2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-20519 | MEDIUM | 6.1 | 0.8% | Mar 19, 2020 | ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the user/ URI, as demonstrated by a crafted e-mail address. |
| CVE-2019-20518 | MEDIUM | 6.1 | 0.8% | Mar 19, 2020 | ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the project/ URI. |
| CVE-2019-20517 | MEDIUM | 6.1 | 0.8% | Mar 19, 2020 | ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the contact/ URI. |
| CVE-2019-20516 | MEDIUM | 6.1 | 0.8% | Mar 19, 2020 | ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the blog/ URI. |
| CVE-2019-20515 | MEDIUM | 6.1 | 0.8% | Mar 19, 2020 | ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the addresses/ URI. |
| CVE-2019-20514 | MEDIUM | 6.1 | 0.8% | Mar 19, 2020 | ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the address/ URI. |
| CVE-2019-20513 | MEDIUM | 6.1 | 0.5% | Mar 19, 2020 | Open edX Ironwood.1 allows support/certificates?user= reflected XSS. |
| CVE-2019-16375 | MEDIUM | 5.4 | 1.1% | Mar 19, 2020 | An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.11, and Community Edition 5.0.x through 5... |
| CVE-2019-16070 | MEDIUM | 6.1 | 0.7% | Mar 19, 2020 | A number of stored Cross-site Scripting (XSS) vulnerabilities were identified in NETSAS Enigma NMS 65.0.0 and prior that... |
| CVE-2019-16062 | MEDIUM | 6.5 | 0.8% | Mar 19, 2020 | NETSAS Enigma NMS 65.0.0 and prior does not encrypt sensitive data stored within the SQL database. It is possible for an... |
| CVE-2019-16010 | MEDIUM | 4.8 | 0.8% | Mar 19, 2020 | A vulnerability in the web UI of the Cisco SD-WAN vManage software could allow an authenticated, remote attacker to cond... |
| CVE-2019-14878 | MEDIUM | 6.5 | 1.3% | Mar 19, 2020 | In the __d2b function of the newlib libc library, all versions prior to 3.3.0 (see newlib/libc/stdlib/mprec.c), Balloc i... |
| CVE-2019-14877 | MEDIUM | 6.5 | 1.3% | Mar 19, 2020 | In the __mdiff function of the newlib libc library, all versions prior to 3.3.0 (see newlib/libc/stdlib/mprec.c), Balloc... |
| CVE-2019-14876 | MEDIUM | 6.5 | 1.3% | Mar 19, 2020 | In the __lshift function of the newlib libc library, all versions prior to 3.3.0 (see newlib/libc/stdlib/mprec.c), Ballo... |
| CVE-2019-14875 | MEDIUM | 6.5 | 1.3% | Mar 19, 2020 | In the __multiply function of the newlib libc library, all versions prior to 3.3.0 (see newlib/libc/stdlib/mprec.c), Bal... |
| CVE-2019-14874 | MEDIUM | 6.5 | 1.3% | Mar 19, 2020 | In the __i2b function of the newlib libc library, all versions prior to 3.3.0 (see newlib/libc/stdlib/mprec.c), Balloc i... |
| CVE-2019-14873 | MEDIUM | 6.5 | 1.3% | Mar 19, 2020 | In the __multadd function of the newlib libc library, prior to versions 3.3.0 (see newlib/libc/stdlib/mprec.c), Balloc i... |
| CVE-2019-12416 | MEDIUM | 6.1 | 2.6% | Mar 19, 2020 | we got reports for 2 injection attacks against the DeltaSpike windowhandler.js. This is only active if a developer selec... |
| CVE-2019-20527 | MEDIUM | 6.1 | 0.9% | Mar 19, 2020 | Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp serverURL parameter. |
| CVE-2019-20524 | MEDIUM | 6.1 | 0.7% | Mar 19, 2020 | ilchCMS 2.1.23 allows XSS via the index.php/partner/index Banner parameter. |
| CVE-2019-20523 | MEDIUM | 6.1 | 0.7% | Mar 19, 2020 | ilchCMS 2.1.23 allows XSS via the index.php/partner/index Name parameter. |
| CVE-2019-20522 | MEDIUM | 6.1 | 0.7% | Mar 19, 2020 | ilchCMS 2.1.23 allows XSS via the index.php/partner/index Link parameter. |
| CVE-2019-19336 | MEDIUM | 6.1 | 0.9% | Mar 19, 2020 | A cross-site scripting vulnerability was reported in the oVirt-engine's OAuth authorization endpoint before version 4.3.... |
| CVE-2019-14872 | MEDIUM | 6.5 | 1.5% | Mar 19, 2020 | The _dtoa_r function of the newlib libc library, prior to version 3.3.0, performs multiple memory allocations without ch... |
| CVE-2019-20485 | MEDIUM | 5.7 | 0.8% | Mar 19, 2020 | qemu/qemu_driver.c in libvirt before 6.0.0 mishandles the holding of a monitor job during a query to a guest agent, whic... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now