2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-20535MEDIUM6.2An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) software. A connection to a new Bluetooth devic...
CVE-2019-20532MEDIUM5.3An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Attackers can access the De...
CVE-2019-17276MEDIUM5.4OnCommand System Manager versions 9.3 prior to 9.3P18 and 9.4 prior to 9.4P2 are susceptible to a cross site scripting v...
CVE-2019-4681MEDIUM6.1IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 is vulnerable to cross-site scripting. This vulnerability allows user...
CVE-2019-20626MEDIUM6.5The remote keyless system on Honda HR-V 2017 vehicles sends the same RF signal for each door-open request, which might a...
CVE-2019-4718MEDIUM5.4IBM Jazz for Service Management 3.13 is vulnerable to cross-site scripting. This vulnerability allows users to embed arb...
CVE-2019-15510MEDIUM6.1ManageEngine_DesktopCentral.exe in Zoho ManageEngine Desktop Central 10 allows HTML injection on the user administration...
CVE-2019-18860MEDIUM6.1Squid before 4.9, when certain web browsers are used, mishandles HTML in the host (aka hostname) parameter to cachemgr.c...
CVE-2019-13463MEDIUM6.1An XSS vulnerability in qcopd-shortcode-generator.php in the Simple Link Directory plugin before 7.3.5 for WordPress all...
CVE-2019-13389MEDIUM6.1RainLoop Webmail before 1.13.0 lacks XSS protection mechanisms such as xlink:href validation, the X-XSS-Protection heade...
CVE-2019-16258MEDIUM6.8The bootloader of the homee Brain Cube V2 through 2.23.0 allows attackers with physical access to gain root access by ma...
CVE-2019-10221MEDIUM6.1A Reflected Cross Site Scripting vulnerability was found in all pki-core 10.x.x versions, where the pki-ca module from t...
CVE-2019-10179MEDIUM6.1A vulnerability was found in all pki-core 10.x.x versions, where the Key Recovery Authority (KRA) Agent Service did not ...
CVE-2019-19486MEDIUM6.5Local File Inclusion in minPlayCommand.php in Centreon (19.04.4 and below) allows an attacker to traverse paths via a pl...
CVE-2019-19484MEDIUM6.1Open redirect via parameter ‘p’ in login.php in Centreon (19.04.4 and below) allows an attacker to craft a payload and e...
CVE-2019-19026MEDIUM4.9Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows SQL Injection via project quotas in the VMware ...
CVE-2019-18782MEDIUM5.3SuiteCRM 7.10.x prior to 7.10.21 and 7.11.x prior to 7.11.9 does not correctly implement the .htaccess protection mechan...
CVE-2019-16529MEDIUM5.3An issue was discovered in the CheckUser extension through 1.35.0 for MediaWiki. Oversighted edit summaries are still vi...
CVE-2019-16069MEDIUM6.1A number of stored Cross-site Scripting (XSS) vulnerabilities were identified in NETSAS Enigma NMS 65.0.0 and prior that...
CVE-2019-15539MEDIUM6.1The proj_doc_edit_page.php Project Documentation feature in MantisBT before 2.21.3 has a stored cross-site scripting (XS...
CVE-2019-15124MEDIUM6.1In the MobileFrontend extension for MediaWiki, XSS exists within the edit summary field of the watchlist feed. This affe...
CVE-2019-20526MEDIUM6.1Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp password parameter.
CVE-2019-20525MEDIUM6.1Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp driver parameter.
CVE-2019-20521MEDIUM6.1ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the api/ URI.
CVE-2019-20520MEDIUM6.1ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the api/method/ URI.

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now