2019 CVE Vulnerabilities

17,621 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-15710HIGH7.2An OS command injection vulnerability in FortiExtender 4.1.0 to 4.1.1, 4.0.0 and below under CLI admin console may allow...
CVE-2019-18657MEDIUM5.3ClickHouse before 19.13.5.44 allows HTTP header injection via the url table function.
CVE-2019-14356MEDIUM5.3On Coldcard MK1 and MK2 devices, a side channel for the row-based OLED display was found. The power consumption of each ...
CVE-2019-18656MEDIUM6.1Pimcore 6.2.3 has XSS in the translations grid because bundles/AdminBundle/Resources/public/js/pimcore/settings/translat...
CVE-2019-18465CRITICAL9.8In Progress MOVEit Transfer 11.1 before 11.1.3, a vulnerability has been found that could allow an attacker to sign in w...
CVE-2019-18464CRITICAL9.8In Progress MOVEit Transfer 10.2 before 10.2.6 (2018.3), 11.0 before 11.0.4 (2019.0.4), and 11.1 before 11.1.3 (2019.1.3...
CVE-2019-16251MEDIUM4.3plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated optio...
CVE-2019-12612HIGH7.8An issue was discovered in Bitdefender BOX firmware versions before 2.1.37.37-34 that allows an attacker to pass arbitra...
CVE-2019-3421HIGH8The 7520V3V1.0.0B09P27 version, and all earlier versions of ZTE product ZX297520V3 are impacted by a Command Injection v...
CVE-2019-3419MEDIUM5.7A security vulnerability exists in a management port in the version of ZTE's ZXMP M721V3.10P01B10_M2NCP. An attacker cou...
CVE-2019-18369MEDIUM5.3In JetBrains YouTrack before 2019.2.55152, removing tags from the issues list without the corresponding permission was p...
CVE-2019-18368HIGH7.3In JetBrains Toolbox App before 1.15.5666 for Windows, privilege escalation was possible.
CVE-2019-18367MEDIUM5.3In JetBrains TeamCity before 2019.1.2, a non-destructive operation could be performed by a user without the correspondin...
CVE-2019-18366MEDIUM5.3In JetBrains TeamCity before 2019.1.2, secure values could be exposed to users with the "View build runtime parameters a...
CVE-2019-18365MEDIUM4.3In JetBrains TeamCity before 2019.1.4, reverse tabnabbing was possible on several pages.
CVE-2019-18364CRITICAL9.8In JetBrains TeamCity before 2019.1.4, insecure Java Deserialization could potentially allow remote code execution.
CVE-2019-18363MEDIUM5.3In JetBrains TeamCity before 2019.1.2, access could be gained to the history of builds of a deleted build configuration ...
CVE-2019-18362MEDIUM5.3JetBrains MPS before 2019.2.2 exposed listening ports to the network.
CVE-2019-18361MEDIUM5.3JetBrains IntelliJ IDEA before 2019.2 allows local user privilege escalation, potentially leading to arbitrary code exec...
CVE-2019-18360MEDIUM5.3In JetBrains Hub versions earlier than 2019.1.11738, username enumeration was possible through password recovery.
CVE-2019-18425CRITICAL9.8An issue was discovered in Xen through 4.12.x allowing 32-bit PV guest OS users to gain guest OS privileges by installin...
CVE-2019-18424MEDIUM6.8An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where...
CVE-2019-18423HIGH8.8An issue was discovered in Xen through 4.12.x allowing ARM guest OS users to cause a denial of service via a XENMEM_add_...
CVE-2019-18422HIGH8.8An issue was discovered in Xen through 4.12.x allowing ARM guest OS users to cause a denial of service or gain privilege...
CVE-2019-18421HIGH7.5An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to gain host OS privileges by leveraging ra...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now