2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-20479 | MEDIUM | 6.1 | 1.6% | Feb 20, 2020 | A flaw was found in mod_auth_openidc before version 2.4.1. An open redirect issue exists in URLs with a slash and backsl... |
| CVE-2019-17333 | MEDIUM | 5.4 | 0.7% | Feb 19, 2020 | The Web server component of TIBCO Software Inc.'s TIBCO EBX contains a vulnerability that theoretically allows authentic... |
| CVE-2019-10797 | MEDIUM | 6.5 | 1.2% | Feb 19, 2020 | Netty in WSO2 transport-http before v6.3.1 is vulnerable to HTTP Response Splitting due to HTTP Header validation being ... |
| CVE-2019-12246 | MEDIUM | 4.3 | 0.7% | Feb 19, 2020 | SilverStripe through 4.3.3 allows a Denial of Service on flush and development URL tools. |
| CVE-2019-4457 | MEDIUM | 6.5 | 0.9% | Feb 19, 2020 | IBM Jazz Foundation 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, and 6.0.6.1 could allow an authenticated user to obta... |
| CVE-2019-4429 | MEDIUM | 5.4 | 0.6% | Feb 19, 2020 | IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to em... |
| CVE-2019-10795 | MEDIUM | 6.3 | 1.1% | Feb 18, 2020 | undefsafe before 2.0.3 is vulnerable to Prototype Pollution. The 'a' function could be tricked into adding or modifying ... |
| CVE-2019-10794 | MEDIUM | 6.3 | 0.7% | Feb 18, 2020 | All versions of component-flatten are vulnerable to Prototype Pollution. The a function could be tricked into adding or ... |
| CVE-2019-10793 | MEDIUM | 6.3 | 1.1% | Feb 18, 2020 | dot-object before 2.1.3 is vulnerable to Prototype Pollution. The set function could be tricked into adding or modifying... |
| CVE-2019-10792 | MEDIUM | 6.3 | 1.0% | Feb 18, 2020 | bodymen before 1.1.1 is vulnerable to Prototype Pollution. The handler function could be tricked into adding or modifyin... |
| CVE-2019-19325 | MEDIUM | 6.1 | 0.7% | Feb 17, 2020 | SilverStripe through 4.4.x before 4.4.5 and 4.5.x before 4.5.2 allows Reflected XSS on the login form and custom forms. ... |
| CVE-2019-20474 | MEDIUM | 4.3 | 1.4% | Feb 17, 2020 | An issue was discovered in Zoho ManageEngine Remote Access Plus 10.0.447. The service to test the mail-server configurat... |
| CVE-2019-12954 | MEDIUM | 5.4 | 1.4% | Feb 17, 2020 | SolarWinds Network Performance Monitor (Orion Platform 2018, NPM 12.3, NetPath 1.1.3) allows XSS by authenticated users ... |
| CVE-2019-12825 | MEDIUM | 4.3 | 1.1% | Feb 17, 2020 | Unauthorized Access to the Container Registry of other groups was discovered in GitLab Enterprise 12.0.0-pre. In other w... |
| CVE-2019-15594 | MEDIUM | 4.3 | 0.8% | Feb 14, 2020 | GitLab 11.8 and later contains a security vulnerability that allows a user to obtain details of restricted pipelines via... |
| CVE-2019-15592 | MEDIUM | 4.3 | 1.0% | Feb 14, 2020 | GitLab 12.2.2 and below contains a security vulnerability that allows a guest user in a private project to see the merge... |
| CVE-2019-13966 | MEDIUM | 6.1 | 0.8% | Feb 14, 2020 | In iTop through 2.6.0, an XSS payload can be delivered in certain fields (such as icon) of the XML file used to build th... |
| CVE-2019-13965 | MEDIUM | 6.1 | 1.6% | Feb 14, 2020 | Because of a lack of sanitization around error messages, multiple Reflective XSS issues exist in iTop through 2.6.0 via ... |
| CVE-2019-6195 | MEDIUM | 4.8 | 0.6% | Feb 14, 2020 | An authorization bypass exists in Lenovo XClarity Controller (XCC) versions prior to 3.08 CDI340V, 3.01 TEI392O, 1.71 PS... |
| CVE-2019-6194 | MEDIUM | 5.5 | 0.7% | Feb 14, 2020 | An XML External Entity (XXE) processing vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prio... |
| CVE-2019-6190 | MEDIUM | 5.5 | 0.3% | Feb 14, 2020 | Lenovo was notified of a potential denial of service vulnerability, affecting various versions of BIOS for Lenovo Deskto... |
| CVE-2019-19758 | MEDIUM | 6.1 | 0.9% | Feb 14, 2020 | A vulnerability in the web interface of Lenovo EZ Media & Backup Center, ix2 & ix2-dl version 4.1.406.34763 and prior co... |
| CVE-2019-19757 | MEDIUM | 5.4 | 0.5% | Feb 14, 2020 | An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered a Document Object Model (DOM) base... |
| CVE-2019-20455 | MEDIUM | 5.9 | 1.0% | Feb 14, 2020 | Gateways/Gateway.php in Heartland & Global Payments PHP SDK before 2.0.0 does not enforce SSL certificate validations. |
| CVE-2019-3998 | MEDIUM | 5.5 | 0.4% | Feb 13, 2020 | Authentication bypass using an alternate path or channel in SimpliSafe SS3 firmware 1.4 allows a local, unauthenticated ... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now