2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-13422Search Guard Kibana Plugin versions before 5.6.8-7 and before 6.x.y-12 had an issue that an attacker can redirect the us...
CVE-2019-13421Search Guard versions before 23.1 had an issue that an administrative user is able to retrieve bcrypt password hashes of...
CVE-2019-11589The ChangeSharedFilterOwner resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from ve...
CVE-2019-11588The ViewSystemInfo class doGarbageCollection method in Jira before version 7.13.6, from version 8.0.0 before version 8.2...
CVE-2019-11587Various exposed resources of the ViewLogging class in Jira before version 7.13.6, from version 8.0.0 before version 8.2....
CVE-2019-11586The AddResolution.jspa resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version...
CVE-2019-11585The startup.jsp resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 ...
CVE-2019-11584The MigratePriorityScheme resource in Jira before version 8.3.2 allows remote attackers to inject arbitrary HTML or Java...
CVE-2019-15514The Privacy > Phone Number feature in the Telegram app 5.10 for Android and iOS provides an incorrect indication that th...
CVE-2019-15494openITCOCKPIT before 3.7.1 allows SSRF, aka RVID 5-445b21.
CVE-2019-15493openITCOCKPIT before 3.7.1 allows deletion of files, aka RVID 4-445b21.
CVE-2019-15492openITCOCKPIT before 3.7.1 has reflected XSS, aka RVID 3-445b21.
CVE-2019-15491openITCOCKPIT before 3.7.1 has CSRF, aka RVID 2-445b21.
CVE-2019-15490openITCOCKPIT before 3.7.1 allows code injection, aka RVID 1-445b21.
CVE-2019-15488Ignite Realtime Openfire before 4.4.1 has reflected XSS via an LDAP setup test.
CVE-2019-15487DfE School Experience before v16333-GA has XSS via a teacher training URL.
CVE-2019-15486django-js-reverse (aka Django JS Reverse) before 0.9.1 has XSS via js_reverse_inline.
CVE-2019-15485Bolt before 3.6.10 has XSS via createFolder or createFile in Controller/Async/FilesystemManager.php.
CVE-2019-15484Bolt before 3.6.10 has XSS via an image's alt or title field.
CVE-2019-15483Bolt before 3.6.10 has XSS via a title that is mishandled in the system log.
CVE-2019-15482selectize-plugin-a11y before 1.1.0 has XSS via the msg field.
CVE-2019-15481Kimai v2 before 1.1 has XSS via a timesheet description.
CVE-2019-15480Domoticz 4.10717 has XSS via item.Name.
CVE-2019-15477Jooby before 1.6.4 has XSS via the default error handler.
CVE-2019-15476Former before 4.2.1 has XSS via a checkbox value.

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now