2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-13021 | MEDIUM | 6.5 | 0.6% | May 14, 2020 | The administrative passwords for all versions of Bond JetSelect are stored within an unprotected file on the filesystem,... |
| CVE-2019-15083 | MEDIUM | 6.1 | 6.3% | May 14, 2020 | Default installations of Zoho ManageEngine ServiceDesk Plus 10.0 before 10500 are vulnerable to XSS injected by a workst... |
| CVE-2019-2388 | MEDIUM | 5.3 | 1.0% | May 13, 2020 | In affected Ops Manager versions there is an exposed http route was that may allow attackers to view a specific access l... |
| CVE-2019-4478 | MEDIUM | 6.5 | 1.0% | May 12, 2020 | IBM Maximo Asset Management 7.6.0, and 7.6.1 could allow an authenticated user to obtain highly sensitive information th... |
| CVE-2019-4667 | MEDIUM | 5.9 | 0.8% | May 11, 2020 | IBM UrbanCode Deploy (UCD) 7.0.5.2 could allow a remote attacker to obtain sensitive information, caused by the failure ... |
| CVE-2019-20795 | MEDIUM | 4.4 | 0.4% | May 9, 2020 | iproute2 before 5.1.0 has a use-after-free in get_netnsid_from_name in ip/ipnetns.c. NOTE: security relevance may be lim... |
| CVE-2019-20794 | MEDIUM | 4.7 | 0.5% | May 9, 2020 | An issue was discovered in the Linux kernel 4.18 through 5.6.11 when unprivileged user namespaces are allowed. A user ca... |
| CVE-2019-18870 | MEDIUM | 6.5 | 1.1% | May 7, 2020 | A path traversal via the iniFile parameter in excel.php in Blaauw Remote Kiln Control through v3.00r4 allows an authenti... |
| CVE-2019-18865 | MEDIUM | 5.3 | 1.1% | May 7, 2020 | Information disclosure via error message discrepancies in authentication functions in Blaauw Remote Kiln Control through... |
| CVE-2019-20768 | MEDIUM | 5.4 | 0.7% | May 5, 2020 | ServiceNow IT Service Management Kingston through Patch 14-1, London through Patch 7, and Madrid before patch 4 allow st... |
| CVE-2019-19515 | MEDIUM | 6.1 | 0.8% | May 5, 2020 | Ayision Ays-WR01 v28K.RPT.20161224 devices allow stored XSS in wireless settings. |
| CVE-2019-19514 | MEDIUM | 5.4 | 0.6% | May 5, 2020 | Ayision Ays-WR01 v28K.RPT.20161224 devices allow stored XSS in basic repeater settings via an SSID. |
| CVE-2019-12864 | MEDIUM | 5.5 | 0.5% | May 4, 2020 | SolarWinds Orion Platform 2018.4 HF3 (NPM 12.4, NetPath 1.1.4) is vulnerable to Information Leakage, because of improper... |
| CVE-2019-17557 | MEDIUM | 5.4 | 1.2% | May 4, 2020 | It was found that the Apache Syncope EndUser UI login page prio to 2.0.15 and 2.1.6 reflects the successMessage paramete... |
| CVE-2019-4209 | MEDIUM | 6.1 | 0.6% | May 1, 2020 | HCL Connections v5.5, v6.0, and v6.5 contains an open redirect vulnerability which could be exploited by an attacker to ... |
| CVE-2019-4288 | MEDIUM | 4.3 | 0.3% | Apr 29, 2020 | IBM Maximo Anywhere 7.6.2.0, 7.6.2.1, 7.6.3.0, and 7.6.3.1 could disclose highly senstiive user information to an authen... |
| CVE-2019-4286 | MEDIUM | 4.3 | 0.3% | Apr 29, 2020 | IBM Maximo Anywhere 7.6.2.0, 7.6.2.1, 7.6.3.0, and 7.6.3.1 could disclose highly senstiive user information to an authen... |
| CVE-2019-7634 | MEDIUM | 5.4 | 0.6% | Apr 29, 2020 | SUAP V2 allows XSS during the update of user information. |
| CVE-2019-20792 | MEDIUM | 6.8 | 0.7% | Apr 29, 2020 | OpenSC before 0.20.0 has a double free in coolkey_free_private_data because coolkey_add_object in libopensc/card-coolkey... |
| CVE-2019-19101 | MEDIUM | 5.9 | 0.5% | Apr 29, 2020 | A missing secure communication definition and an incomplete TLS validation in the upgrade service in B&R Automation Stud... |
| CVE-2019-15877 | MEDIUM | 5.5 | 0.2% | Apr 28, 2020 | In FreeBSD 12.1-STABLE before r356606 and 12.1-RELEASE before 12.1-RELEASE-p3, driver specific ioctl command handlers in... |
| CVE-2019-15876 | MEDIUM | 5.5 | 0.3% | Apr 28, 2020 | In FreeBSD 12.1-STABLE before r356089, 12.1-RELEASE before 12.1-RELEASE-p3, 11.3-STABLE before r356090, and 11.3-RELEASE... |
| CVE-2019-5303 | MEDIUM | 5.3 | 0.3% | Apr 27, 2020 | There are two denial of service vulnerabilities on some Huawei smartphones. An attacker may send specially crafted TD-SC... |
| CVE-2019-5302 | MEDIUM | 5.3 | 0.3% | Apr 27, 2020 | There are two denial of service vulnerabilities on some Huawei smartphones. An attacker may send specially crafted TD-SC... |
| CVE-2019-4729 | MEDIUM | 4.3 | 1.6% | Apr 27, 2020 | IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain sensitive information when a detailed technic... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now