2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-13021MEDIUM6.5The administrative passwords for all versions of Bond JetSelect are stored within an unprotected file on the filesystem,...
CVE-2019-15083MEDIUM6.1Default installations of Zoho ManageEngine ServiceDesk Plus 10.0 before 10500 are vulnerable to XSS injected by a workst...
CVE-2019-2388MEDIUM5.3In affected Ops Manager versions there is an exposed http route was that may allow attackers to view a specific access l...
CVE-2019-4478MEDIUM6.5IBM Maximo Asset Management 7.6.0, and 7.6.1 could allow an authenticated user to obtain highly sensitive information th...
CVE-2019-4667MEDIUM5.9IBM UrbanCode Deploy (UCD) 7.0.5.2 could allow a remote attacker to obtain sensitive information, caused by the failure ...
CVE-2019-20795MEDIUM4.4iproute2 before 5.1.0 has a use-after-free in get_netnsid_from_name in ip/ipnetns.c. NOTE: security relevance may be lim...
CVE-2019-20794MEDIUM4.7An issue was discovered in the Linux kernel 4.18 through 5.6.11 when unprivileged user namespaces are allowed. A user ca...
CVE-2019-18870MEDIUM6.5A path traversal via the iniFile parameter in excel.php in Blaauw Remote Kiln Control through v3.00r4 allows an authenti...
CVE-2019-18865MEDIUM5.3Information disclosure via error message discrepancies in authentication functions in Blaauw Remote Kiln Control through...
CVE-2019-20768MEDIUM5.4ServiceNow IT Service Management Kingston through Patch 14-1, London through Patch 7, and Madrid before patch 4 allow st...
CVE-2019-19515MEDIUM6.1Ayision Ays-WR01 v28K.RPT.20161224 devices allow stored XSS in wireless settings.
CVE-2019-19514MEDIUM5.4Ayision Ays-WR01 v28K.RPT.20161224 devices allow stored XSS in basic repeater settings via an SSID.
CVE-2019-12864MEDIUM5.5SolarWinds Orion Platform 2018.4 HF3 (NPM 12.4, NetPath 1.1.4) is vulnerable to Information Leakage, because of improper...
CVE-2019-17557MEDIUM5.4It was found that the Apache Syncope EndUser UI login page prio to 2.0.15 and 2.1.6 reflects the successMessage paramete...
CVE-2019-4209MEDIUM6.1HCL Connections v5.5, v6.0, and v6.5 contains an open redirect vulnerability which could be exploited by an attacker to ...
CVE-2019-4288MEDIUM4.3IBM Maximo Anywhere 7.6.2.0, 7.6.2.1, 7.6.3.0, and 7.6.3.1 could disclose highly senstiive user information to an authen...
CVE-2019-4286MEDIUM4.3IBM Maximo Anywhere 7.6.2.0, 7.6.2.1, 7.6.3.0, and 7.6.3.1 could disclose highly senstiive user information to an authen...
CVE-2019-7634MEDIUM5.4SUAP V2 allows XSS during the update of user information.
CVE-2019-20792MEDIUM6.8OpenSC before 0.20.0 has a double free in coolkey_free_private_data because coolkey_add_object in libopensc/card-coolkey...
CVE-2019-19101MEDIUM5.9A missing secure communication definition and an incomplete TLS validation in the upgrade service in B&R Automation Stud...
CVE-2019-15877MEDIUM5.5In FreeBSD 12.1-STABLE before r356606 and 12.1-RELEASE before 12.1-RELEASE-p3, driver specific ioctl command handlers in...
CVE-2019-15876MEDIUM5.5In FreeBSD 12.1-STABLE before r356089, 12.1-RELEASE before 12.1-RELEASE-p3, 11.3-STABLE before r356090, and 11.3-RELEASE...
CVE-2019-5303MEDIUM5.3There are two denial of service vulnerabilities on some Huawei smartphones. An attacker may send specially crafted TD-SC...
CVE-2019-5302MEDIUM5.3There are two denial of service vulnerabilities on some Huawei smartphones. An attacker may send specially crafted TD-SC...
CVE-2019-4729MEDIUM4.3IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain sensitive information when a detailed technic...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now