2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-19677 | MEDIUM | 4.3 | 0.7% | Mar 18, 2020 | arxes-tolina 3.0.0 allows User Enumeration. |
| CVE-2019-20528 | MEDIUM | 6.1 | 0.9% | Mar 18, 2020 | Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp username parameter. |
| CVE-2019-20512 | MEDIUM | 6.1 | 0.4% | Mar 18, 2020 | Open edX Ironwood.1 allows support/certificates?course_id= reflected XSS. |
| CVE-2019-20511 | MEDIUM | 6.1 | 0.7% | Mar 18, 2020 | ERPNext 11.1.47 allows blog?blog_category= Frame Injection. |
| CVE-2019-12921 | MEDIUM | 6.5 | 8.0% | Mar 18, 2020 | In GraphicsMagick before 1.3.32, the text filename component allows remote attackers to read arbitrary files via a craft... |
| CVE-2019-12370 | MEDIUM | 6.1 | 1.1% | Mar 18, 2020 | The Spark application through 2.0.2 for Android allows XSS via an event attribute and arbitrary file loading via a src a... |
| CVE-2019-12369 | MEDIUM | 6.1 | 1.0% | Mar 18, 2020 | The TypeApp application through 1.9.5.35 for Android allows XSS via an event attribute and arbitrary file loading via a ... |
| CVE-2019-12368 | MEDIUM | 6.1 | 1.0% | Mar 18, 2020 | The Edison Mail application through 1.7.1 for Android allows XSS via an event attribute and arbitrary file loading via a... |
| CVE-2019-12367 | MEDIUM | 6.1 | 1.0% | Mar 18, 2020 | The BlueMail application through 1.9.5.36 for Android allows XSS via an event attribute and arbitrary file loading via a... |
| CVE-2019-12366 | MEDIUM | 6.1 | 1.0% | Mar 18, 2020 | The Nine application through 4.5.3a for Android allows XSS via an event attribute and arbitrary file loading via a src a... |
| CVE-2019-12365 | MEDIUM | 6.1 | 1.0% | Mar 18, 2020 | The Newton application through 10.0.23 for Android allows XSS via an event attribute and arbitrary file loading via a sr... |
| CVE-2019-12122 | MEDIUM | 6.5 | 0.6% | Mar 18, 2020 | An issue was discovered in ONAP Portal through Dublin. By executing a call to ONAPPORTAL/portalApi/loggedinUser, an atta... |
| CVE-2019-19335 | MEDIUM | 4.4 | 0.3% | Mar 18, 2020 | During installation of an OpenShift 4 cluster, the `openshift-install` command line tool creates an `auth` directory, wi... |
| CVE-2019-14871 | MEDIUM | 6.5 | 1.0% | Mar 18, 2020 | The REENT_CHECK macro (see newlib/libc/include/sys/reent.h) as used by REENT_CHECK_TM, REENT_CHECK_MISC, REENT_CHECK_MP ... |
| CVE-2019-10178 | MEDIUM | 6.1 | 1.0% | Mar 18, 2020 | It was found that the Token Processing Service (TPS) did not properly sanitize the Token IDs from the "Activity" page, e... |
| CVE-2019-10146 | MEDIUM | 4.7 | 0.7% | Mar 18, 2020 | A Reflected Cross Site Scripting flaw was found in all pki-core 10.x.x versions module from the pki-core server due to t... |
| CVE-2019-14884 | MEDIUM | 6.1 | 0.9% | Mar 18, 2020 | A vulnerability was found in Moodle 3.7 before 3.73, 3.6 before 3.6.7 and 3.5 before 3.5.9, where a reflected XSS possib... |
| CVE-2019-14883 | MEDIUM | 5.3 | 1.1% | Mar 18, 2020 | A vulnerability was found in Moodle 3.6 before 3.6.7 and 3.7 before 3.7.3, where tokens used to fetch inline atachments ... |
| CVE-2019-14882 | MEDIUM | 6.1 | 1.1% | Mar 18, 2020 | A vulnerability was found in Moodle 3.7 to 3.7.3, 3.6 to 3.6.7, 3.5 to 3.5.9 and earlier where an open redirect existed ... |
| CVE-2019-14881 | MEDIUM | 6.1 | 1.1% | Mar 18, 2020 | A vulnerability was found in moodle 3.7 before 3.7.3, where there is blind XSS reflected in some locations where user em... |
| CVE-2019-20497 | MEDIUM | 5.4 | 0.6% | Mar 17, 2020 | cPanel before 82.0.18 allows stored XSS via WHM Backup Restoration (SEC-533). |
| CVE-2019-20496 | MEDIUM | 5.5 | 0.3% | Mar 17, 2020 | cPanel before 82.0.18 allows attackers to conduct arbitrary chown operations as root during log processing (SEC-532). |
| CVE-2019-20495 | MEDIUM | 6.5 | 1.0% | Mar 17, 2020 | cPanel before 82.0.18 allows attackers to read an arbitrary database via MySQL dump streaming (SEC-531). |
| CVE-2019-20493 | MEDIUM | 6.1 | 0.7% | Mar 17, 2020 | cPanel before 82.0.18 allows self-XSS because JSON string escaping is mishandled (SEC-520). |
| CVE-2019-20407 | MEDIUM | 4.3 | 1.2% | Mar 17, 2020 | The ConfigureBambooRelease resource in Jira Software and Jira Software Data Center before version 8.6.1 allows authentic... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now