2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-18199 | MEDIUM | 6.6 | 0.4% | Oct 24, 2019 | An issue was discovered on Fujitsu Wireless Keyboard Set LX390 GK381 devices. Because of the lack of proper encryption o... |
| CVE-2019-17581 | MEDIUM | 6.1 | 0.7% | Oct 24, 2019 | tonyy dormsystem through 1.3 allows DOM XSS. |
| CVE-2019-15703 | HIGH | 7.5 | 1.0% | Oct 24, 2019 | An Insufficient Entropy in PRNG vulnerability in Fortinet FortiOS 6.2.1, 6.2.0, 6.0.8 and below for device not enable ha... |
| CVE-2019-4486 | MEDIUM | 5.4 | 0.7% | Oct 24, 2019 | IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrar... |
| CVE-2019-4459 | MEDIUM | 5.4 | 0.6% | Oct 24, 2019 | IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise 2.5 through 2.5.0.9 and 2.4 through 2.4.0.5 is vulnerable t... |
| CVE-2019-4398 | LOW | 3.3 | 0.3% | Oct 24, 2019 | IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise 2.5 through 2.5.0.9 and 2.4 through 2.4.0.5 could allow a l... |
| CVE-2019-4397 | MEDIUM | 6.5 | 1.0% | Oct 24, 2019 | IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise 2.5 through 2.5.0.9 and 2.4 through 2.4.0.5 stores sensitiv... |
| CVE-2019-18394 | CRITICAL | 9.8 | 32.3% | Oct 24, 2019 | A Server Side Request Forgery (SSRF) vulnerability in FaviconServlet.java in Ignite Realtime Openfire through 4.4.2 allo... |
| CVE-2019-18393 | MEDIUM | 5.3 | 13.9% | Oct 24, 2019 | PluginServlet.java in Ignite Realtime Openfire through 4.4.2 does not ensure that retrieved files are located under the ... |
| CVE-2019-18387 | CRITICAL | 9.8 | 1.4% | Oct 23, 2019 | Sourcecodester Hotel and Lodge Management System 1.0 is vulnerable to unauthenticated SQL injection and can allow remote... |
| CVE-2019-18213 | HIGH | 8.8 | 2.0% | Oct 23, 2019 | XML Language Server (aka lsp4xml) before 0.9.1, as used in Red Hat XML Language Support (aka vscode-xml) before 0.9.1 fo... |
| CVE-2019-18212 | MEDIUM | 6.5 | 2.8% | Oct 23, 2019 | XMLLanguageService.java in XML Language Server (aka lsp4xml) before 0.9.1, as used in Red Hat XML Language Support (aka ... |
| CVE-2019-8238 | HIGH | 7.5 | 4.7% | Oct 23, 2019 | Adobe Acrobat and Reader versions 2019.010.20100 and earlier; 2019.010.20099 and earlier versions; 2017.011.30140 and ea... |
| CVE-2019-8237 | CRITICAL | 9.8 | 2.8% | Oct 23, 2019 | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20... |
| CVE-2019-8236 | CRITICAL | 9.8 | 3.4% | Oct 23, 2019 | Creative Cloud Desktop Application version 4.6.1 and earlier versions have Security Bypass vulnerability. Successful exp... |
| CVE-2019-18385 | HIGH | 7.5 | 1.9% | Oct 23, 2019 | An issue was discovered on TerraMaster FS-210 4.0.19 devices. An unauthenticated attacker can download log files via the... |
| CVE-2019-18384 | MEDIUM | 6.5 | 1.4% | Oct 23, 2019 | An issue was discovered on TerraMaster FS-210 4.0.19 devices. An authenticated remote non-administrative user can read u... |
| CVE-2019-18383 | HIGH | 7.5 | 1.6% | Oct 23, 2019 | An issue was discovered on TerraMaster FS-210 4.0.19 devices. One can download backup files remotely from terramaster_TN... |
| CVE-2019-18382 | HIGH | 7.5 | 1.1% | Oct 23, 2019 | An issue was discovered on AVStar PE204 3.10.70 IP camera devices. A denial of service can occur on open TCP port 23456.... |
| CVE-2019-18371 | HIGH | 7.5 | 55.4% | Oct 23, 2019 | An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable. There is a directory traversal vulnerabilit... |
| CVE-2019-18370 | CRITICAL | 9.8 | 40.3% | Oct 23, 2019 | An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable. The backup file is in tar.gz format. After ... |
| CVE-2019-18359 | MEDIUM | 5.5 | 1.4% | Oct 23, 2019 | A buffer over-read was discovered in ReadMP3APETag in apetag.c in MP3Gain 1.6.2. The vulnerability causes an application... |
| CVE-2019-12415 | MEDIUM | 5.5 | 1.0% | Oct 23, 2019 | In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a spe... |
| CVE-2019-9597 | MEDIUM | 6.5 | 1.0% | Oct 23, 2019 | Darktrace Enterprise Immune System before 3.1 allows CSRF via the /config endpoint. |
| CVE-2019-9596 | MEDIUM | 6.5 | 1.6% | Oct 23, 2019 | Darktrace Enterprise Immune System before 3.1 allows CSRF via the /whitelisteddomains endpoint. |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now