2019 CVE Vulnerabilities
17,621 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-13531 | MEDIUM | 4.6 | 0.4% | Nov 8, 2019 | In Medtronic Valleylab FT10 Energy Platform (VLFT10GEN) version 2.1.0 and lower and version 2.0.3 and lower, and Valleyl... |
| CVE-2019-3426 | HIGH | 8.8 | 1.0% | Nov 8, 2019 | The 9000EV5.0R1B12 version, and all earlier versions of ZTE product ZXUPN-9000E are impacted by the input validation vul... |
| CVE-2019-3425 | HIGH | 8.8 | 1.0% | Nov 8, 2019 | The 9000EV5.0R1B12 version, and all earlier versions of ZTE product ZXUPN-9000E are impacted by vulnerability of permiss... |
| CVE-2019-12410 | HIGH | 7.5 | 4.7% | Nov 8, 2019 | While investigating UBSAN errors in https://github.com/apache/arrow/pull/5365 it was discovered Apache Arrow versions 0.... |
| CVE-2019-12408 | HIGH | 7.5 | 3.2% | Nov 8, 2019 | It was discovered that the C++ implementation (which underlies the R, Python and Ruby implementations) of Apache Arrow 0... |
| CVE-2019-18623 | CRITICAL | 9.8 | 1.5% | Nov 8, 2019 | Escalation of privileges in EnergyCAP 7 through 7.5.6 allows an attacker to access data. If an unauthenticated user clic... |
| CVE-2019-17661 | HIGH | 8.8 | 2.4% | Nov 8, 2019 | A CSV injection in the codepress-admin-columns (aka Admin Columns) plugin 3.4.6 for WordPress allows malicious users to ... |
| CVE-2019-17327 | HIGH | 7.2 | 2.7% | Nov 8, 2019 | JEUS 7 Fix#0~5 and JEUS 8Fix#0~1 versions contains a directory traversal vulnerability caused by improper input paramete... |
| CVE-2019-16210 | MEDIUM | 5.5 | 0.2% | Nov 8, 2019 | Brocade SANnav versions before v2.0, logs plain text database connection password while triggering support save. |
| CVE-2019-16209 | HIGH | 7.4 | 0.7% | Nov 8, 2019 | A vulnerability, in The ReportsTrustManager class of Brocade SANnav versions before v2.0, could allow an attacker to per... |
| CVE-2019-16208 | HIGH | 7.5 | 0.4% | Nov 8, 2019 | Password-based encryption (PBE) algorithm, of Brocade SANnav versions before v2.0, has a weakness in generating cryptogr... |
| CVE-2019-16207 | HIGH | 7.8 | 0.3% | Nov 8, 2019 | Brocade SANnav versions before v2.0 use a hard-coded password, which could allow local authenticated attackers to access... |
| CVE-2019-16206 | MEDIUM | 5.5 | 0.2% | Nov 8, 2019 | The authentication mechanism, in Brocade SANnav versions before v2.0, logs plaintext account credentials at the ‘trace’ ... |
| CVE-2019-16205 | HIGH | 8.8 | 1.3% | Nov 8, 2019 | A vulnerability, in Brocade SANnav versions before v2.0, could allow remote attackers to brute-force a valid session ID.... |
| CVE-2019-13557 | MEDIUM | 5.3 | 1.2% | Nov 8, 2019 | In Tasy EMR, Tasy WebPortal Versions 3.02.1757 and prior, there is an information exposure vulnerability which may allow... |
| CVE-2019-3866 | MEDIUM | 5.5 | 0.3% | Nov 8, 2019 | An information-exposure vulnerability was discovered where openstack-mistral's undercloud log files containing clear-tex... |
| CVE-2019-14860 | MEDIUM | 6.5 | 1.2% | Nov 8, 2019 | It was found that the Syndesis configuration for Cross-Origin Resource Sharing was set to allow all origins. An attacker... |
| CVE-2019-14824 | MEDIUM | 6.5 | 1.3% | Nov 8, 2019 | A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute va... |
| CVE-2019-10222 | HIGH | 7.5 | 4.6% | Nov 8, 2019 | A flaw was found in the Ceph RGW configuration with Beast as the front end handling client requests. An unauthenticated ... |
| CVE-2019-10219 | MEDIUM | 6.1 | 2.2% | Nov 8, 2019 | A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads ... |
| CVE-2019-15005 | MEDIUM | 4.3 | 1.3% | Nov 8, 2019 | The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivileged user to initiate p... |
| CVE-2019-18835 | CRITICAL | 9.8 | 0.9% | Nov 8, 2019 | Matrix Synapse before 1.5.0 mishandles signature checking on some federation APIs. Events sent over /send_join, /send_le... |
| CVE-2019-18818 | CRITICAL | 9.8 | 97.6% | Nov 7, 2019 | strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/s... |
| CVE-2019-18821 | MEDIUM | 5.5 | 0.3% | Nov 7, 2019 | Eximious Logo Designer 3.82 has a User Mode Write AV starting at ExiCustomPathLib!ExiCustomPathLib::CGradientColorsProfi... |
| CVE-2019-18820 | MEDIUM | 5.5 | 0.4% | Nov 7, 2019 | Eximious Logo Designer 3.82 has Heap Corruption starting at ntdll!RtlpNtMakeTemporaryKey+0x0000000000001a78. |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now