2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-19669MEDIUM6.5A CSRF vulnerability exists in the Upload Center Forms Component of Web File Manager in Rumpus FTP 8.2.9.1. This could a...
CVE-2019-19667MEDIUM5.4A CSRF vulnerability exists in the Block Clients component of Web File Manager in Rumpus FTP 8.2.9.1 that could allow an...
CVE-2019-19666MEDIUM4.3A CSRF vulnerability exists in the Event Notices Settings of Web File Manager in Rumpus FTP 8.2.9.1. An attacker can cre...
CVE-2019-19661MEDIUM6.1A Cookie based reflected XSS exists in the Web File Manager of Rumpus FTP Server 8.2.9.1, related to RumpusLoginUserName...
CVE-2019-19662MEDIUM6.5A CSRF vulnerability exists in the Web File Manager's Create/Delete Accounts functionality of Rumpus FTP Server 8.2.9.1....
CVE-2019-19665MEDIUM6.5A CSRF vulnerability exists in the FTP Settings of Web File Manager in Rumpus FTP 8.2.9.1. Exploitation of this vulnerab...
CVE-2019-19663MEDIUM6.5A CSRF vulnerability exists in the Folder Sets Settings of Web File Manager in Rumpus FTP 8.2.9.1. This allows an attack...
CVE-2019-19660MEDIUM6.5A CSRF vulnerability exists in the Web File Manager's Network Setting functionality of Rumpus FTP Server 8.2.9.1. By exp...
CVE-2019-11482MEDIUM4.7Sander Bos discovered a time of check to time of use (TOCTTOU) vulnerability in apport that allowed a user to cause core...
CVE-2019-13163MEDIUM5.9The Fujitsu TLS library allows a man-in-the-middle attack. This affects Interstage Application Development Cycle Manager...
CVE-2019-19800MEDIUM5.3Zoho ManageEngine Applications Manager 14 before 14520 allows a remote unauthenticated attacker to disclose OS file name...
CVE-2019-12426MEDIUM5.3an unauthenticated user could get access to information of some backend screens by invoking setSessionLocale in Apache O...
CVE-2019-17652MEDIUM6.5A stack buffer overflow vulnerability in FortiClient for Linux 6.2.1 and below may allow a user with low privilege to ca...
CVE-2019-16152MEDIUM6.5A Denial of service (DoS) vulnerability in FortiClient for Linux 6.2.1 and below may allow an user with low privilege to...
CVE-2019-20405MEDIUM4.3The JMX monitoring flag in Atlassian Jira Server and Data Center before version 8.6.0 allows remote attackers to turn th...
CVE-2019-20404MEDIUM4.3The API in Atlassian Jira Server and Data Center before version 8.6.0 allows authenticated remote attackers to determine...
CVE-2019-20403MEDIUM5.3The API in Atlassian Jira Server and Data Center before version 8.6.0 allows remote attackers to determine if a Jira pro...
CVE-2019-20402MEDIUM4.9Support zip files in Atlassian Jira Server and Data Center before version 8.6.0 could be downloaded by a System Administ...
CVE-2019-20401MEDIUM6.5Various installation setup resources in Jira before version 8.5.2 allow remote attackers to configure a Jira instance, w...
CVE-2019-20106MEDIUM4.3Comment properties in Atlassian Jira Server and Data Center before version 7.13.12, from 8.0.0 before version 8.5.4, and...
CVE-2019-20173MEDIUM6.1The Auth0 wp-auth0 plugin 3.11.x before 3.11.3 for WordPress allows XSS via a wle parameter associated with wp-login.php...
CVE-2019-15253MEDIUM4.8A vulnerability in the web-based management interface of Cisco Digital Network Architecture (DNA) Center could allow an ...
CVE-2019-4670MEDIUM6.5IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to obtain sensitive information ca...
CVE-2019-15624MEDIUM4.9Improper Input Validation in Nextcloud Server 15.0.7 allows group admins to create users with IDs of system folders.
CVE-2019-15623MEDIUM5.3Exposure of Private Information in Nextcloud Server 16.0.1 causes the server to send it's domain and user IDs to the Nex...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now