2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-0355 | HIGH | 7.2 | 1.6% | Sep 10, 2019 | SAP NetWeaver Application Server Java Web Container, ENGINEAPI (before versions 7.10, 7.20, 7.30, 7.31, 7.40, 7.50) and ... |
| CVE-2019-0353 | LOW | 3.3 | 0.3% | Sep 10, 2019 | Under certain conditions SAP Business One client (B1_ON_HANA, SAP-M-BO), before versions 9.2 and 9.3, allows an attacker... |
| CVE-2019-0352 | HIGH | 7.5 | 1.1% | Sep 10, 2019 | In SAP Business Objects Business Intelligence Platform, before versions 4.1, 4.2 and 4.3, some dynamic pages (like jsp) ... |
| CVE-2019-5503 | MEDIUM | 5.3 | 0.7% | Sep 10, 2019 | OnCommand Workflow Automation versions prior to 5.0 shipped without certain HTTP Security headers configured which could... |
| CVE-2019-3975 | CRITICAL | 9.8 | 4.6% | Sep 10, 2019 | Stack-based buffer overflow in Advantech WebAccess/SCADA 8.4.1 allows a remote, unauthenticated attacker to execute arbi... |
| CVE-2019-16106 | HIGH | 7.5 | 1.1% | Sep 10, 2019 | The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to change the p... |
| CVE-2019-15896 | CRITICAL | 9.8 | 7.5% | Sep 10, 2019 | An issue was discovered in the LifterLMS plugin through 3.34.5 for WordPress. The upload_import function in the class.ll... |
| CVE-2019-14730 | MEDIUM | 4.3 | 1.5% | Sep 10, 2019 | In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to delete a... |
| CVE-2019-14729 | MEDIUM | 4.3 | 1.5% | Sep 10, 2019 | In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to delete a... |
| CVE-2019-14728 | MEDIUM | 4.3 | 1.5% | Sep 10, 2019 | In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to add an e... |
| CVE-2019-14727 | MEDIUM | 4.3 | 1.5% | Sep 10, 2019 | In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to change t... |
| CVE-2019-14726 | MEDIUM | 5.4 | 1.3% | Sep 10, 2019 | In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to access a... |
| CVE-2019-14723 | MEDIUM | 4.3 | 1.5% | Sep 10, 2019 | In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to delete a... |
| CVE-2019-14722 | MEDIUM | 4.3 | 1.5% | Sep 10, 2019 | In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to delete a... |
| CVE-2019-14721 | MEDIUM | 6.5 | 1.8% | Sep 10, 2019 | In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to remove a... |
| CVE-2019-12401 | HIGH | 7.5 | 7.5% | Sep 10, 2019 | Solr versions 1.3.0 to 1.4.1, 3.1.0 to 3.6.2 and 4.0.0 to 4.10.4 are vulnerable to an XML resource consumption attack (a... |
| CVE-2019-16202 | MEDIUM | 6.5 | 1.3% | Sep 10, 2019 | MISP before 2.4.115 allows privilege escalation in certain situations. After updating to 2.4.115, escalation attempts ar... |
| CVE-2019-7176 | LOW | 3.7 | 0.9% | Sep 9, 2019 | An issue was discovered in GitLab Community and Enterprise Edition 8.x (starting in 8.9), 9.x, 10.x, and 11.x before 11.... |
| CVE-2019-6791 | MEDIUM | 6.5 | 0.8% | Sep 9, 2019 | An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x befor... |
| CVE-2019-16192 | CRITICAL | 9.8 | 2.1% | Sep 9, 2019 | upload_model() in /admini/controllers/system/managemodel.php in DocCms 2016.5.17 allow remote attackers to execute arbit... |
| CVE-2019-16187 | HIGH | 7.5 | 1.4% | Sep 9, 2019 | Limesurvey before 3.17.14 uses an anti-CSRF cookie without the HttpOnly flag, which allows attackers to access a cookie ... |
| CVE-2019-16186 | HIGH | 7.2 | 1.3% | Sep 9, 2019 | In Limesurvey before 3.17.14, admin users can access the plugin manager without proper permissions. |
| CVE-2019-16185 | HIGH | 7.2 | 1.3% | Sep 9, 2019 | In Limesurvey before 3.17.14, admin users can view, update, or delete reserved menu entries without proper permissions. |
| CVE-2019-16184 | CRITICAL | 9.8 | 1.7% | Sep 9, 2019 | A CSV injection vulnerability was found in Limesurvey before 3.17.14 that allows survey participants to inject commands ... |
| CVE-2019-16183 | LOW | 2.7 | 0.8% | Sep 9, 2019 | In Limesurvey before 3.17.14, admin users can run an integrity check without proper permissions. |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now