2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-19669 | MEDIUM | 6.5 | 0.4% | Feb 10, 2020 | A CSRF vulnerability exists in the Upload Center Forms Component of Web File Manager in Rumpus FTP 8.2.9.1. This could a... |
| CVE-2019-19667 | MEDIUM | 5.4 | 0.4% | Feb 10, 2020 | A CSRF vulnerability exists in the Block Clients component of Web File Manager in Rumpus FTP 8.2.9.1 that could allow an... |
| CVE-2019-19666 | MEDIUM | 4.3 | 0.4% | Feb 10, 2020 | A CSRF vulnerability exists in the Event Notices Settings of Web File Manager in Rumpus FTP 8.2.9.1. An attacker can cre... |
| CVE-2019-19661 | MEDIUM | 6.1 | 0.8% | Feb 10, 2020 | A Cookie based reflected XSS exists in the Web File Manager of Rumpus FTP Server 8.2.9.1, related to RumpusLoginUserName... |
| CVE-2019-19662 | MEDIUM | 6.5 | 0.4% | Feb 10, 2020 | A CSRF vulnerability exists in the Web File Manager's Create/Delete Accounts functionality of Rumpus FTP Server 8.2.9.1.... |
| CVE-2019-19665 | MEDIUM | 6.5 | 0.4% | Feb 10, 2020 | A CSRF vulnerability exists in the FTP Settings of Web File Manager in Rumpus FTP 8.2.9.1. Exploitation of this vulnerab... |
| CVE-2019-19663 | MEDIUM | 6.5 | 0.4% | Feb 10, 2020 | A CSRF vulnerability exists in the Folder Sets Settings of Web File Manager in Rumpus FTP 8.2.9.1. This allows an attack... |
| CVE-2019-19660 | MEDIUM | 6.5 | 0.4% | Feb 10, 2020 | A CSRF vulnerability exists in the Web File Manager's Network Setting functionality of Rumpus FTP Server 8.2.9.1. By exp... |
| CVE-2019-11482 | MEDIUM | 4.7 | 0.2% | Feb 8, 2020 | Sander Bos discovered a time of check to time of use (TOCTTOU) vulnerability in apport that allowed a user to cause core... |
| CVE-2019-13163 | MEDIUM | 5.9 | 0.6% | Feb 7, 2020 | The Fujitsu TLS library allows a man-in-the-middle attack. This affects Interstage Application Development Cycle Manager... |
| CVE-2019-19800 | MEDIUM | 5.3 | 3.9% | Feb 6, 2020 | Zoho ManageEngine Applications Manager 14 before 14520 allows a remote unauthenticated attacker to disclose OS file name... |
| CVE-2019-12426 | MEDIUM | 5.3 | 4.9% | Feb 6, 2020 | an unauthenticated user could get access to information of some backend screens by invoking setSessionLocale in Apache O... |
| CVE-2019-17652 | MEDIUM | 6.5 | 1.4% | Feb 6, 2020 | A stack buffer overflow vulnerability in FortiClient for Linux 6.2.1 and below may allow a user with low privilege to ca... |
| CVE-2019-16152 | MEDIUM | 6.5 | 1.4% | Feb 6, 2020 | A Denial of service (DoS) vulnerability in FortiClient for Linux 6.2.1 and below may allow an user with low privilege to... |
| CVE-2019-20405 | MEDIUM | 4.3 | 0.6% | Feb 6, 2020 | The JMX monitoring flag in Atlassian Jira Server and Data Center before version 8.6.0 allows remote attackers to turn th... |
| CVE-2019-20404 | MEDIUM | 4.3 | 1.3% | Feb 6, 2020 | The API in Atlassian Jira Server and Data Center before version 8.6.0 allows authenticated remote attackers to determine... |
| CVE-2019-20403 | MEDIUM | 5.3 | 1.5% | Feb 6, 2020 | The API in Atlassian Jira Server and Data Center before version 8.6.0 allows remote attackers to determine if a Jira pro... |
| CVE-2019-20402 | MEDIUM | 4.9 | 0.8% | Feb 6, 2020 | Support zip files in Atlassian Jira Server and Data Center before version 8.6.0 could be downloaded by a System Administ... |
| CVE-2019-20401 | MEDIUM | 6.5 | 0.8% | Feb 6, 2020 | Various installation setup resources in Jira before version 8.5.2 allow remote attackers to configure a Jira instance, w... |
| CVE-2019-20106 | MEDIUM | 4.3 | 1.2% | Feb 6, 2020 | Comment properties in Atlassian Jira Server and Data Center before version 7.13.12, from 8.0.0 before version 8.5.4, and... |
| CVE-2019-20173 | MEDIUM | 6.1 | 2.5% | Feb 5, 2020 | The Auth0 wp-auth0 plugin 3.11.x before 3.11.3 for WordPress allows XSS via a wle parameter associated with wp-login.php... |
| CVE-2019-15253 | MEDIUM | 4.8 | 3.1% | Feb 5, 2020 | A vulnerability in the web-based management interface of Cisco Digital Network Architecture (DNA) Center could allow an ... |
| CVE-2019-4670 | MEDIUM | 6.5 | 1.8% | Feb 5, 2020 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to obtain sensitive information ca... |
| CVE-2019-15624 | MEDIUM | 4.9 | 1.5% | Feb 4, 2020 | Improper Input Validation in Nextcloud Server 15.0.7 allows group admins to create users with IDs of system folders. |
| CVE-2019-15623 | MEDIUM | 5.3 | 1.9% | Feb 4, 2020 | Exposure of Private Information in Nextcloud Server 16.0.1 causes the server to send it's domain and user IDs to the Nex... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now