2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-19677MEDIUM4.3arxes-tolina 3.0.0 allows User Enumeration.
CVE-2019-20528MEDIUM6.1Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp username parameter.
CVE-2019-20512MEDIUM6.1Open edX Ironwood.1 allows support/certificates?course_id= reflected XSS.
CVE-2019-20511MEDIUM6.1ERPNext 11.1.47 allows blog?blog_category= Frame Injection.
CVE-2019-12921MEDIUM6.5In GraphicsMagick before 1.3.32, the text filename component allows remote attackers to read arbitrary files via a craft...
CVE-2019-12370MEDIUM6.1The Spark application through 2.0.2 for Android allows XSS via an event attribute and arbitrary file loading via a src a...
CVE-2019-12369MEDIUM6.1The TypeApp application through 1.9.5.35 for Android allows XSS via an event attribute and arbitrary file loading via a ...
CVE-2019-12368MEDIUM6.1The Edison Mail application through 1.7.1 for Android allows XSS via an event attribute and arbitrary file loading via a...
CVE-2019-12367MEDIUM6.1The BlueMail application through 1.9.5.36 for Android allows XSS via an event attribute and arbitrary file loading via a...
CVE-2019-12366MEDIUM6.1The Nine application through 4.5.3a for Android allows XSS via an event attribute and arbitrary file loading via a src a...
CVE-2019-12365MEDIUM6.1The Newton application through 10.0.23 for Android allows XSS via an event attribute and arbitrary file loading via a sr...
CVE-2019-12122MEDIUM6.5An issue was discovered in ONAP Portal through Dublin. By executing a call to ONAPPORTAL/portalApi/loggedinUser, an atta...
CVE-2019-19335MEDIUM4.4During installation of an OpenShift 4 cluster, the `openshift-install` command line tool creates an `auth` directory, wi...
CVE-2019-14871MEDIUM6.5The REENT_CHECK macro (see newlib/libc/include/sys/reent.h) as used by REENT_CHECK_TM, REENT_CHECK_MISC, REENT_CHECK_MP ...
CVE-2019-10178MEDIUM6.1It was found that the Token Processing Service (TPS) did not properly sanitize the Token IDs from the "Activity" page, e...
CVE-2019-10146MEDIUM4.7A Reflected Cross Site Scripting flaw was found in all pki-core 10.x.x versions module from the pki-core server due to t...
CVE-2019-14884MEDIUM6.1A vulnerability was found in Moodle 3.7 before 3.73, 3.6 before 3.6.7 and 3.5 before 3.5.9, where a reflected XSS possib...
CVE-2019-14883MEDIUM5.3A vulnerability was found in Moodle 3.6 before 3.6.7 and 3.7 before 3.7.3, where tokens used to fetch inline atachments ...
CVE-2019-14882MEDIUM6.1A vulnerability was found in Moodle 3.7 to 3.7.3, 3.6 to 3.6.7, 3.5 to 3.5.9 and earlier where an open redirect existed ...
CVE-2019-14881MEDIUM6.1A vulnerability was found in moodle 3.7 before 3.7.3, where there is blind XSS reflected in some locations where user em...
CVE-2019-20497MEDIUM5.4cPanel before 82.0.18 allows stored XSS via WHM Backup Restoration (SEC-533).
CVE-2019-20496MEDIUM5.5cPanel before 82.0.18 allows attackers to conduct arbitrary chown operations as root during log processing (SEC-532).
CVE-2019-20495MEDIUM6.5cPanel before 82.0.18 allows attackers to read an arbitrary database via MySQL dump streaming (SEC-531).
CVE-2019-20493MEDIUM6.1cPanel before 82.0.18 allows self-XSS because JSON string escaping is mishandled (SEC-520).
CVE-2019-20407MEDIUM4.3The ConfigureBambooRelease resource in Jira Software and Jira Software Data Center before version 8.6.1 allows authentic...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now