2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-20105MEDIUM4.9The EditApplinkServlet resource in the Atlassian Application Links plugin before version 5.4.20, from version 6.0.0 befo...
CVE-2019-20491MEDIUM5.4cPanel before 82.0.18 allows attackers to leverage virtual mail accounts in order to bypass account suspensions (SEC-508...
CVE-2019-19852MEDIUM4.8An XSS Injection vulnerability exists in Sangoma FreePBX and PBXact 13, 14, and 15 within the Call Event Logging report ...
CVE-2019-19615MEDIUM4.8Multiple XSS vulnerabilities exist in the Backup & Restore module \ v14.0.10.2 through v14.0.10.7 for FreePBX, as shown ...
CVE-2019-19613MEDIUM5.2An issue was discovered in Halvotec RaQuest 10.23.10801.0. The login page of the admin application is vulnerable to an O...
CVE-2019-19612MEDIUM5.4An issue was discovered in Halvotec RaQuest 10.23.10801.0. Several features of the application allow stored Cross-site S...
CVE-2019-19610MEDIUM5.4An issue was discovered in Halvotec RaQuest 10.23.10801.0. It allows session fixation. Fixed in Release 24.2020.20608.0.
CVE-2019-19461MEDIUM5.4Post-authentication Stored XSS in Team Password Manager through 7.93.204 allows attackers to steal other users' credenti...
CVE-2019-18917MEDIUM6.5A potential security vulnerability has been identified for certain HP Printers and All-in-Ones that would allow bypassin...
CVE-2019-19946MEDIUM6.5The API in Dradis Pro 3.4.1 allows any user to extract the content of a project, even if this user is not part of the pr...
CVE-2019-4719MEDIUM5.5IBM MQ and IBM MQ Appliance 7.1, 7.5, 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD could allow a local attacker to obtain sensitive...
CVE-2019-4656MEDIUM6.5IBM MQ and IBM MQ Appliance 7.1, 7.5, 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD is vulnerable to a denial of service attack that...
CVE-2019-4619MEDIUM5.5IBM MQ and IBM MQ Appliance 7.1, 7.5, 8.0, 9.0 LTS, 9.1 LTS, and 9.1 CD could allow a local attacker to obtain sensitive...
CVE-2019-4617MEDIUM4.4IBM Cloud Automation Manager 3.2.1.0 does not renew a session variable after a successful authentication which could lea...
CVE-2019-19941MEDIUM5.4Missing hostname validation in Swisscom Centro Grande before 6.16.12 allows a remote attacker to inject its local IP add...
CVE-2019-19851MEDIUM4.8An XSS Injection vulnerability exists in Sangoma FreePBX and PBXact 13, 14, and 15 within the Debug/Test page of the Sup...
CVE-2019-19211MEDIUM6.1Dolibarr ERP/CRM before 10.0.3 has an Insufficient Filtering issue that can lead to user/card.php XSS.
CVE-2019-19210MEDIUM5.4Dolibarr ERP/CRM before 10.0.3 allows XSS because uploaded HTML documents are served as text/html despite being renamed ...
CVE-2019-14512MEDIUM6.1LimeSurvey 3.17.7+190627 has XSS via Boxes in application/extensions/PanelBoxWidget/views/box.php or a label title in ap...
CVE-2019-6696MEDIUM6.1An improper input validation vulnerability in FortiOS 6.2.1, 6.2.0, 6.0.8 and below until 5.4.0 under admin webUI may al...
CVE-2019-15708MEDIUM6.7A system command injection vulnerability in the FortiAP-S/W2 6.2.1, 6.2.0, 6.0.5 and below, FortiAP 6.0.5 and below and ...
CVE-2019-2088MEDIUM5.5In StatsService, there is a possible out of bounds read. This could lead to local information disclosure if UBSAN were n...
CVE-2019-2058MEDIUM6.5In libAACdec, there is a possible out of bounds read. This could lead to remote information disclosure, with no addition...
CVE-2019-15608MEDIUM5.9The package integrity validation in yarn < 1.19.0 contains a TOCTOU vulnerability where the hash is computed before writ...
CVE-2019-3770MEDIUM6.4Dell Wyse Management Suite versions prior to 1.4.1 contain a stored cross-site scripting vulnerability when unregisterin...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now