2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-4597 | MEDIUM | 6.3 | 0.8% | Feb 26, 2020 | IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 is vulnerable to SQL injection. A remote attacker c... |
| CVE-2019-4596 | MEDIUM | 5.4 | 0.6% | Feb 26, 2020 | IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 is vulnerable to cross-site scripting. This vulnera... |
| CVE-2019-4537 | MEDIUM | 5.3 | 1.1% | Feb 26, 2020 | IBM WebSphere Service Registry and Repository 8.5 could allow a user to obtain sensitive version information that could ... |
| CVE-2019-19993 | MEDIUM | 5.3 | 1.2% | Feb 26, 2020 | An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. Several full path disclosure vulnera... |
| CVE-2019-19992 | MEDIUM | 6.5 | 1.1% | Feb 26, 2020 | An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. A user with valid credentials is abl... |
| CVE-2019-19991 | MEDIUM | 5.4 | 0.9% | Feb 26, 2020 | An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. Multiple Reflected Cross-site script... |
| CVE-2019-19990 | MEDIUM | 5.4 | 0.9% | Feb 26, 2020 | An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. Multiple Stored Cross-site scripting... |
| CVE-2019-19987 | MEDIUM | 6.5 | 0.5% | Feb 26, 2020 | An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. It allows Cross-Site Request Forgery... |
| CVE-2019-19134 | MEDIUM | 6.1 | 5.7% | Feb 26, 2020 | The Hero Maps Premium plugin 2.2.1 and prior for WordPress is prone to unauthenticated XSS via the views/dashboard/index... |
| CVE-2019-12863 | MEDIUM | 4.8 | 1.1% | Feb 25, 2020 | SolarWinds Orion Platform 2018.4 HF3 (NPM 12.4, NetPath 1.1.4) allows Stored HTML Injection by administrators via the We... |
| CVE-2019-4672 | MEDIUM | 5.3 | 1.4% | Feb 25, 2020 | IBM QRadar Advisor 1.1 through 2.5 could allow an unauthorized attacker to obtain sensitive information from specially c... |
| CVE-2019-17569 | MEDIUM | 4.8 | 8.9% | Feb 24, 2020 | The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression... |
| CVE-2019-17229 | MEDIUM | 6.1 | 1.4% | Feb 24, 2020 | includes/options.php in the motors-car-dealership-classified-listings (aka Motors - Car Dealer & Classified Ads) plugin ... |
| CVE-2019-17228 | MEDIUM | 6.5 | 1.2% | Feb 24, 2020 | includes/options.php in the motors-car-dealership-classified-listings (aka Motors - Car Dealer & Classified Ads) plugin ... |
| CVE-2019-12513 | MEDIUM | 6.1 | 0.8% | Feb 24, 2020 | In NETGEAR Nighthawk X10-R900 prior to 1.0.4.24, by sending a DHCP discover request containing a malicious hostname fiel... |
| CVE-2019-12512 | MEDIUM | 6.1 | 0.9% | Feb 24, 2020 | In NETGEAR Nighthawk X10-R900 prior to 1.0.4.24, an attacker may execute stored XSS attacks against this device by suppl... |
| CVE-2019-10798 | MEDIUM | 5.3 | 1.0% | Feb 24, 2020 | rdf-graph-array through 0.3.0-rc6 manipulation of JavaScript objects resutling in Prototype Pollution. The rdf.Graph.pro... |
| CVE-2019-4745 | MEDIUM | 4.3 | 0.9% | Feb 24, 2020 | IBM Maximo Asset Management 7.6.1.0 could allow a remote attacker to disclose sensitive information to an authenticated ... |
| CVE-2019-4703 | MEDIUM | 5.3 | 0.5% | Feb 24, 2020 | IBM Spectrum Protect Plus 10.1.0 and 10.5.0, when protecting Microsoft SQL or Microsoft Exchange, could allow an attacke... |
| CVE-2019-4595 | MEDIUM | 6.1 | 0.7% | Feb 24, 2020 | IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 could allow a remote attacker to conduct phishing a... |
| CVE-2019-3670 | MEDIUM | 6.1 | 1.2% | Feb 24, 2020 | Remote Code Execution vulnerability in the web interface in McAfee Web Advisor (WA) 8.0.34745 and earlier allows remote ... |
| CVE-2019-18846 | MEDIUM | 5 | 0.9% | Feb 21, 2020 | OX App Suite through 7.10.2 allows SSRF. |
| CVE-2019-19865 | MEDIUM | 6.1 | 0.6% | Feb 21, 2020 | Atos Unify OpenScape UC Application V9 before version V9 R4.31.0 and V10 before version V10 R0.6.0 allows XSS. An attack... |
| CVE-2019-19694 | MEDIUM | 4.7 | 0.4% | Feb 20, 2020 | The Trend Micro Security 2019 (15.0.0.1163 and below) consumer family of products is vulnerable to a denial of service (... |
| CVE-2019-4583 | MEDIUM | 4.3 | 1.0% | Feb 20, 2020 | IBM Maximo Asset Management 7.6.0.10 and 7.6.1.1 could allow an authenticated user to obtain sensitive information from ... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now