2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-20636MEDIUM6.7In the Linux kernel before 5.4.12, drivers/input/input.c has out-of-bounds writes via a crafted keycode table, as demons...
CVE-2019-17231MEDIUM6.1includes/theme-functions.php in the OneTone theme through 3.0.6 for WordPress has multiple stored XSS issues.
CVE-2019-17230MEDIUM5.3includes/theme-functions.php in the OneTone theme through 3.0.6 for WordPress allows unauthenticated options changes.
CVE-2019-18905MEDIUM5.9A Insufficient Verification of Data Authenticity vulnerability in autoyast2 of SUSE Linux Enterprise Server 12, SUSE Lin...
CVE-2019-19096MEDIUM6.1The Redis data structure component used in ABB eSOMS versions 6.0 to 6.0.2 stores credentials in clear text. If an attac...
CVE-2019-19095MEDIUM5.4Lack of adequate input/output validation for ABB eSOMS versions 4.0 to 6.0.2 might allow an attacker to attack such as s...
CVE-2019-19093MEDIUM6.5eSOMS versions 4.0 to 6.0.3 do not enforce password complexity settings, potentially resulting in lower access security ...
CVE-2019-19091MEDIUM4.3For ABB eSOMS versions 4.0 to 6.0.3, HTTPS responses contain comments with sensitive information about the application. ...
CVE-2019-19089MEDIUM6.1For ABB eSOMS versions 4.0 to 6.0.3, the X-Content-Type-Options Header is missing in the HTTP response, potentially caus...
CVE-2019-19003MEDIUM6.1For ABB eSOMS versions 4.0 to 6.0.2, the HTTPOnly flag is not set. This can allow Javascript to access the cookie conten...
CVE-2019-19002MEDIUM5.4For ABB eSOMS versions 4.0 to 6.0.2, the X-XSS-Protection HTTP response header is not set in responses from the web serv...
CVE-2019-19001MEDIUM6.5For ABB eSOMS versions 4.0 to 6.0.2, the X-Frame-Options header is not configured in HTTP response. This can potentially...
CVE-2019-19000MEDIUM6.5For ABB eSOMS 4.0 to 6.0.3, the Cache-Control and Pragma HTTP header(s) have not been properly configured within the app...
CVE-2019-20635MEDIUM6.1codeBeamer before 9.5.0-RC3 does not properly restrict the ability to execute custom Java code and access the Java class...
CVE-2019-11254MEDIUM6.5The Kubernetes API Server component in versions 1.1-1.14, and versions prior to 1.15.10, 1.16.7 and 1.17.3 allows an aut...
CVE-2019-13495MEDIUM5.4In firmware version 4.50 of Zyxel XGS2210-52HP, multiple stored cross-site scripting (XSS) issues allows remote authenti...
CVE-2019-14905MEDIUM5.6A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and ear...
CVE-2019-10180MEDIUM4.8A vulnerability was found in all pki-core 10.x.x version, where the Token Processing Service (TPS) did not properly sani...
CVE-2019-2391MEDIUM5.4Incorrect parsing of certain JSON input may result in js-bson not correctly serializing BSON. This may cause unexpected ...
CVE-2019-9509MEDIUM5.4The web interface of the Vertiv Avocent UMG-4000 version 4.2.1.19 is vulnerable to reflected XSS in an HTTP POST paramet...
CVE-2019-19913MEDIUM4.8In Intland codeBeamer ALM 9.5 and earlier, there is stored XSS via the Trackers Title parameter.
CVE-2019-19912MEDIUM4.8In Intland codeBeamer ALM 9.5 and earlier, a cross-site scripting (XSS) vulnerability in the Upload Flash File feature a...
CVE-2019-15796MEDIUM4.7Python-apt doesn't check if hashes are signed in `Version.fetch_binary()` and `Version.fetch_source()` of apt/package.py...
CVE-2019-15795MEDIUM4.7python-apt only checks the MD5 sums of downloaded files in `Version.fetch_binary()` and `Version.fetch_source()` of apt/...
CVE-2019-18626MEDIUM4.3Harris Ormed Self Service before 2019.1.4 allows an authenticated user to view W-2 forms belonging to other users via an...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now