1 | 0.8% | Jul 14, 2020 | An issue was discovered in Verint Impact 360 15.1. At wfo/help/help_popup.jsp, the helpURL parameter can be changed to e... |
| CVE-2019-19338 | MEDIUM | 5.5 | 0.5% | Jul 13, 2020 | A flaw was found in the fix for CVE-2019-11135, in the Linux upstream kernel versions before 5.5 where, the way Intel CP... |
| CVE-2019-20901 | MEDIUM | 6.1 | 1.2% | Jul 13, 2020 | The login.jsp resource in Jira before version 8.5.2, and from version 8.6.0 before version 8.6.1 allows remote attackers... |
| CVE-2019-20900 | MEDIUM | 4.8 | 0.9% | Jul 13, 2020 | Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript... |
| CVE-2019-20899 | MEDIUM | 5.3 | 2.1% | Jul 13, 2020 | The Gadget API in Atlassian Jira Server and Data Center in affected versions allows remote attackers to make Jira unresp... |
| CVE-2019-20897 | MEDIUM | 6.5 | 1.9% | Jul 13, 2020 | The avatar upload feature in affected versions of Atlassian Jira Server and Data Center allows remote attackers to achie... |
| CVE-2019-19935 | MEDIUM | 6.1 | 1.8% | Jul 7, 2020 | Froala Editor before 3.2.3 allows XSS. |
| CVE-2019-4324 | MEDIUM | 6.1 | 0.6% | Jul 7, 2020 | "HCL AppScan Enterprise is susceptible to Cross-Site Scripting while importing a specially crafted test policy." |
| CVE-2019-4323 | MEDIUM | 4.3 | 0.8% | Jul 7, 2020 | "HCL AppScan Enterprise advisory API documentation is susceptible to clickjacking, which could allow an attacker to embe... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now