2019 CVE Vulnerabilities
17,621 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-15710 | HIGH | 7.2 | 1.9% | Oct 31, 2019 | An OS command injection vulnerability in FortiExtender 4.1.0 to 4.1.1, 4.0.0 and below under CLI admin console may allow... |
| CVE-2019-18657 | MEDIUM | 5.3 | 1.5% | Oct 31, 2019 | ClickHouse before 19.13.5.44 allows HTTP header injection via the url table function. |
| CVE-2019-14356 | MEDIUM | 5.3 | 1.2% | Oct 31, 2019 | On Coldcard MK1 and MK2 devices, a side channel for the row-based OLED display was found. The power consumption of each ... |
| CVE-2019-18656 | MEDIUM | 6.1 | 0.7% | Oct 31, 2019 | Pimcore 6.2.3 has XSS in the translations grid because bundles/AdminBundle/Resources/public/js/pimcore/settings/translat... |
| CVE-2019-18465 | CRITICAL | 9.8 | 1.5% | Oct 31, 2019 | In Progress MOVEit Transfer 11.1 before 11.1.3, a vulnerability has been found that could allow an attacker to sign in w... |
| CVE-2019-18464 | CRITICAL | 9.8 | 1.9% | Oct 31, 2019 | In Progress MOVEit Transfer 10.2 before 10.2.6 (2018.3), 11.0 before 11.0.4 (2019.0.4), and 11.1 before 11.1.3 (2019.1.3... |
| CVE-2019-16251 | MEDIUM | 4.3 | 0.9% | Oct 31, 2019 | plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated optio... |
| CVE-2019-12612 | HIGH | 7.8 | 0.3% | Oct 31, 2019 | An issue was discovered in Bitdefender BOX firmware versions before 2.1.37.37-34 that allows an attacker to pass arbitra... |
| CVE-2019-3421 | HIGH | 8 | 1.1% | Oct 31, 2019 | The 7520V3V1.0.0B09P27 version, and all earlier versions of ZTE product ZX297520V3 are impacted by a Command Injection v... |
| CVE-2019-3419 | MEDIUM | 5.7 | 0.5% | Oct 31, 2019 | A security vulnerability exists in a management port in the version of ZTE's ZXMP M721V3.10P01B10_M2NCP. An attacker cou... |
| CVE-2019-18369 | MEDIUM | 5.3 | 1.1% | Oct 31, 2019 | In JetBrains YouTrack before 2019.2.55152, removing tags from the issues list without the corresponding permission was p... |
| CVE-2019-18368 | HIGH | 7.3 | 1.0% | Oct 31, 2019 | In JetBrains Toolbox App before 1.15.5666 for Windows, privilege escalation was possible. |
| CVE-2019-18367 | MEDIUM | 5.3 | 0.7% | Oct 31, 2019 | In JetBrains TeamCity before 2019.1.2, a non-destructive operation could be performed by a user without the correspondin... |
| CVE-2019-18366 | MEDIUM | 5.3 | 1.1% | Oct 31, 2019 | In JetBrains TeamCity before 2019.1.2, secure values could be exposed to users with the "View build runtime parameters a... |
| CVE-2019-18365 | MEDIUM | 4.3 | 0.8% | Oct 31, 2019 | In JetBrains TeamCity before 2019.1.4, reverse tabnabbing was possible on several pages. |
| CVE-2019-18364 | CRITICAL | 9.8 | 3.5% | Oct 31, 2019 | In JetBrains TeamCity before 2019.1.4, insecure Java Deserialization could potentially allow remote code execution. |
| CVE-2019-18363 | MEDIUM | 5.3 | 0.9% | Oct 31, 2019 | In JetBrains TeamCity before 2019.1.2, access could be gained to the history of builds of a deleted build configuration ... |
| CVE-2019-18362 | MEDIUM | 5.3 | 0.9% | Oct 31, 2019 | JetBrains MPS before 2019.2.2 exposed listening ports to the network. |
| CVE-2019-18361 | MEDIUM | 5.3 | 0.4% | Oct 31, 2019 | JetBrains IntelliJ IDEA before 2019.2 allows local user privilege escalation, potentially leading to arbitrary code exec... |
| CVE-2019-18360 | MEDIUM | 5.3 | 0.9% | Oct 31, 2019 | In JetBrains Hub versions earlier than 2019.1.11738, username enumeration was possible through password recovery. |
| CVE-2019-18425 | CRITICAL | 9.8 | 2.5% | Oct 31, 2019 | An issue was discovered in Xen through 4.12.x allowing 32-bit PV guest OS users to gain guest OS privileges by installin... |
| CVE-2019-18424 | MEDIUM | 6.8 | 0.5% | Oct 31, 2019 | An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where... |
| CVE-2019-18423 | HIGH | 8.8 | 2.1% | Oct 31, 2019 | An issue was discovered in Xen through 4.12.x allowing ARM guest OS users to cause a denial of service via a XENMEM_add_... |
| CVE-2019-18422 | HIGH | 8.8 | 1.8% | Oct 31, 2019 | An issue was discovered in Xen through 4.12.x allowing ARM guest OS users to cause a denial of service or gain privilege... |
| CVE-2019-18421 | HIGH | 7.5 | 1.7% | Oct 31, 2019 | An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to gain host OS privileges by leveraging ra... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now