2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-0380 | MEDIUM | 4.9 | 0.9% | Oct 8, 2019 | Under certain conditions, SAP Landscape Management enterprise edition, before version 3.0, allows custom secure paramete... |
| CVE-2019-0379 | MEDIUM | 5.3 | 0.8% | Oct 8, 2019 | SAP Process Integration, business-to-business add-on, versions 1.0, 2.0, does not perform authentication check properly ... |
| CVE-2019-0378 | MEDIUM | 5.4 | 0.5% | Oct 8, 2019 | SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before version 4.2, does not suffi... |
| CVE-2019-0377 | MEDIUM | 5.4 | 0.5% | Oct 8, 2019 | SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2, does not suff... |
| CVE-2019-0376 | MEDIUM | 5.4 | 0.5% | Oct 8, 2019 | SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2 and 4.3, does ... |
| CVE-2019-0375 | MEDIUM | 5.4 | 0.7% | Oct 8, 2019 | SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2 and 4.3, does ... |
| CVE-2019-0374 | MEDIUM | 5.4 | 0.7% | Oct 8, 2019 | SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface), before versions 4.2 and 4.3, does ... |
| CVE-2019-0370 | MEDIUM | 6.5 | 0.7% | Oct 8, 2019 | Due to missing input validation, SAP Financial Consolidation, before versions 10.0 and 10.1, enables an attacker to use ... |
| CVE-2019-0369 | MEDIUM | 5.4 | 0.5% | Oct 8, 2019 | SAP Financial Consolidation, before versions 10.0 and 10.1, does not sufficiently encode user-controlled inputs, which a... |
| CVE-2019-0368 | MEDIUM | 5.4 | 0.5% | Oct 8, 2019 | SAP Customer Relationship Management (Email Management), versions: S4CRM before 1.0 and 2.0, BBPCRM before 7.0, 7.01, 7.... |
| CVE-2019-0367 | MEDIUM | 4.3 | 0.5% | Oct 8, 2019 | SAP NetWeaver Process Integration (B2B Toolkit), before versions 1.0 and 2.0, does not perform necessary authorization c... |
| CVE-2019-17186 | HIGH | 8.8 | 5.9% | Oct 8, 2019 | /var/WEB-GUI/cgi-bin/telnet.cgi on FiberHome HG2201T 1.00.M5007_JS_201804 devices allows pre-authentication remote code ... |
| CVE-2019-14846 | HIGH | 7.8 | 0.5% | Oct 8, 2019 | In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were l... |
| CVE-2019-14845 | MEDIUM | 5.3 | 0.4% | Oct 8, 2019 | A vulnerability was found in OpenShift builds, versions 4.1 up to 4.3. Builds that extract source from a container image... |
| CVE-2019-10969 | HIGH | 7.2 | 8.7% | Oct 8, 2019 | Moxa EDR 810, all versions 5.1 and prior, allows an authenticated attacker to abuse the ping feature to execute unauthor... |
| CVE-2019-10963 | MEDIUM | 4.3 | 6.3% | Oct 8, 2019 | Moxa EDR 810, all versions 5.1 and prior, allows an unauthenticated attacker to be able to retrieve some log files from ... |
| CVE-2019-10756 | MEDIUM | 5.4 | 0.6% | Oct 8, 2019 | It is possible to inject JavaScript within node-red-dashboard versions prior to version 2.17.0 due to the ui_notificatio... |
| CVE-2019-10215 | MEDIUM | 6.1 | 1.5% | Oct 8, 2019 | Bootstrap-3-Typeahead after version 4.0.2 is vulnerable to a cross-site scripting flaw in the highlighter() function. An... |
| CVE-2019-17134 | CRITICAL | 9.1 | 2.3% | Oct 8, 2019 | Amphora Images in OpenStack Octavia >=0.10.0 <2.1.2, >=3.0.0 <3.2.0, >=4.0.0 <4.1.0 allows anyone with access to the man... |
| CVE-2019-17187 | HIGH | 7.5 | 10.8% | Oct 8, 2019 | /var/WEB-GUI/cgi-bin/downloadfile.cgi on FiberHome HG2201T 1.00.M5007_JS_201804 devices allows pre-authentication Direct... |
| CVE-2019-17105 | MEDIUM | 5.3 | 1.6% | Oct 8, 2019 | The token generator in index.php in Centreon Web before 2.8.27 is predictable. |
| CVE-2019-17359 | HIGH | 7.5 | 8.9% | Oct 8, 2019 | The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory allocation, and resulta... |
| CVE-2019-17352 | HIGH | 7.5 | 1.7% | Oct 8, 2019 | In JFinal cos before 2019-08-13, as used in JFinal 4.4, there is a vulnerability that can bypass the isSafeFile() functi... |
| CVE-2019-17271 | MEDIUM | 4.9 | 1.4% | Oct 8, 2019 | vBulletin 5.5.4 allows SQL Injection via the ajax/api/hook/getHookList or ajax/api/widget/getWidgetList where parameter. |
| CVE-2019-17108 | MEDIUM | 6.1 | 1.2% | Oct 8, 2019 | Local file inclusion in brokerPerformance.php in Centreon Web before 2.8.28 allows attackers to disclose information or ... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now