2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-14598MEDIUM6.7Improper Authentication in subsystem in Intel(R) CSME versions 12.0 through 12.0.48 (IOT only: 12.0.56), versions 13.0 t...
CVE-2019-10785MEDIUM6.1dojox is vulnerable to Cross-site Scripting in all versions before version 1.16.1, 1.15.2, 1.14.5, 1.13.6, 1.12.7 and 1....
CVE-2019-18791MEDIUM5.4Lexmark printer MS812 and multiple older generation Lexmark devices have a stored XSS vulnerability in the embedded web ...
CVE-2019-14652MEDIUM6.1explorer.js in Amazon AWS JavaScript S3 Explorer (aka aws-js-s3-explorer) v2 alpha before 2019-08-02 allows XSS in certa...
CVE-2019-19192MEDIUM6.5The Bluetooth Low Energy implementation on STMicroelectronics BLE Stack through 1.3.1 for STM32WB5x devices does not pro...
CVE-2019-16336MEDIUM6.5The Bluetooth Low Energy implementation in Cypress PSoC 4 BLE component 3.61 and earlier processes data channel frames w...
CVE-2019-11867MEDIUM5.5Realtek NDIS driver rt640x64.sys, file version 10.1.505.2015, fails to do any size checking on an input buffer from user...
CVE-2019-4741MEDIUM5.3IBM Content Navigator 3.0CD is vulnerable to Server Side Request Forgery (SSRF). This may allow an unauthenticated attac...
CVE-2019-4431MEDIUM5.4IBM Rational Publishing Engine 6.0.6 and 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users ...
CVE-2019-19196MEDIUM6.5The Bluetooth Low Energy Secure Manager Protocol (SMP) implementation on Telink Semiconductor BLE SDK versions before No...
CVE-2019-20100MEDIUM4.7The Atlassian Application Links plugin is vulnerable to cross-site request forgery (CSRF). The following versions are af...
CVE-2019-20099MEDIUM4.3The VerifyPopServerConnection!add.jspa component in Atlassian Jira Server and Data Center before version 8.7.0 is vulner...
CVE-2019-20098MEDIUM4.3The VerifySmtpServerConnection!add.jspa component in Atlassian Jira Server and Data Center before version 8.7.0 is vulne...
CVE-2019-13924MEDIUM5.4A vulnerability has been identified in SCALANCE S602 (All versions < V4.1), SCALANCE S612 (All versions < V4.1), SCALANC...
CVE-2019-18210MEDIUM5.4Persistent XSS in /course/modedit.php of Moodle through 3.7.2 allows authenticated users (Teacher and above) to inject J...
CVE-2019-6744MEDIUM4.3This vulnerability allows local attackers to disclose sensitive information on affected installations of Samsung Knox 1....
CVE-2019-19195MEDIUM6.5The Bluetooth Low Energy implementation on Microchip Technology BluSDK Smart through 6.2 for ATSAMB11 devices does not p...
CVE-2019-19193MEDIUM6.5The Bluetooth Low Energy peripheral implementation on Texas Instruments SIMPLELINK-CC2640R2-SDK through 3.30.00.20 and B...
CVE-2019-17520MEDIUM6.5The Bluetooth Low Energy implementation on Texas Instruments SDK through 3.30.00.20 for CC2640R2 devices does not proper...
CVE-2019-17518MEDIUM6.5The Bluetooth Low Energy implementation on Dialog Semiconductor SDK through 1.0.14.1081 for DA1468x devices responds to ...
CVE-2019-17517MEDIUM5.7The Bluetooth Low Energy implementation on Dialog Semiconductor SDK through 5.0.4 for DA14580/1/2/3 devices does not pro...
CVE-2019-17061MEDIUM6.5The Bluetooth Low Energy (BLE) stack implementation on Cypress PSoC 4 through 3.62 devices does not properly restrict th...
CVE-2019-17060MEDIUM6.5The Bluetooth Low Energy (BLE) stack implementation on the NXP KW41Z (based on the MCUXpresso SDK with Bluetooth Low Ene...
CVE-2019-19668MEDIUM4.3A CSRF vulnerability exists in the File Types component of Web File Manager in Rumpus FTP 8.2.9.1 that allows an attacke...
CVE-2019-19670MEDIUM6.1A HTTP Response Splitting vulnerability was identified in the Web Settings Component of Web File Manager in Rumpus FTP S...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now