2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-6810 | HIGH | 8.8 | 1.7% | Sep 17, 2019 | CWE-284: Improper Access Control vulnerability exists in BMXNOR0200H Ethernet / Serial RTU module (all firmware versions... |
| CVE-2019-6809 | HIGH | 7.5 | 1.8% | Sep 17, 2019 | A CWE-248: Uncaught Exception vulnerability exists in Modicon M580 (firmware versions prior to V2.90), Modicon M340 (fir... |
| CVE-2019-13538 | HIGH | 8.6 | 0.9% | Sep 17, 2019 | 3S-Smart Software Solutions GmbH CODESYS V3 Library Manager, all versions prior to 3.5.16.0, allows the system to displa... |
| CVE-2019-11665 | HIGH | 7.5 | 1.1% | Sep 17, 2019 | Data exposure in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51... |
| CVE-2019-4477 | MEDIUM | 6.5 | 1.3% | Sep 17, 2019 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a user with access to audit logs to obtain sensitive... |
| CVE-2019-4442 | MEDIUM | 4.3 | 2.1% | Sep 17, 2019 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9,0 could allow a remote attacker to traverse directories on the fil... |
| CVE-2019-4342 | MEDIUM | 5.4 | 1.0% | Sep 17, 2019 | IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbit... |
| CVE-2019-4271 | LOW | 3.5 | 0.8% | Sep 17, 2019 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Admin console is vulnerable to a Client-side HTTP parameter poll... |
| CVE-2019-4270 | MEDIUM | 5.4 | 0.7% | Sep 17, 2019 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Admin Console is vulnerable to cross-site scripting. This vulner... |
| CVE-2019-4268 | MEDIUM | 5.3 | 2.7% | Sep 17, 2019 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on the sys... |
| CVE-2019-4183 | HIGH | 7.5 | 3.5% | Sep 17, 2019 | IBM Cognos Analytics 11.0, and 11.1 is vulnerable to a denial of service attack that could allow a remote user to send s... |
| CVE-2019-4175 | HIGH | 7.5 | 1.0% | Sep 17, 2019 | IBM Cognos Controller 10.3.0, 10.3.1, 10.4.0, and 10.4.1 uses weaker than expected cryptographic algorithms that could a... |
| CVE-2019-4171 | LOW | 3.7 | 0.6% | Sep 17, 2019 | IBM Cognos Controller 10.3.0, 10.3.1, 10.4.0, and 10.4.1 does not set the secure attribute on authorization tokens or se... |
| CVE-2019-4086 | MEDIUM | 6.1 | 1.2% | Sep 17, 2019 | IBM Cloud Application Performance Management 8.1.4 could allow a remote attacker to hijack the clicking action of the vi... |
| CVE-2019-13542 | MEDIUM | 6.5 | 1.4% | Sep 17, 2019 | 3S-Smart Software Solutions GmbH CODESYS V3 OPC UA Server, all versions 3.5.11.0 to 3.5.15.0, allows an attacker to send... |
| CVE-2019-11666 | HIGH | 8.8 | 1.2% | Sep 17, 2019 | Insecure deserialization of untrusted data in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34,... |
| CVE-2019-11667 | HIGH | 7.5 | 1.1% | Sep 17, 2019 | Unauthorized access to contact information in Micro Focus Service Manager, versions 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, ... |
| CVE-2019-9681 | MEDIUM | 5.3 | 0.8% | Sep 17, 2019 | Online upgrade information in some firmware packages of Dahua products is not encrypted. Attackers can obtain this infor... |
| CVE-2019-9009 | HIGH | 7.5 | 1.7% | Sep 17, 2019 | An issue was discovered in 3S-Smart CODESYS before 3.5.15.0 . Crafted network packets cause the Control Runtime to crash... |
| CVE-2019-14835 | HIGH | 7.8 | 0.6% | Sep 17, 2019 | A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x, in the way Linux kernel's vhost functionality that t... |
| CVE-2019-14826 | MEDIUM | 4.4 | 0.3% | Sep 17, 2019 | A flaw was found in FreeIPA versions 4.5.0 and later. Session cookies were retained in the cache after logout. An attack... |
| CVE-2019-12755 | MEDIUM | 5.5 | 0.3% | Sep 17, 2019 | Norton Password Manager, prior to 6.5.0.2104, may be susceptible to an information disclosure issue, which is a type of ... |
| CVE-2019-15729 | HIGH | 7.5 | 1.7% | Sep 17, 2019 | An issue was discovered in GitLab Community and Enterprise Edition 8.18 through 12.2.1. An internal endpoint unintention... |
| CVE-2019-11559 | MEDIUM | 6.1 | 1.1% | Sep 17, 2019 | A reflected Cross-site scripting (XSS) vulnerability in HRworks V 1.16.1 allows remote attackers to inject arbitrary web... |
| CVE-2019-9008 | HIGH | 8.8 | 1.9% | Sep 17, 2019 | An issue was discovered in 3S-Smart CODESYS V3 through 3.5.12.30. A user with low privileges can take full control over ... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now