2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-6810HIGH8.8CWE-284: Improper Access Control vulnerability exists in BMXNOR0200H Ethernet / Serial RTU module (all firmware versions...
CVE-2019-6809HIGH7.5A CWE-248: Uncaught Exception vulnerability exists in Modicon M580 (firmware versions prior to V2.90), Modicon M340 (fir...
CVE-2019-13538HIGH8.63S-Smart Software Solutions GmbH CODESYS V3 Library Manager, all versions prior to 3.5.16.0, allows the system to displa...
CVE-2019-11665HIGH7.5Data exposure in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51...
CVE-2019-4477MEDIUM6.5IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a user with access to audit logs to obtain sensitive...
CVE-2019-4442MEDIUM4.3IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9,0 could allow a remote attacker to traverse directories on the fil...
CVE-2019-4342MEDIUM5.4IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbit...
CVE-2019-4271LOW3.5IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Admin console is vulnerable to a Client-side HTTP parameter poll...
CVE-2019-4270MEDIUM5.4IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Admin Console is vulnerable to cross-site scripting. This vulner...
CVE-2019-4268MEDIUM5.3IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on the sys...
CVE-2019-4183HIGH7.5IBM Cognos Analytics 11.0, and 11.1 is vulnerable to a denial of service attack that could allow a remote user to send s...
CVE-2019-4175HIGH7.5IBM Cognos Controller 10.3.0, 10.3.1, 10.4.0, and 10.4.1 uses weaker than expected cryptographic algorithms that could a...
CVE-2019-4171LOW3.7IBM Cognos Controller 10.3.0, 10.3.1, 10.4.0, and 10.4.1 does not set the secure attribute on authorization tokens or se...
CVE-2019-4086MEDIUM6.1IBM Cloud Application Performance Management 8.1.4 could allow a remote attacker to hijack the clicking action of the vi...
CVE-2019-13542MEDIUM6.53S-Smart Software Solutions GmbH CODESYS V3 OPC UA Server, all versions 3.5.11.0 to 3.5.15.0, allows an attacker to send...
CVE-2019-11666HIGH8.8Insecure deserialization of untrusted data in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34,...
CVE-2019-11667HIGH7.5Unauthorized access to contact information in Micro Focus Service Manager, versions 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, ...
CVE-2019-9681MEDIUM5.3Online upgrade information in some firmware packages of Dahua products is not encrypted. Attackers can obtain this infor...
CVE-2019-9009HIGH7.5An issue was discovered in 3S-Smart CODESYS before 3.5.15.0 . Crafted network packets cause the Control Runtime to crash...
CVE-2019-14835HIGH7.8A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x, in the way Linux kernel's vhost functionality that t...
CVE-2019-14826MEDIUM4.4A flaw was found in FreeIPA versions 4.5.0 and later. Session cookies were retained in the cache after logout. An attack...
CVE-2019-12755MEDIUM5.5Norton Password Manager, prior to 6.5.0.2104, may be susceptible to an information disclosure issue, which is a type of ...
CVE-2019-15729HIGH7.5An issue was discovered in GitLab Community and Enterprise Edition 8.18 through 12.2.1. An internal endpoint unintention...
CVE-2019-11559MEDIUM6.1A reflected Cross-site scripting (XSS) vulnerability in HRworks V 1.16.1 allows remote attackers to inject arbitrary web...
CVE-2019-9008HIGH8.8An issue was discovered in 3S-Smart CODESYS V3 through 3.5.12.30. A user with low privileges can take full control over ...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now