2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-20535 | MEDIUM | 6.2 | 0.1% | Mar 24, 2020 | An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) software. A connection to a new Bluetooth devic... |
| CVE-2019-20532 | MEDIUM | 5.3 | 0.4% | Mar 24, 2020 | An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Attackers can access the De... |
| CVE-2019-17276 | MEDIUM | 5.4 | 0.6% | Mar 24, 2020 | OnCommand System Manager versions 9.3 prior to 9.3P18 and 9.4 prior to 9.4P2 are susceptible to a cross site scripting v... |
| CVE-2019-4681 | MEDIUM | 6.1 | 0.7% | Mar 24, 2020 | IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 is vulnerable to cross-site scripting. This vulnerability allows user... |
| CVE-2019-20626 | MEDIUM | 6.5 | 0.7% | Mar 23, 2020 | The remote keyless system on Honda HR-V 2017 vehicles sends the same RF signal for each door-open request, which might a... |
| CVE-2019-4718 | MEDIUM | 5.4 | 0.7% | Mar 23, 2020 | IBM Jazz for Service Management 3.13 is vulnerable to cross-site scripting. This vulnerability allows users to embed arb... |
| CVE-2019-15510 | MEDIUM | 6.1 | 3.2% | Mar 23, 2020 | ManageEngine_DesktopCentral.exe in Zoho ManageEngine Desktop Central 10 allows HTML injection on the user administration... |
| CVE-2019-18860 | MEDIUM | 6.1 | 5.5% | Mar 20, 2020 | Squid before 4.9, when certain web browsers are used, mishandles HTML in the host (aka hostname) parameter to cachemgr.c... |
| CVE-2019-13463 | MEDIUM | 6.1 | 1.1% | Mar 20, 2020 | An XSS vulnerability in qcopd-shortcode-generator.php in the Simple Link Directory plugin before 7.3.5 for WordPress all... |
| CVE-2019-13389 | MEDIUM | 6.1 | 0.9% | Mar 20, 2020 | RainLoop Webmail before 1.13.0 lacks XSS protection mechanisms such as xlink:href validation, the X-XSS-Protection heade... |
| CVE-2019-16258 | MEDIUM | 6.8 | 0.3% | Mar 20, 2020 | The bootloader of the homee Brain Cube V2 through 2.23.0 allows attackers with physical access to gain root access by ma... |
| CVE-2019-10221 | MEDIUM | 6.1 | 1.3% | Mar 20, 2020 | A Reflected Cross Site Scripting vulnerability was found in all pki-core 10.x.x versions, where the pki-ca module from t... |
| CVE-2019-10179 | MEDIUM | 6.1 | 0.9% | Mar 20, 2020 | A vulnerability was found in all pki-core 10.x.x versions, where the Key Recovery Authority (KRA) Agent Service did not ... |
| CVE-2019-19486 | MEDIUM | 6.5 | 1.7% | Mar 20, 2020 | Local File Inclusion in minPlayCommand.php in Centreon (19.04.4 and below) allows an attacker to traverse paths via a pl... |
| CVE-2019-19484 | MEDIUM | 6.1 | 0.9% | Mar 20, 2020 | Open redirect via parameter ‘p’ in login.php in Centreon (19.04.4 and below) allows an attacker to craft a payload and e... |
| CVE-2019-19026 | MEDIUM | 4.9 | 1.4% | Mar 20, 2020 | Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows SQL Injection via project quotas in the VMware ... |
| CVE-2019-18782 | MEDIUM | 5.3 | 0.9% | Mar 20, 2020 | SuiteCRM 7.10.x prior to 7.10.21 and 7.11.x prior to 7.11.9 does not correctly implement the .htaccess protection mechan... |
| CVE-2019-16529 | MEDIUM | 5.3 | 0.9% | Mar 19, 2020 | An issue was discovered in the CheckUser extension through 1.35.0 for MediaWiki. Oversighted edit summaries are still vi... |
| CVE-2019-16069 | MEDIUM | 6.1 | 0.7% | Mar 19, 2020 | A number of stored Cross-site Scripting (XSS) vulnerabilities were identified in NETSAS Enigma NMS 65.0.0 and prior that... |
| CVE-2019-15539 | MEDIUM | 6.1 | 1.1% | Mar 19, 2020 | The proj_doc_edit_page.php Project Documentation feature in MantisBT before 2.21.3 has a stored cross-site scripting (XS... |
| CVE-2019-15124 | MEDIUM | 6.1 | 0.8% | Mar 19, 2020 | In the MobileFrontend extension for MediaWiki, XSS exists within the edit summary field of the watchlist feed. This affe... |
| CVE-2019-20526 | MEDIUM | 6.1 | 0.9% | Mar 19, 2020 | Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp password parameter. |
| CVE-2019-20525 | MEDIUM | 6.1 | 0.9% | Mar 19, 2020 | Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp driver parameter. |
| CVE-2019-20521 | MEDIUM | 6.1 | 0.8% | Mar 19, 2020 | ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the api/ URI. |
| CVE-2019-20520 | MEDIUM | 6.1 | 0.8% | Mar 19, 2020 | ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the api/method/ URI. |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now