2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-8291HIGH7.5Online Store System v1.0 delete_file.php doesn't check to see if a user has administrative rights nor does it check for ...
CVE-2019-8290MEDIUM6.1Vulnerability in Online Store v1.0, The registration form requirements for the member email format can be bypassed by po...
CVE-2019-8289MEDIUM5.4Vulnerability in Online Store v1.0, stored XSS in admin/user_view.php adidas_member_email variable
CVE-2019-8288MEDIUM5.4Vulnerability in Online Store v1.0, Stored XSS in user_view.php where adidas_member_user variable is not sanitized.
CVE-2019-17074MEDIUM5.4An issue was discovered in XunRuiCMS 4.3.1. There is a stored XSS in the module_category area.
CVE-2019-17073MEDIUM6.5emlog through 6.0.0beta allows remote authenticated users to delete arbitrary files via admin/template.php?action=del&tp...
CVE-2019-15041MEDIUM6.1JetBrains YouTrack versions before 2019.1.52545 allowed unbounded URL whitelisting because of Inclusion of Functionality...
CVE-2019-15035MEDIUM4.9An issue was discovered in JetBrains TeamCity 2018.2.4. A TeamCity Project administrator could get access to potentially...
CVE-2019-0231HIGH7.5Handling of the close_notify SSL/TLS message does not lead to a connection closure, leading the server to retain the soc...
CVE-2019-7618MEDIUM6.5A local file disclosure flaw was found in Elastic Code versions 7.3.0, 7.3.1, and 7.3.2. If a malicious code repository ...
CVE-2019-17069HIGH7.5PuTTY before 0.73 might allow remote SSH-1 servers to cause a denial of service by accessing freed memory locations via ...
CVE-2019-17068HIGH7.5PuTTY before 0.73 mishandles the "bracketed paste mode" protection mechanism, which may allow a session to be affected b...
CVE-2019-17067CRITICAL9.8PuTTY before 0.73 on Windows improperly opens port-forwarding listening sockets, which allows attackers to listen on the...
CVE-2019-16943CRITICAL9.8A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is ena...
CVE-2019-16942CRITICAL9.8A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is ena...
CVE-2019-15042HIGH7.5An issue was discovered in JetBrains TeamCity 2018.2.4. It had no SSL certificate validation for some external https con...
CVE-2019-14961MEDIUM6.1JetBrains Upsource before 2019.1.1412 was not properly escaping HTML tags in a code block comments, leading to XSS.
CVE-2019-17064MEDIUM5.5Catalog.cc in Xpdf 4.02 has a NULL pointer dereference because Catalog.pageLabels is initialized too late in the Catalog...
CVE-2019-17063MEDIUM5.5In Snowtide PDFxStream before 3.7.1 (for Java), a crafted PDF file can trigger an extremely long running computation bec...
CVE-2019-15038HIGH7.5An issue was discovered in JetBrains TeamCity 2018.2.4. The TeamCity server was not using some security-related HTTP hea...
CVE-2019-14960HIGH7.8JetBrains Rider before 2019.1.2 was using an unsigned JetBrains.Rider.Unity.Editor.Plugin.Repacked.dll file.
CVE-2019-14957MEDIUM5.3The JetBrains Vim plugin before version 0.52 was storing individual project data in the global vim_settings.xml file. Th...
CVE-2019-14955MEDIUM5.3In JetBrains Hub versions earlier than 2018.4.11436, there was no option to force a user to change the password and no p...
CVE-2019-14953MEDIUM6.1JetBrains YouTrack versions before 2019.2.53938 had a possible XSS through issue attachments when using the Firefox brow...
CVE-2019-4497MEDIUM5.4IBM Jazz Reporting Service (JRS) 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, and 6.0.6.1 is vulnerable to cross-site ...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now