2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-18199MEDIUM6.6An issue was discovered on Fujitsu Wireless Keyboard Set LX390 GK381 devices. Because of the lack of proper encryption o...
CVE-2019-17581MEDIUM6.1tonyy dormsystem through 1.3 allows DOM XSS.
CVE-2019-15703HIGH7.5An Insufficient Entropy in PRNG vulnerability in Fortinet FortiOS 6.2.1, 6.2.0, 6.0.8 and below for device not enable ha...
CVE-2019-4486MEDIUM5.4IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrar...
CVE-2019-4459MEDIUM5.4IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise 2.5 through 2.5.0.9 and 2.4 through 2.4.0.5 is vulnerable t...
CVE-2019-4398LOW3.3IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise 2.5 through 2.5.0.9 and 2.4 through 2.4.0.5 could allow a l...
CVE-2019-4397MEDIUM6.5IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise 2.5 through 2.5.0.9 and 2.4 through 2.4.0.5 stores sensitiv...
CVE-2019-18394CRITICAL9.8A Server Side Request Forgery (SSRF) vulnerability in FaviconServlet.java in Ignite Realtime Openfire through 4.4.2 allo...
CVE-2019-18393MEDIUM5.3PluginServlet.java in Ignite Realtime Openfire through 4.4.2 does not ensure that retrieved files are located under the ...
CVE-2019-18387CRITICAL9.8Sourcecodester Hotel and Lodge Management System 1.0 is vulnerable to unauthenticated SQL injection and can allow remote...
CVE-2019-18213HIGH8.8XML Language Server (aka lsp4xml) before 0.9.1, as used in Red Hat XML Language Support (aka vscode-xml) before 0.9.1 fo...
CVE-2019-18212MEDIUM6.5XMLLanguageService.java in XML Language Server (aka lsp4xml) before 0.9.1, as used in Red Hat XML Language Support (aka ...
CVE-2019-8238HIGH7.5Adobe Acrobat and Reader versions 2019.010.20100 and earlier; 2019.010.20099 and earlier versions; 2017.011.30140 and ea...
CVE-2019-8237CRITICAL9.8Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20...
CVE-2019-8236CRITICAL9.8Creative Cloud Desktop Application version 4.6.1 and earlier versions have Security Bypass vulnerability. Successful exp...
CVE-2019-18385HIGH7.5An issue was discovered on TerraMaster FS-210 4.0.19 devices. An unauthenticated attacker can download log files via the...
CVE-2019-18384MEDIUM6.5An issue was discovered on TerraMaster FS-210 4.0.19 devices. An authenticated remote non-administrative user can read u...
CVE-2019-18383HIGH7.5An issue was discovered on TerraMaster FS-210 4.0.19 devices. One can download backup files remotely from terramaster_TN...
CVE-2019-18382HIGH7.5An issue was discovered on AVStar PE204 3.10.70 IP camera devices. A denial of service can occur on open TCP port 23456....
CVE-2019-18371HIGH7.5An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable. There is a directory traversal vulnerabilit...
CVE-2019-18370CRITICAL9.8An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable. The backup file is in tar.gz format. After ...
CVE-2019-18359MEDIUM5.5A buffer over-read was discovered in ReadMP3APETag in apetag.c in MP3Gain 1.6.2. The vulnerability causes an application...
CVE-2019-12415MEDIUM5.5In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a spe...
CVE-2019-9597MEDIUM6.5Darktrace Enterprise Immune System before 3.1 allows CSRF via the /config endpoint.
CVE-2019-9596MEDIUM6.5Darktrace Enterprise Immune System before 3.1 allows CSRF via the /whitelisteddomains endpoint.

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now