2019 CVE Vulnerabilities

17,621 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-3662MEDIUM6.5Path Traversal: '/absolute/pathname/here' vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows remo...
CVE-2019-3661HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in McAfee Advanced Threat Defense (...
CVE-2019-3640MEDIUM6.5Unprotected Transport of Credentials in ePO extension in McAfee Data Loss Prevention 11.x prior to 11.4.0 allows remote ...
CVE-2019-18954MEDIUM5.3Pomelo v2.2.5 allows external control of critical state data. A malicious user input can corrupt arbitrary methods and a...
CVE-2019-5029CRITICAL9.8An exploitable command injection vulnerability exists in the Config editor of the Exhibitor Web UI versions 1.0.9 to 1.7...
CVE-2019-3660HIGH8.8Improper Neutralization of HTTP requests in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows remote authenticate...
CVE-2019-3651HIGH8.8Information Disclosure vulnerability in McAfee Advanced Threat Defense (ATD prior to 4.8 allows remote authenticated att...
CVE-2019-3650MEDIUM6.5Information Disclosure vulnerability in McAfee Advanced Threat Defense (ATD prior to 4.8 allows remote authenticated att...
CVE-2019-3649MEDIUM6.5Information Disclosure vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows remote authenticated at...
CVE-2019-3420MEDIUM6.5All versions up to V2.5.0_EG1T5_TED of ZTE ZXHN H108N product are impacted by an information leak vulnerability. An atta...
CVE-2019-18952CRITICAL9.8SibSoft Xfilesharing through 2.5.1 allows cgi-bin/up.cgi arbitrary file upload. This can be combined with CVE-2019-18951...
CVE-2019-18951HIGH7.5SibSoft Xfilesharing through 2.5.1 allows op=page&tmpl=../ directory traversal to read arbitrary files.
CVE-2019-18240CRITICAL9.8In Fuji Electric V-Server 4.0.6 and prior, several heap-based buffer overflows have been identified, which may allow an ...
CVE-2019-13555MEDIUM5.9In Mitsubishi Electric MELSEC-Q Series Q03/04/06/13/26UDVCPU: serial number 21081 and prior, Q04/06/13/26UDPVCPU: serial...
CVE-2019-0396HIGH7.1SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), corrected in versions 4.1 and 4.2,...
CVE-2019-0388MEDIUM5.3SAP UI5 HTTP Handler (corrected in SAP_UI versions 7.5, 7.51, 7.52, 7.53, 7.54 and SAP UI_700 version 2.0) allows an att...
CVE-2019-0386MEDIUM6.3Order processing in SAP ERP Sales (corrected in SAP_APPL 6.0, 6.02, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18) and S4HANA...
CVE-2019-18923MEDIUM6.1Insufficient content type validation of proxied resources in go-camo before 2.1.1 allows a remote attacker to serve arbi...
CVE-2019-0393MEDIUM4.3An SQL Injection vulnerability in SAP Quality Management (corrected in S4CORE versions 1.0, 1.01, 1.02, 1.03) allows an ...
CVE-2019-0391MEDIUM4.3Under certain conditions SAP NetWeaver AS Java (corrected in 7.10, 7.20, 7.30, 7.31, 7.40, 7.50) allows an attacker to a...
CVE-2019-0390MEDIUM4.3Under certain conditions SAP Data Hub (corrected in DH_Foundation version 2) allows an attacker to access information wh...
CVE-2019-0389HIGH8.8An administrator of SAP NetWeaver Application Server Java (J2EE-Framework), (corrected in versions 7.1, 7.2, 7.3, 7.31, ...
CVE-2019-0385MEDIUM6.5SAP Enable Now, before version 1908, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Script...
CVE-2019-0382MEDIUM5.4A Cross-Site Scripting vulnerability exists in SAP BusinessObjects Business Intelligence Platform (Web Intelligence-Publ...
CVE-2019-17550MEDIUM6.1The Blog2Social plugin before 5.9.0 for WordPress is affected by: Cross Site Scripting (XSS). The impact is: Allows an a...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now