2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-20884MEDIUM5.3An issue was discovered in Mattermost Server before 5.8.0. It allows attackers to partially attach a file to more than o...
CVE-2019-20883MEDIUM4.3An issue was discovered in Mattermost Server before 5.8.0, when Town Square is set to Read-Only. Users can pin or unpin ...
CVE-2019-20882MEDIUM5.3An issue was discovered in Mattermost Server before 5.8.0. It does not honor the domain requirement when processing a jo...
CVE-2019-20879MEDIUM4.3An issue was discovered in Mattermost Server before 5.8.0, 5.7.2, 5.6.5, and 4.10.7. Changes to e-mail addresses do not ...
CVE-2019-20878MEDIUM4.3An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. Changes, within the application, to...
CVE-2019-20877MEDIUM5.3An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows attackers to obtain sensi...
CVE-2019-20876MEDIUM5.4An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. Users can deactivate themselves, by...
CVE-2019-20875MEDIUM5.3An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows a password reset to proce...
CVE-2019-20873MEDIUM6.5An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows attackers to obtain sensi...
CVE-2019-20872MEDIUM5.5An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. SSRF can attack local services.
CVE-2019-20870MEDIUM4.3An issue was discovered in Mattermost Server before 5.10.0. An attacker can bypass the intended appearance of the Edited...
CVE-2019-20869MEDIUM5.3An issue was discovered in Mattermost Server before 5.10.0, 5.9.1, 5.8.2, and 4.10.9. A non-member could change the Upda...
CVE-2019-20867MEDIUM5.3An issue was discovered in Mattermost Server before 5.11.0. An attacker can interfere with a channel's post loading via ...
CVE-2019-20866MEDIUM5.3An issue was discovered in Mattermost Server before 5.12.0. Use of a Proxy HTTP header, rather than the source address i...
CVE-2019-20860MEDIUM5.5An issue was discovered in Mattermost Server before 5.14.0, 5.13.3, 5.12.6, and 5.9.4. It allows remote attackers to cau...
CVE-2019-20850MEDIUM5.3An issue was discovered in Mattermost Mobile Apps before 1.26.0. A view cache can persist on a device after a logout.
CVE-2019-20849MEDIUM5.3An issue was discovered in Mattermost Mobile Apps before 1.26.0. Cookie data can persist on a device after a logout.
CVE-2019-20847MEDIUM5.3An issue was discovered in Mattermost Server before 5.18.0. An attacker can send a user_typing WebSocket event to any ch...
CVE-2019-20844MEDIUM6.5An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. An attacker can spoof a d...
CVE-2019-16245MEDIUM5.3OMERO before 5.6.1 makes the details of each user available to all users.
CVE-2019-19112MEDIUM6.1The wpForo plugin 1.6.5 for WordPress allows XSS involving the wpf-dw-td-value class of dashboard.php.
CVE-2019-19111MEDIUM6.1The wpForo plugin 1.6.5 for WordPress allows XSS via the wp-admin/admin.php?page=wpforo-phrases langid parameter.
CVE-2019-19110MEDIUM4.8The wpForo plugin 1.6.5 for WordPress allows XSS via the wp-admin/admin.php?page=wpforo-phrases s parameter.
CVE-2019-16252MEDIUM5.9Missing SSL Certificate Validation in the Nutfind.com application through 3.9.12 for Android allows a man-in-the-middle ...
CVE-2019-3588MEDIUM6.8Privilege Escalation vulnerability in Microsoft Windows client (McTray.exe) in McAfee VirusScan Enterprise (VSE) 8.8 pri...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now