2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-0399MEDIUM6.5SAP Portfolio and Project Management, before versions S4CORE 102, 103, EPPM 100 and CPRXRPM 500_702, 600_740, 610_740; u...
CVE-2019-0398HIGH8.8Due to insufficient CSRF protection, SAP BusinessObjects Business Intelligence Platform (Monitoring Application), before...
CVE-2019-0395MEDIUM5.4SAP BusinessObjects Business Intelligence Platform (Fiori BI Launchpad), before version 4.2, allows execution of JavaScr...
CVE-2019-19729HIGH7.5An issue was discovered in the BSON ObjectID (aka bson-objectid) package 1.3.0 for Node.js. ObjectID() allows an attacke...
CVE-2019-19374CRITICAL9.1An issue was discovered in core/assets/form/form_question_types/form_question_type_file_upload/form_question_type_file_u...
CVE-2019-19373HIGH7.5An issue was discovered in Squiz Matrix CMS 5.5.0 prior to 5.5.0.3, 5.5.1 prior to 5.5.1.8, 5.5.2 prior to 5.5.2.4, and ...
CVE-2019-19725CRITICAL9.8sysstat through 12.2.0 has a double free in check_file_actlst in sa_common.c.
CVE-2019-19650HIGH8.8Zoho ManageEngine Applications Manager before 13640 allows a remote authenticated SQL injection via the Agent servlet ag...
CVE-2019-19649CRITICAL9.8Zoho ManageEngine Applications Manager before 13620 allows a remote unauthenticated SQL injection via the SyncEventServl...
CVE-2019-19583HIGH7.5An issue was discovered in Xen through 4.12.x allowing x86 HVM/PVH guest OS users to cause a denial of service (guest OS...
CVE-2019-19582MEDIUM6.5An issue was discovered in Xen through 4.12.x allowing x86 guest OS users to cause a denial of service (infinite loop) b...
CVE-2019-19581MEDIUM6.5An issue was discovered in Xen through 4.12.x allowing 32-bit Arm guest OS users to cause a denial of service (out-of-bo...
CVE-2019-19580MEDIUM6.6An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to gain host OS privileges by leveraging ra...
CVE-2019-19578HIGH8.8An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to cause a denial of service via degenerate...
CVE-2019-19577HIGH7.2An issue was discovered in Xen through 4.12.x allowing x86 AMD HVM guest OS users to cause a denial of service or possib...
CVE-2019-14317MEDIUM5.3wolfSSL and wolfCrypt 4.1.0 and earlier (formerly known as CyaSSL) generate biased DSA nonces. This allows a remote atta...
CVE-2019-18379HIGH7.3Symantec Messaging Gateway, prior to 10.7.3, may be susceptible to a server-side request forgery (SSRF) exploit, which i...
CVE-2019-18378MEDIUM4.8Symantec Messaging Gateway, prior to 10.7.3, may be susceptible to a cross-site scripting (XSS) exploit, which is a type...
CVE-2019-18377HIGH7.2Symantec Messaging Gateway, prior to 10.7.3, may be susceptible to a privilege escalation vulnerability, which is a type...
CVE-2019-10772MEDIUM6.1It is possible to bypass enshrined/svg-sanitize before 0.13.1 using the "xlink:href" attribute due to mishandling of the...
CVE-2019-4715HIGH8.8IBM Spectrum Scale 4.2 and 5.0 could allow a remote authenticated attacker to execute arbitrary commands on the system. ...
CVE-2019-4665MEDIUM5.4IBM Spectrum Scale 4.2 and 5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary...
CVE-2019-15009MEDIUM4.3The /json/profile/removeStarAjax.do resource in Atlassian Fisheye and Crucible before version 4.8.0 allows remote attack...
CVE-2019-15008MEDIUM6.1The /plugins/servlet/branchreview resource in Atlassian Fisheye and Crucible before version 4.7.3 allows remote attacker...
CVE-2019-15007MEDIUM4.8The review resource in Atlassian Fisheye and Crucible before version 4.7.3 allows remote attackers to inject arbitrary H...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now