2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-14900MEDIUM6.5A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementati...
CVE-2019-8252MEDIUM5.5Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20...
CVE-2019-8251MEDIUM5.5Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20...
CVE-2019-20418MEDIUM6.5Affected versions of Atlassian Jira Server and Data Center allow remote attackers to prevent users from accessing the in...
CVE-2019-4704MEDIUM4.3IBM Security Identity Manager Virtual Appliance 7.0.2 does not set the secure attribute on authorization tokens or sessi...
CVE-2019-20408MEDIUM5.3The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.7.0 allows remote attackers to access the con...
CVE-2019-20416MEDIUM4.8Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript...
CVE-2019-20415MEDIUM4.3Atlassian Jira Server and Data Center in affected versions allows remote attackers to modify logging and profiling setti...
CVE-2019-18256MEDIUM4.6BIOTRONIK CardioMessenger II, The affected products use individual per-device credentials that are stored in a recoverab...
CVE-2019-18254MEDIUM4.6BIOTRONIK CardioMessenger II, The affected products do not encrypt sensitive information while at rest. An attacker with...
CVE-2019-18252MEDIUM4.3BIOTRONIK CardioMessenger II, The affected products allow credential reuse for multiple authentication purposes. An atta...
CVE-2019-18248MEDIUM4.3BIOTRONIK CardioMessenger II, The affected products transmit credentials in clear-text prior to switching to an encrypte...
CVE-2019-18246MEDIUM4.3BIOTRONIK CardioMessenger II, The affected products do not properly enforce mutual authentication with the BIOTRONIK Rem...
CVE-2019-20414MEDIUM5.4Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript...
CVE-2019-20412MEDIUM5.3The Convert Sub-Task to Issue page in affected versions of Atlassian Jira Server and Data Center allow remote attackers ...
CVE-2019-20411MEDIUM4.3Affected versions of Atlassian Jira Server and Data Center allow remote attackers to modify Wallboard settings via a Cro...
CVE-2019-20410MEDIUM6.5Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view sensitive information via an I...
CVE-2019-4650MEDIUM6.3IBM Maximo Asset Management 7.6.1.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL s...
CVE-2019-20892MEDIUM6.5net-snmp before 5.8.1.pre1 has a double free in usm_free_usmStateReference in snmplib/snmpusm.c via an SNMPv3 GetBulk re...
CVE-2019-3865MEDIUM6.1A vulnerability was found in quay-2, where a stored XSS vulnerability has been found in the super user function of quay....
CVE-2019-14092MEDIUM5.5System Services exports services without permission protect and can lead to information exposure in Snapdragon Industria...
CVE-2019-10626MEDIUM5.5Payload size is not validated before reading memory that may cause issue of accessing invalid pointer or some garbage da...
CVE-2019-20890MEDIUM4.3An issue was discovered in Mattermost Server before 5.7. It allows a bypass of e-mail address discovery restrictions.
CVE-2019-20889MEDIUM5.3An issue was discovered in Mattermost Server before 5.7, 5.6.3, 5.5.2, and 4.10.5. It mishandles permissions for user-ac...
CVE-2019-20887MEDIUM4.3An issue was discovered in Mattermost Server before 5.7.1, 5.6.4, 5.5.3, and 4.10.6. It does not honor flags API permiss...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now