2019 CVE Vulnerabilities
17,621 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-4570 | MEDIUM | 5.3 | 1.0% | Nov 22, 2019 | IBM Tivoli Netcool Impact 7.1.0 through 7.1.0.16 generates an error message that includes sensitive information about it... |
| CVE-2019-4569 | MEDIUM | 5.4 | 0.6% | Nov 22, 2019 | IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.16 is vulnerable to cross-site scripting. This vulnerability allows user... |
| CVE-2019-4243 | MEDIUM | 4.4 | 0.3% | Nov 22, 2019 | IBM SmartCloud Analytics 1.3.1 through 1.3.5 allows unauthorized disclosure of information like accessing solrconfig.xml... |
| CVE-2019-4216 | MEDIUM | 4.6 | 0.6% | Nov 22, 2019 | IBM SmartCloud Analytics 1.3.1 through 1.3.5 is vulnerable to possible host header injection attack that could lead to H... |
| CVE-2019-4215 | MEDIUM | 6.1 | 0.9% | Nov 22, 2019 | IBM SmartCloud Analytics 1.3.1 through 1.3.5 could allow a remote attacker to hijack the clicking action of the victim. ... |
| CVE-2019-4214 | LOW | 3.7 | 0.5% | Nov 22, 2019 | IBM SmartCloud Analytics 1.3.1 through 1.3.5 does not set the secure attribute on authorization tokens or session cookie... |
| CVE-2019-3428 | MEDIUM | 6.5 | 0.9% | Nov 22, 2019 | The version V6.01.03.01 of ZTE ZXCDN IAMWEB product is impacted by a configuration error vulnerability. An attacker coul... |
| CVE-2019-3427 | HIGH | 7.2 | 1.1% | Nov 22, 2019 | The version V6.01.03.01 of ZTE ZXCDN IAMWEB product is impacted by a code injection vulnerability. An attacker could exp... |
| CVE-2019-19013 | HIGH | 8.8 | 0.8% | Nov 22, 2019 | A CSRF vulnerability in Pagekit 1.0.17 allows an attacker to upload an arbitrary file by removing the CSRF token from a ... |
| CVE-2019-19227 | MEDIUM | 5.5 | 0.6% | Nov 22, 2019 | In the AppleTalk subsystem in the Linux kernel before 5.1, there is a potential NULL pointer dereference because registe... |
| CVE-2019-10206 | MEDIUM | 6.5 | 1.5% | Nov 22, 2019 | ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all 2.7.x before 2.7.13 and all 2.6.x before... |
| CVE-2019-10203 | MEDIUM | 4.3 | 1.6% | Nov 22, 2019 | PowerDNS Authoritative daemon , pdns versions 4.0.x before 4.0.9, 4.1.x before 4.1.11, exiting when encountering a seria... |
| CVE-2019-13157 | HIGH | 7.5 | 1.7% | Nov 22, 2019 | nsGreen.dll in Naver Vaccine 2.1.4 allows remote attackers to overwrite arbitary files via directory traversal sequences... |
| CVE-2019-19221 | MEDIUM | 5.5 | 0.7% | Nov 21, 2019 | In Libarchive 3.4.0, archive_wstring_append_from_mbs in archive_string.c has an out-of-bounds read because of an incorre... |
| CVE-2019-18933 | CRITICAL | 9.8 | 1.4% | Nov 21, 2019 | In Zulip Server versions from 1.7.0 to before 2.0.7, a bug in the new user signup process meant that users who registere... |
| CVE-2019-18889 | CRITICAL | 9.8 | 33.2% | Nov 21, 2019 | An issue was discovered in Symfony 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. Serializing cert... |
| CVE-2019-18888 | HIGH | 7.5 | 2.2% | Nov 21, 2019 | An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4... |
| CVE-2019-18887 | HIGH | 8.1 | 1.3% | Nov 21, 2019 | An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4... |
| CVE-2019-11325 | CRITICAL | 9.8 | 3.4% | Nov 21, 2019 | An issue was discovered in Symfony before 4.2.12 and 4.3.x before 4.3.8. The VarExport component incorrectly escapes str... |
| CVE-2019-19207 | HIGH | 8.8 | 22.7% | Nov 21, 2019 | rConfig 3.9.2 allows devices.php?searchColumn= SQL injection. |
| CVE-2019-19204 | HIGH | 7.5 | 6.9% | Nov 21, 2019 | An issue was discovered in Oniguruma 6.x before 6.9.4_rc2. In the function fetch_interval_quantifier (formerly known as ... |
| CVE-2019-19203 | HIGH | 7.5 | 4.1% | Nov 21, 2019 | An issue was discovered in Oniguruma 6.x before 6.9.4_rc2. In the function gb18030_mbc_enc_len in file gb18030.c, a UCha... |
| CVE-2019-5637 | HIGH | 7.5 | 1.4% | Nov 21, 2019 | When Beckhoff TwinCAT is configured to use the Profinet driver, a denial of service of the controller could be reached b... |
| CVE-2019-5636 | HIGH | 7.5 | 1.4% | Nov 21, 2019 | When a Beckhoff TwinCAT Runtime receives a malformed UDP packet, the ADS Discovery Service shuts down. Note that the Twi... |
| CVE-2019-19202 | HIGH | 8.8 | 1.0% | Nov 21, 2019 | In Vtiger 7.x before 7.2.0, the My Preferences saving functionality allows a user without administrative privileges to c... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now