2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-0380MEDIUM4.9Under certain conditions, SAP Landscape Management enterprise edition, before version 3.0, allows custom secure paramete...
CVE-2019-0379MEDIUM5.3SAP Process Integration, business-to-business add-on, versions 1.0, 2.0, does not perform authentication check properly ...
CVE-2019-0378MEDIUM5.4SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before version 4.2, does not suffi...
CVE-2019-0377MEDIUM5.4SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2, does not suff...
CVE-2019-0376MEDIUM5.4SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2 and 4.3, does ...
CVE-2019-0375MEDIUM5.4SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2 and 4.3, does ...
CVE-2019-0374MEDIUM5.4SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2 and 4.3, does ...
CVE-2019-0370MEDIUM6.5Due to missing input validation, SAP Financial Consolidation, before versions 10.0 and 10.1, enables an attacker to use ...
CVE-2019-0369MEDIUM5.4SAP Financial Consolidation, before versions 10.0 and 10.1, does not sufficiently encode user-controlled inputs, which a...
CVE-2019-0368MEDIUM5.4SAP Customer Relationship Management (Email Management), versions: S4CRM before 1.0 and 2.0, BBPCRM before 7.0, 7.01, 7....
CVE-2019-0367MEDIUM4.3SAP NetWeaver Process Integration (B2B Toolkit), before versions 1.0 and 2.0, does not perform necessary authorization c...
CVE-2019-17186HIGH8.8/var/WEB-GUI/cgi-bin/telnet.cgi on FiberHome HG2201T 1.00.M5007_JS_201804 devices allows pre-authentication remote code ...
CVE-2019-14846HIGH7.8In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were l...
CVE-2019-14845MEDIUM5.3A vulnerability was found in OpenShift builds, versions 4.1 up to 4.3. Builds that extract source from a container image...
CVE-2019-10969HIGH7.2Moxa EDR 810, all versions 5.1 and prior, allows an authenticated attacker to abuse the ping feature to execute unauthor...
CVE-2019-10963MEDIUM4.3Moxa EDR 810, all versions 5.1 and prior, allows an unauthenticated attacker to be able to retrieve some log files from ...
CVE-2019-10756MEDIUM5.4It is possible to inject JavaScript within node-red-dashboard versions prior to version 2.17.0 due to the ui_notificatio...
CVE-2019-10215MEDIUM6.1Bootstrap-3-Typeahead after version 4.0.2 is vulnerable to a cross-site scripting flaw in the highlighter() function. An...
CVE-2019-17134CRITICAL9.1Amphora Images in OpenStack Octavia >=0.10.0 <2.1.2, >=3.0.0 <3.2.0, >=4.0.0 <4.1.0 allows anyone with access to the man...
CVE-2019-17187HIGH7.5/var/WEB-GUI/cgi-bin/downloadfile.cgi on FiberHome HG2201T 1.00.M5007_JS_201804 devices allows pre-authentication Direct...
CVE-2019-17105MEDIUM5.3The token generator in index.php in Centreon Web before 2.8.27 is predictable.
CVE-2019-17359HIGH7.5The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory allocation, and resulta...
CVE-2019-17352HIGH7.5In JFinal cos before 2019-08-13, as used in JFinal 4.4, there is a vulnerability that can bypass the isSafeFile() functi...
CVE-2019-17271MEDIUM4.9vBulletin 5.5.4 allows SQL Injection via the ajax/api/hook/getHookList or ajax/api/widget/getWidgetList where parameter.
CVE-2019-17108MEDIUM6.1Local file inclusion in brokerPerformance.php in Centreon Web before 2.8.28 allows attackers to disclose information or ...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now