2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-0355HIGH7.2SAP NetWeaver Application Server Java Web Container, ENGINEAPI (before versions 7.10, 7.20, 7.30, 7.31, 7.40, 7.50) and ...
CVE-2019-0353LOW3.3Under certain conditions SAP Business One client (B1_ON_HANA, SAP-M-BO), before versions 9.2 and 9.3, allows an attacker...
CVE-2019-0352HIGH7.5In SAP Business Objects Business Intelligence Platform, before versions 4.1, 4.2 and 4.3, some dynamic pages (like jsp) ...
CVE-2019-5503MEDIUM5.3OnCommand Workflow Automation versions prior to 5.0 shipped without certain HTTP Security headers configured which could...
CVE-2019-3975CRITICAL9.8Stack-based buffer overflow in Advantech WebAccess/SCADA 8.4.1 allows a remote, unauthenticated attacker to execute arbi...
CVE-2019-16106HIGH7.5The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to change the p...
CVE-2019-15896CRITICAL9.8An issue was discovered in the LifterLMS plugin through 3.34.5 for WordPress. The upload_import function in the class.ll...
CVE-2019-14730MEDIUM4.3In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to delete a...
CVE-2019-14729MEDIUM4.3In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to delete a...
CVE-2019-14728MEDIUM4.3In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to add an e...
CVE-2019-14727MEDIUM4.3In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to change t...
CVE-2019-14726MEDIUM5.4In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to access a...
CVE-2019-14723MEDIUM4.3In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to delete a...
CVE-2019-14722MEDIUM4.3In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to delete a...
CVE-2019-14721MEDIUM6.5In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to remove a...
CVE-2019-12401HIGH7.5Solr versions 1.3.0 to 1.4.1, 3.1.0 to 3.6.2 and 4.0.0 to 4.10.4 are vulnerable to an XML resource consumption attack (a...
CVE-2019-16202MEDIUM6.5MISP before 2.4.115 allows privilege escalation in certain situations. After updating to 2.4.115, escalation attempts ar...
CVE-2019-7176LOW3.7An issue was discovered in GitLab Community and Enterprise Edition 8.x (starting in 8.9), 9.x, 10.x, and 11.x before 11....
CVE-2019-6791MEDIUM6.5An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x befor...
CVE-2019-16192CRITICAL9.8upload_model() in /admini/controllers/system/managemodel.php in DocCms 2016.5.17 allow remote attackers to execute arbit...
CVE-2019-16187HIGH7.5Limesurvey before 3.17.14 uses an anti-CSRF cookie without the HttpOnly flag, which allows attackers to access a cookie ...
CVE-2019-16186HIGH7.2In Limesurvey before 3.17.14, admin users can access the plugin manager without proper permissions.
CVE-2019-16185HIGH7.2In Limesurvey before 3.17.14, admin users can view, update, or delete reserved menu entries without proper permissions.
CVE-2019-16184CRITICAL9.8A CSV injection vulnerability was found in Limesurvey before 3.17.14 that allows survey participants to inject commands ...
CVE-2019-16183LOW2.7In Limesurvey before 3.17.14, admin users can run an integrity check without proper permissions.

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now