2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-20105 | MEDIUM | 4.9 | 1.5% | Mar 17, 2020 | The EditApplinkServlet resource in the Atlassian Application Links plugin before version 5.4.20, from version 6.0.0 befo... |
| CVE-2019-20491 | MEDIUM | 5.4 | 0.7% | Mar 16, 2020 | cPanel before 82.0.18 allows attackers to leverage virtual mail accounts in order to bypass account suspensions (SEC-508... |
| CVE-2019-19852 | MEDIUM | 4.8 | 0.6% | Mar 16, 2020 | An XSS Injection vulnerability exists in Sangoma FreePBX and PBXact 13, 14, and 15 within the Call Event Logging report ... |
| CVE-2019-19615 | MEDIUM | 4.8 | 0.6% | Mar 16, 2020 | Multiple XSS vulnerabilities exist in the Backup & Restore module \ v14.0.10.2 through v14.0.10.7 for FreePBX, as shown ... |
| CVE-2019-19613 | MEDIUM | 5.2 | 0.5% | Mar 16, 2020 | An issue was discovered in Halvotec RaQuest 10.23.10801.0. The login page of the admin application is vulnerable to an O... |
| CVE-2019-19612 | MEDIUM | 5.4 | 0.7% | Mar 16, 2020 | An issue was discovered in Halvotec RaQuest 10.23.10801.0. Several features of the application allow stored Cross-site S... |
| CVE-2019-19610 | MEDIUM | 5.4 | 0.9% | Mar 16, 2020 | An issue was discovered in Halvotec RaQuest 10.23.10801.0. It allows session fixation. Fixed in Release 24.2020.20608.0. |
| CVE-2019-19461 | MEDIUM | 5.4 | 0.5% | Mar 16, 2020 | Post-authentication Stored XSS in Team Password Manager through 7.93.204 allows attackers to steal other users' credenti... |
| CVE-2019-18917 | MEDIUM | 6.5 | 1.5% | Mar 16, 2020 | A potential security vulnerability has been identified for certain HP Printers and All-in-Ones that would allow bypassin... |
| CVE-2019-19946 | MEDIUM | 6.5 | 1.2% | Mar 16, 2020 | The API in Dradis Pro 3.4.1 allows any user to extract the content of a project, even if this user is not part of the pr... |
| CVE-2019-4719 | MEDIUM | 5.5 | 0.3% | Mar 16, 2020 | IBM MQ and IBM MQ Appliance 7.1, 7.5, 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD could allow a local attacker to obtain sensitive... |
| CVE-2019-4656 | MEDIUM | 6.5 | 1.6% | Mar 16, 2020 | IBM MQ and IBM MQ Appliance 7.1, 7.5, 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD is vulnerable to a denial of service attack that... |
| CVE-2019-4619 | MEDIUM | 5.5 | 0.3% | Mar 16, 2020 | IBM MQ and IBM MQ Appliance 7.1, 7.5, 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD could allow a local attacker to obtain sensitive... |
| CVE-2019-4617 | MEDIUM | 4.4 | 0.3% | Mar 16, 2020 | IBM Cloud Automation Manager 3.2.1.0 does not renew a session variable after a successful authentication which could lea... |
| CVE-2019-19941 | MEDIUM | 5.4 | 0.7% | Mar 16, 2020 | Missing hostname validation in Swisscom Centro Grande before 6.16.12 allows a remote attacker to inject its local IP add... |
| CVE-2019-19851 | MEDIUM | 4.8 | 0.5% | Mar 16, 2020 | An XSS Injection vulnerability exists in Sangoma FreePBX and PBXact 13, 14, and 15 within the Debug/Test page of the Sup... |
| CVE-2019-19211 | MEDIUM | 6.1 | 1.7% | Mar 16, 2020 | Dolibarr ERP/CRM before 10.0.3 has an Insufficient Filtering issue that can lead to user/card.php XSS. |
| CVE-2019-19210 | MEDIUM | 5.4 | 0.9% | Mar 16, 2020 | Dolibarr ERP/CRM before 10.0.3 allows XSS because uploaded HTML documents are served as text/html despite being renamed ... |
| CVE-2019-14512 | MEDIUM | 6.1 | 1.0% | Mar 16, 2020 | LimeSurvey 3.17.7+190627 has XSS via Boxes in application/extensions/PanelBoxWidget/views/box.php or a label title in ap... |
| CVE-2019-6696 | MEDIUM | 6.1 | 0.7% | Mar 15, 2020 | An improper input validation vulnerability in FortiOS 6.2.1, 6.2.0, 6.0.8 and below until 5.4.0 under admin webUI may al... |
| CVE-2019-15708 | MEDIUM | 6.7 | 0.6% | Mar 15, 2020 | A system command injection vulnerability in the FortiAP-S/W2 6.2.1, 6.2.0, 6.0.5 and below, FortiAP 6.0.5 and below and ... |
| CVE-2019-2088 | MEDIUM | 5.5 | 0.1% | Mar 15, 2020 | In StatsService, there is a possible out of bounds read. This could lead to local information disclosure if UBSAN were n... |
| CVE-2019-2058 | MEDIUM | 6.5 | 0.7% | Mar 15, 2020 | In libAACdec, there is a possible out of bounds read. This could lead to remote information disclosure, with no addition... |
| CVE-2019-15608 | MEDIUM | 5.9 | 1.8% | Mar 15, 2020 | The package integrity validation in yarn < 1.19.0 contains a TOCTOU vulnerability where the hash is computed before writ... |
| CVE-2019-3770 | MEDIUM | 6.4 | 0.7% | Mar 13, 2020 | Dell Wyse Management Suite versions prior to 1.4.1 contain a stored cross-site scripting vulnerability when unregisterin... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now