2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-20479MEDIUM6.1A flaw was found in mod_auth_openidc before version 2.4.1. An open redirect issue exists in URLs with a slash and backsl...
CVE-2019-17333MEDIUM5.4The Web server component of TIBCO Software Inc.'s TIBCO EBX contains a vulnerability that theoretically allows authentic...
CVE-2019-10797MEDIUM6.5Netty in WSO2 transport-http before v6.3.1 is vulnerable to HTTP Response Splitting due to HTTP Header validation being ...
CVE-2019-12246MEDIUM4.3SilverStripe through 4.3.3 allows a Denial of Service on flush and development URL tools.
CVE-2019-4457MEDIUM6.5IBM Jazz Foundation 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, and 6.0.6.1 could allow an authenticated user to obta...
CVE-2019-4429MEDIUM5.4IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to em...
CVE-2019-10795MEDIUM6.3undefsafe before 2.0.3 is vulnerable to Prototype Pollution. The 'a' function could be tricked into adding or modifying ...
CVE-2019-10794MEDIUM6.3All versions of component-flatten are vulnerable to Prototype Pollution. The a function could be tricked into adding or ...
CVE-2019-10793MEDIUM6.3dot-object before 2.1.3 is vulnerable to Prototype Pollution. The set function could be tricked into adding or modifying...
CVE-2019-10792MEDIUM6.3bodymen before 1.1.1 is vulnerable to Prototype Pollution. The handler function could be tricked into adding or modifyin...
CVE-2019-19325MEDIUM6.1SilverStripe through 4.4.x before 4.4.5 and 4.5.x before 4.5.2 allows Reflected XSS on the login form and custom forms. ...
CVE-2019-20474MEDIUM4.3An issue was discovered in Zoho ManageEngine Remote Access Plus 10.0.447. The service to test the mail-server configurat...
CVE-2019-12954MEDIUM5.4SolarWinds Network Performance Monitor (Orion Platform 2018, NPM 12.3, NetPath 1.1.3) allows XSS by authenticated users ...
CVE-2019-12825MEDIUM4.3Unauthorized Access to the Container Registry of other groups was discovered in GitLab Enterprise 12.0.0-pre. In other w...
CVE-2019-15594MEDIUM4.3GitLab 11.8 and later contains a security vulnerability that allows a user to obtain details of restricted pipelines via...
CVE-2019-15592MEDIUM4.3GitLab 12.2.2 and below contains a security vulnerability that allows a guest user in a private project to see the merge...
CVE-2019-13966MEDIUM6.1In iTop through 2.6.0, an XSS payload can be delivered in certain fields (such as icon) of the XML file used to build th...
CVE-2019-13965MEDIUM6.1Because of a lack of sanitization around error messages, multiple Reflective XSS issues exist in iTop through 2.6.0 via ...
CVE-2019-6195MEDIUM4.8An authorization bypass exists in Lenovo XClarity Controller (XCC) versions prior to 3.08 CDI340V, 3.01 TEI392O, 1.71 PS...
CVE-2019-6194MEDIUM5.5An XML External Entity (XXE) processing vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prio...
CVE-2019-6190MEDIUM5.5Lenovo was notified of a potential denial of service vulnerability, affecting various versions of BIOS for Lenovo Deskto...
CVE-2019-19758MEDIUM6.1A vulnerability in the web interface of Lenovo EZ Media & Backup Center, ix2 & ix2-dl version 4.1.406.34763 and prior co...
CVE-2019-19757MEDIUM5.4An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered a Document Object Model (DOM) base...
CVE-2019-20455MEDIUM5.9Gateways/Gateway.php in Heartland & Global Payments PHP SDK before 2.0.0 does not enforce SSL certificate validations.
CVE-2019-3998MEDIUM5.5Authentication bypass using an alternate path or channel in SimpliSafe SS3 firmware 1.4 allows a local, unauthenticated ...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now