2019 CVE Vulnerabilities
17,621 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-3662 | MEDIUM | 6.5 | 1.2% | Nov 14, 2019 | Path Traversal: '/absolute/pathname/here' vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows remo... |
| CVE-2019-3661 | HIGH | 8.8 | 1.1% | Nov 14, 2019 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in McAfee Advanced Threat Defense (... |
| CVE-2019-3640 | MEDIUM | 6.5 | 0.5% | Nov 14, 2019 | Unprotected Transport of Credentials in ePO extension in McAfee Data Loss Prevention 11.x prior to 11.4.0 allows remote ... |
| CVE-2019-18954 | MEDIUM | 5.3 | 1.2% | Nov 14, 2019 | Pomelo v2.2.5 allows external control of critical state data. A malicious user input can corrupt arbitrary methods and a... |
| CVE-2019-5029 | CRITICAL | 9.8 | 57.1% | Nov 13, 2019 | An exploitable command injection vulnerability exists in the Config editor of the Exhibitor Web UI versions 1.0.9 to 1.7... |
| CVE-2019-3660 | HIGH | 8.8 | 1.2% | Nov 13, 2019 | Improper Neutralization of HTTP requests in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows remote authenticate... |
| CVE-2019-3651 | HIGH | 8.8 | 1.1% | Nov 13, 2019 | Information Disclosure vulnerability in McAfee Advanced Threat Defense (ATD prior to 4.8 allows remote authenticated att... |
| CVE-2019-3650 | MEDIUM | 6.5 | 0.9% | Nov 13, 2019 | Information Disclosure vulnerability in McAfee Advanced Threat Defense (ATD prior to 4.8 allows remote authenticated att... |
| CVE-2019-3649 | MEDIUM | 6.5 | 0.9% | Nov 13, 2019 | Information Disclosure vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows remote authenticated at... |
| CVE-2019-3420 | MEDIUM | 6.5 | 0.7% | Nov 13, 2019 | All versions up to V2.5.0_EG1T5_TED of ZTE ZXHN H108N product are impacted by an information leak vulnerability. An atta... |
| CVE-2019-18952 | CRITICAL | 9.8 | 45.4% | Nov 13, 2019 | SibSoft Xfilesharing through 2.5.1 allows cgi-bin/up.cgi arbitrary file upload. This can be combined with CVE-2019-18951... |
| CVE-2019-18951 | HIGH | 7.5 | 19.8% | Nov 13, 2019 | SibSoft Xfilesharing through 2.5.1 allows op=page&tmpl=../ directory traversal to read arbitrary files. |
| CVE-2019-18240 | CRITICAL | 9.8 | 14.0% | Nov 13, 2019 | In Fuji Electric V-Server 4.0.6 and prior, several heap-based buffer overflows have been identified, which may allow an ... |
| CVE-2019-13555 | MEDIUM | 5.9 | 1.5% | Nov 13, 2019 | In Mitsubishi Electric MELSEC-Q Series Q03/04/06/13/26UDVCPU: serial number 21081 and prior, Q04/06/13/26UDPVCPU: serial... |
| CVE-2019-0396 | HIGH | 7.1 | 0.9% | Nov 13, 2019 | SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), corrected in versions 4.1 and 4.2,... |
| CVE-2019-0388 | MEDIUM | 5.3 | 0.7% | Nov 13, 2019 | SAP UI5 HTTP Handler (corrected in SAP_UI versions 7.5, 7.51, 7.52, 7.53, 7.54 and SAP UI_700 version 2.0) allows an att... |
| CVE-2019-0386 | MEDIUM | 6.3 | 0.7% | Nov 13, 2019 | Order processing in SAP ERP Sales (corrected in SAP_APPL 6.0, 6.02, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18) and S4HANA... |
| CVE-2019-18923 | MEDIUM | 6.1 | 0.9% | Nov 13, 2019 | Insufficient content type validation of proxied resources in go-camo before 2.1.1 allows a remote attacker to serve arbi... |
| CVE-2019-0393 | MEDIUM | 4.3 | 0.7% | Nov 13, 2019 | An SQL Injection vulnerability in SAP Quality Management (corrected in S4CORE versions 1.0, 1.01, 1.02, 1.03) allows an ... |
| CVE-2019-0391 | MEDIUM | 4.3 | 0.9% | Nov 13, 2019 | Under certain conditions SAP NetWeaver AS Java (corrected in 7.10, 7.20, 7.30, 7.31, 7.40, 7.50) allows an attacker to a... |
| CVE-2019-0390 | MEDIUM | 4.3 | 0.7% | Nov 13, 2019 | Under certain conditions SAP Data Hub (corrected in DH_Foundation version 2) allows an attacker to access information wh... |
| CVE-2019-0389 | HIGH | 8.8 | 1.3% | Nov 13, 2019 | An administrator of SAP NetWeaver Application Server Java (J2EE-Framework), (corrected in versions 7.1, 7.2, 7.3, 7.31, ... |
| CVE-2019-0385 | MEDIUM | 6.5 | 0.5% | Nov 13, 2019 | SAP Enable Now, before version 1908, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Script... |
| CVE-2019-0382 | MEDIUM | 5.4 | 0.5% | Nov 13, 2019 | A Cross-Site Scripting vulnerability exists in SAP BusinessObjects Business Intelligence Platform (Web Intelligence-Publ... |
| CVE-2019-17550 | MEDIUM | 6.1 | 1.3% | Nov 13, 2019 | The Blog2Social plugin before 5.9.0 for WordPress is affected by: Cross Site Scripting (XSS). The impact is: Allows an a... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now