2019 CVE Vulnerabilities

17,621 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-13531MEDIUM4.6In Medtronic Valleylab FT10 Energy Platform (VLFT10GEN) version 2.1.0 and lower and version 2.0.3 and lower, and Valleyl...
CVE-2019-3426HIGH8.8The 9000EV5.0R1B12 version, and all earlier versions of ZTE product ZXUPN-9000E are impacted by the input validation vul...
CVE-2019-3425HIGH8.8The 9000EV5.0R1B12 version, and all earlier versions of ZTE product ZXUPN-9000E are impacted by vulnerability of permiss...
CVE-2019-12410HIGH7.5While investigating UBSAN errors in https://github.com/apache/arrow/pull/5365 it was discovered Apache Arrow versions 0....
CVE-2019-12408HIGH7.5It was discovered that the C++ implementation (which underlies the R, Python and Ruby implementations) of Apache Arrow 0...
CVE-2019-18623CRITICAL9.8Escalation of privileges in EnergyCAP 7 through 7.5.6 allows an attacker to access data. If an unauthenticated user clic...
CVE-2019-17661HIGH8.8A CSV injection in the codepress-admin-columns (aka Admin Columns) plugin 3.4.6 for WordPress allows malicious users to ...
CVE-2019-17327HIGH7.2JEUS 7 Fix#0~5 and JEUS 8Fix#0~1 versions contains a directory traversal vulnerability caused by improper input paramete...
CVE-2019-16210MEDIUM5.5Brocade SANnav versions before v2.0, logs plain text database connection password while triggering support save.
CVE-2019-16209HIGH7.4A vulnerability, in The ReportsTrustManager class of Brocade SANnav versions before v2.0, could allow an attacker to per...
CVE-2019-16208HIGH7.5Password-based encryption (PBE) algorithm, of Brocade SANnav versions before v2.0, has a weakness in generating cryptogr...
CVE-2019-16207HIGH7.8Brocade SANnav versions before v2.0 use a hard-coded password, which could allow local authenticated attackers to access...
CVE-2019-16206MEDIUM5.5The authentication mechanism, in Brocade SANnav versions before v2.0, logs plaintext account credentials at the ‘trace’ ...
CVE-2019-16205HIGH8.8A vulnerability, in Brocade SANnav versions before v2.0, could allow remote attackers to brute-force a valid session ID....
CVE-2019-13557MEDIUM5.3In Tasy EMR, Tasy WebPortal Versions 3.02.1757 and prior, there is an information exposure vulnerability which may allow...
CVE-2019-3866MEDIUM5.5An information-exposure vulnerability was discovered where openstack-mistral's undercloud log files containing clear-tex...
CVE-2019-14860MEDIUM6.5It was found that the Syndesis configuration for Cross-Origin Resource Sharing was set to allow all origins. An attacker...
CVE-2019-14824MEDIUM6.5A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute va...
CVE-2019-10222HIGH7.5A flaw was found in the Ceph RGW configuration with Beast as the front end handling client requests. An unauthenticated ...
CVE-2019-10219MEDIUM6.1A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads ...
CVE-2019-15005MEDIUM4.3The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivileged user to initiate p...
CVE-2019-18835CRITICAL9.8Matrix Synapse before 1.5.0 mishandles signature checking on some federation APIs. Events sent over /send_join, /send_le...
CVE-2019-18818CRITICAL9.8strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/s...
CVE-2019-18821MEDIUM5.5Eximious Logo Designer 3.82 has a User Mode Write AV starting at ExiCustomPathLib!ExiCustomPathLib::CGradientColorsProfi...
CVE-2019-18820MEDIUM5.5Eximious Logo Designer 3.82 has Heap Corruption starting at ntdll!RtlpNtMakeTemporaryKey+0x0000000000001a78.

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now