2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-14900 | MEDIUM | 6.5 | 2.1% | Jul 6, 2020 | A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementati... |
| CVE-2019-8252 | MEDIUM | 5.5 | 2.4% | Jul 6, 2020 | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20... |
| CVE-2019-8251 | MEDIUM | 5.5 | 2.4% | Jul 6, 2020 | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20... |
| CVE-2019-20418 | MEDIUM | 6.5 | 1.0% | Jul 3, 2020 | Affected versions of Atlassian Jira Server and Data Center allow remote attackers to prevent users from accessing the in... |
| CVE-2019-4704 | MEDIUM | 4.3 | 0.6% | Jul 1, 2020 | IBM Security Identity Manager Virtual Appliance 7.0.2 does not set the secure attribute on authorization tokens or sessi... |
| CVE-2019-20408 | MEDIUM | 5.3 | 1.0% | Jul 1, 2020 | The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.7.0 allows remote attackers to access the con... |
| CVE-2019-20416 | MEDIUM | 4.8 | 0.6% | Jun 30, 2020 | Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript... |
| CVE-2019-20415 | MEDIUM | 4.3 | 0.6% | Jun 30, 2020 | Atlassian Jira Server and Data Center in affected versions allows remote attackers to modify logging and profiling setti... |
| CVE-2019-18256 | MEDIUM | 4.6 | 0.4% | Jun 29, 2020 | BIOTRONIK CardioMessenger II, The affected products use individual per-device credentials that are stored in a recoverab... |
| CVE-2019-18254 | MEDIUM | 4.6 | 0.2% | Jun 29, 2020 | BIOTRONIK CardioMessenger II, The affected products do not encrypt sensitive information while at rest. An attacker with... |
| CVE-2019-18252 | MEDIUM | 4.3 | 0.5% | Jun 29, 2020 | BIOTRONIK CardioMessenger II, The affected products allow credential reuse for multiple authentication purposes. An atta... |
| CVE-2019-18248 | MEDIUM | 4.3 | 0.4% | Jun 29, 2020 | BIOTRONIK CardioMessenger II, The affected products transmit credentials in clear-text prior to switching to an encrypte... |
| CVE-2019-18246 | MEDIUM | 4.3 | 0.5% | Jun 29, 2020 | BIOTRONIK CardioMessenger II, The affected products do not properly enforce mutual authentication with the BIOTRONIK Rem... |
| CVE-2019-20414 | MEDIUM | 5.4 | 1.0% | Jun 29, 2020 | Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript... |
| CVE-2019-20412 | MEDIUM | 5.3 | 1.9% | Jun 29, 2020 | The Convert Sub-Task to Issue page in affected versions of Atlassian Jira Server and Data Center allow remote attackers ... |
| CVE-2019-20411 | MEDIUM | 4.3 | 0.7% | Jun 29, 2020 | Affected versions of Atlassian Jira Server and Data Center allow remote attackers to modify Wallboard settings via a Cro... |
| CVE-2019-20410 | MEDIUM | 6.5 | 1.9% | Jun 29, 2020 | Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view sensitive information via an I... |
| CVE-2019-4650 | MEDIUM | 6.3 | 1.0% | Jun 26, 2020 | IBM Maximo Asset Management 7.6.1.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL s... |
| CVE-2019-20892 | MEDIUM | 6.5 | 2.3% | Jun 25, 2020 | net-snmp before 5.8.1.pre1 has a double free in usm_free_usmStateReference in snmplib/snmpusm.c via an SNMPv3 GetBulk re... |
| CVE-2019-3865 | MEDIUM | 6.1 | 0.7% | Jun 22, 2020 | A vulnerability was found in quay-2, where a stored XSS vulnerability has been found in the super user function of quay.... |
| CVE-2019-14092 | MEDIUM | 5.5 | 0.2% | Jun 22, 2020 | System Services exports services without permission protect and can lead to information exposure in Snapdragon Industria... |
| CVE-2019-10626 | MEDIUM | 5.5 | 0.2% | Jun 22, 2020 | Payload size is not validated before reading memory that may cause issue of accessing invalid pointer or some garbage da... |
| CVE-2019-20890 | MEDIUM | 4.3 | 0.8% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.7. It allows a bypass of e-mail address discovery restrictions. |
| CVE-2019-20889 | MEDIUM | 5.3 | 0.8% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.7, 5.6.3, 5.5.2, and 4.10.5. It mishandles permissions for user-ac... |
| CVE-2019-20887 | MEDIUM | 4.3 | 0.7% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.7.1, 5.6.4, 5.5.3, and 4.10.6. It does not honor flags API permiss... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now