2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-11278 | HIGH | 8.8 | 1.3% | Sep 26, 2019 | CF UAA versions prior to 74.1.0, allow external input to be directly queried against. A remote malicious user with 'clie... |
| CVE-2019-12562 | MEDIUM | 6.1 | 6.2% | Sep 26, 2019 | Stored Cross-Site Scripting in DotNetNuke (DNN) Version before 9.4.0 allows remote attackers to store and embed the mali... |
| CVE-2019-16667 | HIGH | 8.8 | 54.5% | Sep 26, 2019 | diag_command.php in pfSense 2.4.4-p3 allows CSRF via the txtCommand or txtRecallBuffer field, as demonstrated by executi... |
| CVE-2019-16915 | CRITICAL | 9.8 | 3.7% | Sep 26, 2019 | An issue was discovered in pfSense through 2.4.4-p3. widgets/widgets/picture.widget.php uses the widgetkey parameter dir... |
| CVE-2019-16914 | MEDIUM | 6.1 | 2.0% | Sep 26, 2019 | An XSS issue was discovered in pfSense through 2.4.4-p3. In services_captiveportal_mac.php, the username and delmac para... |
| CVE-2019-6175 | HIGH | 7.5 | 1.7% | Sep 26, 2019 | A denial of service vulnerability was reported in Lenovo System Update versions prior to 5.07.0088 that could allow conf... |
| CVE-2019-6161 | HIGH | 7.5 | 1.4% | Sep 26, 2019 | An internal product security audit discovered a session handling vulnerability in the web interface of ThinkAgile CP-SB ... |
| CVE-2019-16895 | — | — | — | Sep 26, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-16894. Reason: This candidate is a reservation d... |
| CVE-2019-16894 | CRITICAL | 9.8 | 3.0% | Sep 26, 2019 | download.php in inoERP 4.15 allows SQL injection through insecure deserialization. |
| CVE-2019-16869 | HIGH | 7.5 | 8.4% | Sep 26, 2019 | Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a "Transfer-Encoding : chunked... |
| CVE-2019-16755 | CRITICAL | 9.8 | 2.5% | Sep 26, 2019 | BMC Remedy ITSM Suite is prone to unspecified vulnerabilities in both DWP and SmartIT components, which can permit remot... |
| CVE-2019-16532 | MEDIUM | 6.1 | 1.2% | Sep 26, 2019 | An HTTP Host header injection vulnerability exists in YzmCMS V5.3. A malicious user can poison a web cache or trigger re... |
| CVE-2019-16524 | MEDIUM | 4.8 | 1.0% | Sep 26, 2019 | The easy-fancybox plugin before 1.8.18 for WordPress (aka Easy FancyBox) is susceptible to Stored XSS in the Settings Me... |
| CVE-2019-16409 | MEDIUM | 5.3 | 1.2% | Sep 26, 2019 | In the Versioned Files module through 2.0.3 for SilverStripe 3.x, unpublished versions of files are publicly exposed to ... |
| CVE-2019-13523 | MEDIUM | 5.3 | 1.8% | Sep 26, 2019 | In Honeywell Performance IP Cameras and Performance NVRs, the integrated web server of the affected devices could allow ... |
| CVE-2019-12091 | HIGH | 7.8 | 0.9% | Sep 26, 2019 | The Netskope client service, v57 before 57.2.0.219 and v60 before 60.2.0.214, running with NT\SYSTEM privilege, accepts ... |
| CVE-2019-10882 | HIGH | 7.8 | 0.4% | Sep 26, 2019 | The Netskope client service, v57 before 57.2.0.219 and v60 before 60.2.0.214, running with NT\SYSTEM privilege, accepts ... |
| CVE-2019-10097 | HIGH | 7.2 | 52.9% | Sep 26, 2019 | In Apache HTTP Server 2.4.32-2.4.39, when mod_remoteip was configured to use a trusted intermediary proxy server using t... |
| CVE-2019-10092 | MEDIUM | 6.1 | 81.5% | Sep 26, 2019 | In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page... |
| CVE-2019-10082 | CRITICAL | 9.1 | 16.5% | Sep 26, 2019 | In Apache HTTP Server 2.4.18-2.4.39, using fuzzed network input, the http/2 session handling could be made to read memor... |
| CVE-2019-0203 | HIGH | 7.5 | 3.4% | Sep 26, 2019 | In Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0, Subversion's svnserve server process may exit ... |
| CVE-2019-4378 | MEDIUM | 6.5 | 1.6% | Sep 26, 2019 | IBM MQ 7.5.0.0 - 7.5.0.9, 7.1.0.0 - 7.1.0.9, 8.0.0.0 - 8.0.0.12, 9.0.0.0 - 9.0.0.6, 9.1.0.0 - 9.1.0.2, and 9.1.0 - 9.1.2... |
| CVE-2019-4262 | MEDIUM | 5.3 | 1.0% | Sep 26, 2019 | IBM QRadar SIEM 7.2 and 7.3 is vulnerable to Server Side Request Forgery (SSRF). This may allow an unauthenticated attac... |
| CVE-2019-16910 | MEDIUM | 5.3 | 1.8% | Sep 26, 2019 | Arm Mbed TLS before 2.19.0 and Arm Mbed Crypto before 2.0.0, when deterministic ECDSA is enabled, use an RNG with insuff... |
| CVE-2019-16904 | MEDIUM | 5.4 | 0.7% | Sep 26, 2019 | TeamPass 2.1.27.36 allows Stored XSS by setting a crafted password for an item in a common available folder or sharing t... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now