2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-12432 | MEDIUM | 4.3 | 0.8% | Mar 10, 2020 | An issue was discovered in GitLab Community and Enterprise Edition 8.13 through 11.11. Non-member users who subscribed t... |
| CVE-2019-12431 | MEDIUM | 4.3 | 0.8% | Mar 10, 2020 | An issue was discovered in GitLab Community and Enterprise Edition 8.13 through 11.11. Restricted users could access the... |
| CVE-2019-12429 | MEDIUM | 6.5 | 0.9% | Mar 10, 2020 | An issue was discovered in GitLab Community and Enterprise Edition 11.9 through 11.11. Unprivileged users were able to a... |
| CVE-2019-11345 | MEDIUM | 6.1 | 0.8% | Mar 10, 2020 | Citrix SD-WAN Center 10.2.x before 10.2.1 and NetScaler SD-WAN Center 10.0.x before 10.0.7 allow XSS. |
| CVE-2019-11686 | MEDIUM | 5.5 | 0.2% | Mar 10, 2020 | Western Digital SanDisk X300, X300s, X400, and X600 devices: A vulnerability in the wear-leveling algorithm of the drive... |
| CVE-2019-10706 | MEDIUM | 6.3 | 0.3% | Mar 10, 2020 | Western Digital SanDisk SanDisk X300, X300s, X400, and X600 devices: The firmware update authentication method relies on... |
| CVE-2019-10065 | MEDIUM | 4.3 | 0.8% | Mar 10, 2020 | An issue was discovered in Open Ticket Request System (OTRS) 7.0 through 7.0.6. An attacker who is logged into OTRS as a... |
| CVE-2019-4608 | MEDIUM | 5.4 | 0.7% | Mar 10, 2020 | IBM Tivoli Workload Scheduler 9.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitr... |
| CVE-2019-10806 | MEDIUM | 4.3 | 1.1% | Mar 9, 2020 | vega-util prior to 1.13.1 allows manipulation of object prototype. The 'vega.mergeConfig' method within vega-util could ... |
| CVE-2019-19773 | MEDIUM | 5.4 | 0.7% | Mar 6, 2020 | Various Lexmark products have stored XSS in the embedded web server used in older generation Lexmark devices. Affected p... |
| CVE-2019-19772 | MEDIUM | 5.4 | 0.7% | Mar 6, 2020 | Various Lexmark products have reflected XSS in the embedded web server used in older generation Lexmark devices. Affecte... |
| CVE-2019-20503 | MEDIUM | 6.5 | 3.2% | Mar 6, 2020 | usrsctp before 2019-12-20 has out-of-bounds reads in sctp_load_addresses_from_init. |
| CVE-2019-14886 | MEDIUM | 6.5 | 0.3% | Mar 5, 2020 | A vulnerability was found in business-central, as shipped in rhdm-7.5.1 and rhpam-7.5.1, where encoded passwords are sto... |
| CVE-2019-10616 | MEDIUM | 5.5 | 0.2% | Mar 5, 2020 | Possibility of null pointer access if the SPDM commands are executed in the non-standard way in TZ. in Snapdragon Auto, ... |
| CVE-2019-19222 | MEDIUM | 5.4 | 1.9% | Mar 4, 2020 | A Stored XSS issue in the D-Link DSL-2680 web administration interface (Firmware EU_1.03) allows an authenticated attack... |
| CVE-2019-19792 | MEDIUM | 6.7 | 0.4% | Mar 3, 2020 | A permissions issue in ESET Cyber Security before 6.8.300.0 for macOS allows a local attacker to escalate privileges by ... |
| CVE-2019-17549 | MEDIUM | 6.5 | 1.2% | Mar 3, 2020 | ESET Cyber Security before 6.8.1.0 is vulnerable to a denial-of-service allowing any user to stop (kill) ESET processes.... |
| CVE-2019-19371 | MEDIUM | 6.1 | 1.0% | Mar 2, 2020 | A cross-site scripting (XSS) vulnerability in the web conferencing component of Mitel MiCollab AWV before 8.1.2.2 could ... |
| CVE-2019-19370 | MEDIUM | 6.1 | 1.0% | Mar 2, 2020 | A cross-site scripting (XSS) vulnerability in the web conferencing component of the Mitel MiCollab application before 9.... |
| CVE-2019-18863 | MEDIUM | 5.9 | 0.5% | Mar 2, 2020 | A key length vulnerability in the implementation of the SRTP 128-bit key on Mitel 6800 and 6900 SIP series phones, versi... |
| CVE-2019-20486 | MEDIUM | 6.1 | 0.7% | Mar 2, 2020 | An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. Multiple pages (setup.cgi and adv_index.htm) within the w... |
| CVE-2019-18901 | MEDIUM | 5.5 | 0.4% | Mar 2, 2020 | A UNIX Symbolic Link (Symlink) Following vulnerability in the mysql-systemd-helper of the mariadb packaging of SUSE Linu... |
| CVE-2019-4669 | MEDIUM | 6.3 | 0.8% | Feb 27, 2020 | IBM Business Process Manager 8.5.7.0 through 8.5.7.0 2017.06, 8.6.0.0 through 8.6.0.0 CF2018.03, and IBM Business Automa... |
| CVE-2019-4726 | MEDIUM | 4.3 | 0.5% | Feb 26, 2020 | IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 is vulnerable to cross-site request forgery which c... |
| CVE-2019-4598 | MEDIUM | 6.3 | 0.8% | Feb 26, 2020 | IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 is vulnerable to SQL injection. A remote attacker c... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now