2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-0399 | MEDIUM | 6.5 | 0.9% | Dec 11, 2019 | SAP Portfolio and Project Management, before versions S4CORE 102, 103, EPPM 100 and CPRXRPM 500_702, 600_740, 610_740; u... |
| CVE-2019-0398 | HIGH | 8.8 | 0.5% | Dec 11, 2019 | Due to insufficient CSRF protection, SAP BusinessObjects Business Intelligence Platform (Monitoring Application), before... |
| CVE-2019-0395 | MEDIUM | 5.4 | 0.7% | Dec 11, 2019 | SAP BusinessObjects Business Intelligence Platform (Fiori BI Launchpad), before version 4.2, allows execution of JavaScr... |
| CVE-2019-19729 | HIGH | 7.5 | 1.1% | Dec 11, 2019 | An issue was discovered in the BSON ObjectID (aka bson-objectid) package 1.3.0 for Node.js. ObjectID() allows an attacke... |
| CVE-2019-19374 | CRITICAL | 9.1 | 3.4% | Dec 11, 2019 | An issue was discovered in core/assets/form/form_question_types/form_question_type_file_upload/form_question_type_file_u... |
| CVE-2019-19373 | HIGH | 7.5 | 4.8% | Dec 11, 2019 | An issue was discovered in Squiz Matrix CMS 5.5.0 prior to 5.5.0.3, 5.5.1 prior to 5.5.1.8, 5.5.2 prior to 5.5.2.4, and ... |
| CVE-2019-19725 | CRITICAL | 9.8 | 2.8% | Dec 11, 2019 | sysstat through 12.2.0 has a double free in check_file_actlst in sa_common.c. |
| CVE-2019-19650 | HIGH | 8.8 | 5.7% | Dec 11, 2019 | Zoho ManageEngine Applications Manager before 13640 allows a remote authenticated SQL injection via the Agent servlet ag... |
| CVE-2019-19649 | CRITICAL | 9.8 | 9.5% | Dec 11, 2019 | Zoho ManageEngine Applications Manager before 13620 allows a remote unauthenticated SQL injection via the SyncEventServl... |
| CVE-2019-19583 | HIGH | 7.5 | 2.2% | Dec 11, 2019 | An issue was discovered in Xen through 4.12.x allowing x86 HVM/PVH guest OS users to cause a denial of service (guest OS... |
| CVE-2019-19582 | MEDIUM | 6.5 | 0.4% | Dec 11, 2019 | An issue was discovered in Xen through 4.12.x allowing x86 guest OS users to cause a denial of service (infinite loop) b... |
| CVE-2019-19581 | MEDIUM | 6.5 | 0.4% | Dec 11, 2019 | An issue was discovered in Xen through 4.12.x allowing 32-bit Arm guest OS users to cause a denial of service (out-of-bo... |
| CVE-2019-19580 | MEDIUM | 6.6 | 1.2% | Dec 11, 2019 | An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to gain host OS privileges by leveraging ra... |
| CVE-2019-19578 | HIGH | 8.8 | 0.4% | Dec 11, 2019 | An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to cause a denial of service via degenerate... |
| CVE-2019-19577 | HIGH | 7.2 | 0.5% | Dec 11, 2019 | An issue was discovered in Xen through 4.12.x allowing x86 AMD HVM guest OS users to cause a denial of service or possib... |
| CVE-2019-14317 | MEDIUM | 5.3 | 1.8% | Dec 11, 2019 | wolfSSL and wolfCrypt 4.1.0 and earlier (formerly known as CyaSSL) generate biased DSA nonces. This allows a remote atta... |
| CVE-2019-18379 | HIGH | 7.3 | 1.1% | Dec 11, 2019 | Symantec Messaging Gateway, prior to 10.7.3, may be susceptible to a server-side request forgery (SSRF) exploit, which i... |
| CVE-2019-18378 | MEDIUM | 4.8 | 0.7% | Dec 11, 2019 | Symantec Messaging Gateway, prior to 10.7.3, may be susceptible to a cross-site scripting (XSS) exploit, which is a type... |
| CVE-2019-18377 | HIGH | 7.2 | 1.4% | Dec 11, 2019 | Symantec Messaging Gateway, prior to 10.7.3, may be susceptible to a privilege escalation vulnerability, which is a type... |
| CVE-2019-10772 | MEDIUM | 6.1 | 0.7% | Dec 11, 2019 | It is possible to bypass enshrined/svg-sanitize before 0.13.1 using the "xlink:href" attribute due to mishandling of the... |
| CVE-2019-4715 | HIGH | 8.8 | 4.0% | Dec 11, 2019 | IBM Spectrum Scale 4.2 and 5.0 could allow a remote authenticated attacker to execute arbitrary commands on the system. ... |
| CVE-2019-4665 | MEDIUM | 5.4 | 0.6% | Dec 11, 2019 | IBM Spectrum Scale 4.2 and 5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary... |
| CVE-2019-15009 | MEDIUM | 4.3 | 0.7% | Dec 11, 2019 | The /json/profile/removeStarAjax.do resource in Atlassian Fisheye and Crucible before version 4.8.0 allows remote attack... |
| CVE-2019-15008 | MEDIUM | 6.1 | 0.7% | Dec 11, 2019 | The /plugins/servlet/branchreview resource in Atlassian Fisheye and Crucible before version 4.7.3 allows remote attacker... |
| CVE-2019-15007 | MEDIUM | 4.8 | 0.6% | Dec 11, 2019 | The review resource in Atlassian Fisheye and Crucible before version 4.7.3 allows remote attackers to inject arbitrary H... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now