2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-12432MEDIUM4.3An issue was discovered in GitLab Community and Enterprise Edition 8.13 through 11.11. Non-member users who subscribed t...
CVE-2019-12431MEDIUM4.3An issue was discovered in GitLab Community and Enterprise Edition 8.13 through 11.11. Restricted users could access the...
CVE-2019-12429MEDIUM6.5An issue was discovered in GitLab Community and Enterprise Edition 11.9 through 11.11. Unprivileged users were able to a...
CVE-2019-11345MEDIUM6.1Citrix SD-WAN Center 10.2.x before 10.2.1 and NetScaler SD-WAN Center 10.0.x before 10.0.7 allow XSS.
CVE-2019-11686MEDIUM5.5Western Digital SanDisk X300, X300s, X400, and X600 devices: A vulnerability in the wear-leveling algorithm of the drive...
CVE-2019-10706MEDIUM6.3Western Digital SanDisk SanDisk X300, X300s, X400, and X600 devices: The firmware update authentication method relies on...
CVE-2019-10065MEDIUM4.3An issue was discovered in Open Ticket Request System (OTRS) 7.0 through 7.0.6. An attacker who is logged into OTRS as a...
CVE-2019-4608MEDIUM5.4IBM Tivoli Workload Scheduler 9.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitr...
CVE-2019-10806MEDIUM4.3vega-util prior to 1.13.1 allows manipulation of object prototype. The 'vega.mergeConfig' method within vega-util could ...
CVE-2019-19773MEDIUM5.4Various Lexmark products have stored XSS in the embedded web server used in older generation Lexmark devices. Affected p...
CVE-2019-19772MEDIUM5.4Various Lexmark products have reflected XSS in the embedded web server used in older generation Lexmark devices. Affecte...
CVE-2019-20503MEDIUM6.5usrsctp before 2019-12-20 has out-of-bounds reads in sctp_load_addresses_from_init.
CVE-2019-14886MEDIUM6.5A vulnerability was found in business-central, as shipped in rhdm-7.5.1 and rhpam-7.5.1, where encoded passwords are sto...
CVE-2019-10616MEDIUM5.5Possibility of null pointer access if the SPDM commands are executed in the non-standard way in TZ. in Snapdragon Auto, ...
CVE-2019-19222MEDIUM5.4A Stored XSS issue in the D-Link DSL-2680 web administration interface (Firmware EU_1.03) allows an authenticated attack...
CVE-2019-19792MEDIUM6.7A permissions issue in ESET Cyber Security before 6.8.300.0 for macOS allows a local attacker to escalate privileges by ...
CVE-2019-17549MEDIUM6.5ESET Cyber Security before 6.8.1.0 is vulnerable to a denial-of-service allowing any user to stop (kill) ESET processes....
CVE-2019-19371MEDIUM6.1A cross-site scripting (XSS) vulnerability in the web conferencing component of Mitel MiCollab AWV before 8.1.2.2 could ...
CVE-2019-19370MEDIUM6.1A cross-site scripting (XSS) vulnerability in the web conferencing component of the Mitel MiCollab application before 9....
CVE-2019-18863MEDIUM5.9A key length vulnerability in the implementation of the SRTP 128-bit key on Mitel 6800 and 6900 SIP series phones, versi...
CVE-2019-20486MEDIUM6.1An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. Multiple pages (setup.cgi and adv_index.htm) within the w...
CVE-2019-18901MEDIUM5.5A UNIX Symbolic Link (Symlink) Following vulnerability in the mysql-systemd-helper of the mariadb packaging of SUSE Linu...
CVE-2019-4669MEDIUM6.3IBM Business Process Manager 8.5.7.0 through 8.5.7.0 2017.06, 8.6.0.0 through 8.6.0.0 CF2018.03, and IBM Business Automa...
CVE-2019-4726MEDIUM4.3IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 is vulnerable to cross-site request forgery which c...
CVE-2019-4598MEDIUM6.3IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 is vulnerable to SQL injection. A remote attacker c...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now