2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-4366MEDIUM5.3IBM Cognos Analytics 11.0 and 11.1 is susceptible to an information disclosure vulnerability where an attacker could gai...
CVE-2019-20032MEDIUM6.5An attacker with access to an InMail voicemail box equipped with the find me/follow me feature on Aspire-derived NEC PBX...
CVE-2019-4731MEDIUM5.5IBM MQ Appliance 9.1.4.CD could allow a local attacker to obtain highly sensitive information by inclusion of sensitive ...
CVE-2019-18834MEDIUM6.1Persistent XSS in the WooCommerce Subscriptions plugin before 2.6.3 for WordPress allows remote attackers to execute arb...
CVE-2019-11252MEDIUM6.5The Kubernetes kube-controller-manager in versions v1.0-v1.17 is vulnerable to a credential leakage via error messages i...
CVE-2019-18618MEDIUM6Incorrect access control in the firmware of Synaptics VFS75xx family fingerprint sensors that include external flash (al...
CVE-2019-12000MEDIUM6.6HPE has found a potential Remote Access Restriction Bypass in HPE MSE Msg Gw application E-LTU prior to version 3.2 when...
CVE-2019-4091MEDIUM5.4"HCL Marketing Platform is vulnerable to cross-site scripting during addition of new users and also while searching for ...
CVE-2019-4090MEDIUM5.4"HCL Campaign is vulnerable to cross-site scripting when a user provides XSS scripts in Campaign Description field."
CVE-2019-20911MEDIUM6.5An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to denial of service in bit_calc_CRC in b...
CVE-2019-4748MEDIUM5.4IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability allows users to embed...
CVE-2019-4747MEDIUM5.4IBM Team Concert (RTC) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScr...
CVE-2019-20908MEDIUM6.7An issue was discovered in drivers/firmware/efi/efi.c in the Linux kernel before 5.4. Incorrect access permissions for t...
CVE-2019-17639MEDIUM5.3In Eclipse OpenJ9 prior to version 0.21 on Power platforms, calling the System.arraycopy method with a length longer tha...
CVE-2019-19326MEDIUM5.9Silverstripe CMS sites through 4.4.4 which have opted into HTTP Cache Headers on responses served by the framework's HTT...
CVE-2019-12783MEDIUM6.1An issue was discovered in Verint Impact 360 15.1. At wfo/control/signin, the rd parameter can accept a URL, to which us...
CVE-2019-12773MEDIUM6.1An issue was discovered in Verint Impact 360 15.1. At wfo/help/help_popup.jsp, the helpURL parameter can be changed to e...
CVE-2019-19338MEDIUM5.5A flaw was found in the fix for CVE-2019-11135, in the Linux upstream kernel versions before 5.5 where, the way Intel CP...
CVE-2019-20901MEDIUM6.1The login.jsp resource in Jira before version 8.5.2, and from version 8.6.0 before version 8.6.1 allows remote attackers...
CVE-2019-20900MEDIUM4.8Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript...
CVE-2019-20899MEDIUM5.3The Gadget API in Atlassian Jira Server and Data Center in affected versions allows remote attackers to make Jira unresp...
CVE-2019-20897MEDIUM6.5The avatar upload feature in affected versions of Atlassian Jira Server and Data Center allows remote attackers to achie...
CVE-2019-19935MEDIUM6.1Froala Editor before 3.2.3 allows XSS.
CVE-2019-4324MEDIUM6.1"HCL AppScan Enterprise is susceptible to Cross-Site Scripting while importing a specially crafted test policy."
CVE-2019-4323MEDIUM4.3"HCL AppScan Enterprise advisory API documentation is susceptible to clickjacking, which could allow an attacker to embe...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now