2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-20519MEDIUM6.1ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the user/ URI, as demonstrated by a crafted e-mail address.
CVE-2019-20518MEDIUM6.1ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the project/ URI.
CVE-2019-20517MEDIUM6.1ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the contact/ URI.
CVE-2019-20516MEDIUM6.1ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the blog/ URI.
CVE-2019-20515MEDIUM6.1ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the addresses/ URI.
CVE-2019-20514MEDIUM6.1ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the address/ URI.
CVE-2019-20513MEDIUM6.1Open edX Ironwood.1 allows support/certificates?user= reflected XSS.
CVE-2019-16375MEDIUM5.4An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.11, and Community Edition 5.0.x through 5...
CVE-2019-16070MEDIUM6.1A number of stored Cross-site Scripting (XSS) vulnerabilities were identified in NETSAS Enigma NMS 65.0.0 and prior that...
CVE-2019-16062MEDIUM6.5NETSAS Enigma NMS 65.0.0 and prior does not encrypt sensitive data stored within the SQL database. It is possible for an...
CVE-2019-16010MEDIUM4.8A vulnerability in the web UI of the Cisco SD-WAN vManage software could allow an authenticated, remote attacker to cond...
CVE-2019-14878MEDIUM6.5In the __d2b function of the newlib libc library, all versions prior to 3.3.0 (see newlib/libc/stdlib/mprec.c), Balloc i...
CVE-2019-14877MEDIUM6.5In the __mdiff function of the newlib libc library, all versions prior to 3.3.0 (see newlib/libc/stdlib/mprec.c), Balloc...
CVE-2019-14876MEDIUM6.5In the __lshift function of the newlib libc library, all versions prior to 3.3.0 (see newlib/libc/stdlib/mprec.c), Ballo...
CVE-2019-14875MEDIUM6.5In the __multiply function of the newlib libc library, all versions prior to 3.3.0 (see newlib/libc/stdlib/mprec.c), Bal...
CVE-2019-14874MEDIUM6.5In the __i2b function of the newlib libc library, all versions prior to 3.3.0 (see newlib/libc/stdlib/mprec.c), Balloc i...
CVE-2019-14873MEDIUM6.5In the __multadd function of the newlib libc library, prior to versions 3.3.0 (see newlib/libc/stdlib/mprec.c), Balloc i...
CVE-2019-12416MEDIUM6.1we got reports for 2 injection attacks against the DeltaSpike windowhandler.js. This is only active if a developer selec...
CVE-2019-20527MEDIUM6.1Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp serverURL parameter.
CVE-2019-20524MEDIUM6.1ilchCMS 2.1.23 allows XSS via the index.php/partner/index Banner parameter.
CVE-2019-20523MEDIUM6.1ilchCMS 2.1.23 allows XSS via the index.php/partner/index Name parameter.
CVE-2019-20522MEDIUM6.1ilchCMS 2.1.23 allows XSS via the index.php/partner/index Link parameter.
CVE-2019-19336MEDIUM6.1A cross-site scripting vulnerability was reported in the oVirt-engine's OAuth authorization endpoint before version 4.3....
CVE-2019-14872MEDIUM6.5The _dtoa_r function of the newlib libc library, prior to version 3.3.0, performs multiple memory allocations without ch...
CVE-2019-20485MEDIUM5.7qemu/qemu_driver.c in libvirt before 6.0.0 mishandles the holding of a monitor job during a query to a guest agent, whic...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now