2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-8291 | HIGH | 7.5 | 1.4% | Oct 1, 2019 | Online Store System v1.0 delete_file.php doesn't check to see if a user has administrative rights nor does it check for ... |
| CVE-2019-8290 | MEDIUM | 6.1 | 1.2% | Oct 1, 2019 | Vulnerability in Online Store v1.0, The registration form requirements for the member email format can be bypassed by po... |
| CVE-2019-8289 | MEDIUM | 5.4 | 0.8% | Oct 1, 2019 | Vulnerability in Online Store v1.0, stored XSS in admin/user_view.php adidas_member_email variable |
| CVE-2019-8288 | MEDIUM | 5.4 | 0.8% | Oct 1, 2019 | Vulnerability in Online Store v1.0, Stored XSS in user_view.php where adidas_member_user variable is not sanitized. |
| CVE-2019-17074 | MEDIUM | 5.4 | 0.6% | Oct 1, 2019 | An issue was discovered in XunRuiCMS 4.3.1. There is a stored XSS in the module_category area. |
| CVE-2019-17073 | MEDIUM | 6.5 | 1.8% | Oct 1, 2019 | emlog through 6.0.0beta allows remote authenticated users to delete arbitrary files via admin/template.php?action=del&tp... |
| CVE-2019-15041 | MEDIUM | 6.1 | 1.0% | Oct 1, 2019 | JetBrains YouTrack versions before 2019.1.52545 allowed unbounded URL whitelisting because of Inclusion of Functionality... |
| CVE-2019-15035 | MEDIUM | 4.9 | 1.1% | Oct 1, 2019 | An issue was discovered in JetBrains TeamCity 2018.2.4. A TeamCity Project administrator could get access to potentially... |
| CVE-2019-0231 | HIGH | 7.5 | 2.2% | Oct 1, 2019 | Handling of the close_notify SSL/TLS message does not lead to a connection closure, leading the server to retain the soc... |
| CVE-2019-7618 | MEDIUM | 6.5 | 1.5% | Oct 1, 2019 | A local file disclosure flaw was found in Elastic Code versions 7.3.0, 7.3.1, and 7.3.2. If a malicious code repository ... |
| CVE-2019-17069 | HIGH | 7.5 | 2.2% | Oct 1, 2019 | PuTTY before 0.73 might allow remote SSH-1 servers to cause a denial of service by accessing freed memory locations via ... |
| CVE-2019-17068 | HIGH | 7.5 | 1.8% | Oct 1, 2019 | PuTTY before 0.73 mishandles the "bracketed paste mode" protection mechanism, which may allow a session to be affected b... |
| CVE-2019-17067 | CRITICAL | 9.8 | 1.6% | Oct 1, 2019 | PuTTY before 0.73 on Windows improperly opens port-forwarding listening sockets, which allows attackers to listen on the... |
| CVE-2019-16943 | CRITICAL | 9.8 | 4.9% | Oct 1, 2019 | A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is ena... |
| CVE-2019-16942 | CRITICAL | 9.8 | 5.7% | Oct 1, 2019 | A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is ena... |
| CVE-2019-15042 | HIGH | 7.5 | 0.7% | Oct 1, 2019 | An issue was discovered in JetBrains TeamCity 2018.2.4. It had no SSL certificate validation for some external https con... |
| CVE-2019-14961 | MEDIUM | 6.1 | 0.8% | Oct 1, 2019 | JetBrains Upsource before 2019.1.1412 was not properly escaping HTML tags in a code block comments, leading to XSS. |
| CVE-2019-17064 | MEDIUM | 5.5 | 1.4% | Oct 1, 2019 | Catalog.cc in Xpdf 4.02 has a NULL pointer dereference because Catalog.pageLabels is initialized too late in the Catalog... |
| CVE-2019-17063 | MEDIUM | 5.5 | 0.8% | Oct 1, 2019 | In Snowtide PDFxStream before 3.7.1 (for Java), a crafted PDF file can trigger an extremely long running computation bec... |
| CVE-2019-15038 | HIGH | 7.5 | 1.1% | Oct 1, 2019 | An issue was discovered in JetBrains TeamCity 2018.2.4. The TeamCity server was not using some security-related HTTP hea... |
| CVE-2019-14960 | HIGH | 7.8 | 0.3% | Oct 1, 2019 | JetBrains Rider before 2019.1.2 was using an unsigned JetBrains.Rider.Unity.Editor.Plugin.Repacked.dll file. |
| CVE-2019-14957 | MEDIUM | 5.3 | 1.1% | Oct 1, 2019 | The JetBrains Vim plugin before version 0.52 was storing individual project data in the global vim_settings.xml file. Th... |
| CVE-2019-14955 | MEDIUM | 5.3 | 0.9% | Oct 1, 2019 | In JetBrains Hub versions earlier than 2018.4.11436, there was no option to force a user to change the password and no p... |
| CVE-2019-14953 | MEDIUM | 6.1 | 0.9% | Oct 1, 2019 | JetBrains YouTrack versions before 2019.2.53938 had a possible XSS through issue attachments when using the Firefox brow... |
| CVE-2019-4497 | MEDIUM | 5.4 | 0.7% | Oct 1, 2019 | IBM Jazz Reporting Service (JRS) 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, and 6.0.6.1 is vulnerable to cross-site ... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now