2019 CVE Vulnerabilities
17,621 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-18420 | MEDIUM | 6.5 | 2.5% | Oct 31, 2019 | An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to cause a denial of service via a VCPUOP_i... |
| CVE-2019-17551 | MEDIUM | 6.1 | 0.7% | Oct 31, 2019 | In Apak Wholesale Floorplanning Finance 6.31.8.3 and 6.31.8.5, an attacker can send an authenticated POST request with a... |
| CVE-2019-18645 | MEDIUM | 5.5 | 0.4% | Oct 31, 2019 | The quarantine restoration function in Total Defense Anti-virus 11.5.2.28 is vulnerable to symbolic link attacks, allowi... |
| CVE-2019-18644 | MEDIUM | 5.9 | 0.6% | Oct 31, 2019 | The malware scan function in Total Defense Anti-virus 11.5.2.28 is vulnerable to a TOCTOU bug; consequently, symbolic li... |
| CVE-2019-18635 | HIGH | 7.5 | 2.1% | Oct 30, 2019 | An issue was discovered in Mooltipass Moolticute through v0.42.1 and v0.42.x-testing through v0.42.5-testing. There is a... |
| CVE-2019-18633 | CRITICAL | 9.8 | 0.8% | Oct 30, 2019 | European Commission eIDAS-Node Integration Package before 2.3.1 has Missing Certificate Validation because a certain Exp... |
| CVE-2019-18632 | CRITICAL | 9.8 | 0.8% | Oct 30, 2019 | European Commission eIDAS-Node Integration Package before 2.3.1 allows Certificate Faking because an attacker can sign a... |
| CVE-2019-12417 | MEDIUM | 4.8 | 1.3% | Oct 30, 2019 | A malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript ... |
| CVE-2019-10762 | CRITICAL | 9.8 | 1.4% | Oct 30, 2019 | columnQuote in medoo before 1.7.5 allows remote attackers to perform a SQL Injection due to improper escaping. |
| CVE-2019-17326 | MEDIUM | 6.5 | 1.3% | Oct 30, 2019 | ClipSoft REXPERT 1.0.0.527 and earlier version allows remote attacker to arbitrary file deletion by issuing a HTTP GET r... |
| CVE-2019-17325 | MEDIUM | 6.5 | 1.2% | Oct 30, 2019 | ClipSoft REXPERT 1.0.0.527 and earlier version allows remote attacker to upload arbitrary local file via the ActiveX met... |
| CVE-2019-17324 | MEDIUM | 6.5 | 1.2% | Oct 30, 2019 | ClipSoft REXPERT 1.0.0.527 and earlier version allows directory traversal by issuing a special HTTP POST request with ..... |
| CVE-2019-17323 | HIGH | 8.8 | 1.6% | Oct 30, 2019 | ClipSoft REXPERT 1.0.0.527 and earlier version allows arbitrary file creation and execution via report print function of... |
| CVE-2019-17322 | MEDIUM | 6.5 | 1.2% | Oct 30, 2019 | ClipSoft REXPERT 1.0.0.527 and earlier version allows arbitrary file creation via a POST request with the parameter set ... |
| CVE-2019-17321 | MEDIUM | 5.3 | 0.9% | Oct 30, 2019 | ClipSoft REXPERT 1.0.0.527 and earlier version have an information disclosure issue. When requesting web page associated... |
| CVE-2019-18207 | MEDIUM | 5.4 | 0.5% | Oct 30, 2019 | In Zucchetti InfoBusiness before and including 4.4.1, an authenticated user can inject client-side code due to improper ... |
| CVE-2019-18206 | HIGH | 8.8 | 0.5% | Oct 30, 2019 | A cross-site request forgery (CSRF) vulnerability in Zucchetti InfoBusiness before and including 4.4.1 allows arbitrary ... |
| CVE-2019-18205 | MEDIUM | 6.1 | 0.7% | Oct 30, 2019 | Multiple Reflected Cross-site Scripting (XSS) vulnerabilities exist in Zucchetti InfoBusiness before and including 4.4.1... |
| CVE-2019-18204 | HIGH | 8.8 | 1.7% | Oct 30, 2019 | Zucchetti InfoBusiness before and including 4.4.1 allows any authenticated user to upload .php files in order to achieve... |
| CVE-2019-15682 | HIGH | 7.5 | 1.4% | Oct 30, 2019 | RDesktop version 1.8.4 contains multiple out-of-bound access read vulnerabilities in its code, which results in a denial... |
| CVE-2019-7620 | HIGH | 7.5 | 1.5% | Oct 30, 2019 | Logstash versions before 7.4.1 and 6.8.4 contain a denial of service flaw in the Logstash Beats input plugin. An unauthe... |
| CVE-2019-7619 | MEDIUM | 5.3 | 2.4% | Oct 30, 2019 | Elasticsearch versions 7.0.0-7.3.2 and 6.7.0-6.8.3 contain a username disclosure flaw was found in the API Key service. ... |
| CVE-2019-8235 | MEDIUM | 6.5 | 1.9% | Oct 30, 2019 | An insecure direct object reference (IDOR) vulnerability exists in Magento 2.3 prior to 2.3.1, 2.2 prior to 2.2.8, and 2... |
| CVE-2019-9926 | HIGH | 8.8 | 1.9% | Oct 29, 2019 | An issue was discovered in LabKey Server 19.1.0. It is possible to force a logged-in administrator to execute code throu... |
| CVE-2019-9758 | MEDIUM | 5.4 | 1.0% | Oct 29, 2019 | An issue was discovered in LabKey Server 19.1.0. The display name of a user is vulnerable to stored XSS that can execute... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now