2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-4420 | MEDIUM | 6.2 | 0.4% | Aug 20, 2019 | IBM Intelligent Operations Center V5.1.0 through V5.2.0 could disclose detailed error messages, revealing sensitive info... |
| CVE-2019-4419 | HIGH | 8.2 | 2.4% | Aug 20, 2019 | IBM Intelligent Operations Center V5.1.0 through V5.2.0 is vulnerable to an XML External Entity Injection (XXE) attack w... |
| CVE-2019-4402 | HIGH | 7.5 | 1.6% | Aug 20, 2019 | IBM API Connect 2018.1 through 2018.4.1.6 developer portal could allow an unauthorized user to cause a denial of service... |
| CVE-2019-4310 | HIGH | 7.5 | 2.2% | Aug 20, 2019 | IBM Security Guardium Big Data Intelligence 4.0 (SonarG) uses an inadequate account lockout setting that could allow a r... |
| CVE-2019-4308 | MEDIUM | 4.3 | 1.0% | Aug 20, 2019 | IBM Emptoris Sourcing 10.1.0 through 10.1.3, IBM Contract Management 10.1.0 through 10.1.3, and IBM Emptoris Spend Analy... |
| CVE-2019-4294 | HIGH | 7.8 | 0.9% | Aug 20, 2019 | IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.6, 7.6.0.0 through 7.6.0.15 and IBM MQ Appliance 8.0.0.0 through 8.0.0... |
| CVE-2019-4253 | HIGH | 7.8 | 0.4% | Aug 20, 2019 | IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local privileged Informix user to load a malicious sha... |
| CVE-2019-4117 | HIGH | 8.8 | 0.6% | Aug 20, 2019 | IBM Cloud Private 3.1.1 and 3.1.2 is vulnerable to cross-site request forgery which could allow an attacker to execute m... |
| CVE-2019-4049 | MEDIUM | 5.5 | 0.3% | Aug 20, 2019 | IBM MQ 9.1.0.0, 9.1.0.1, 9.1.1, and 9.1.0.2 is vulnerable to a denial of service due to a local user being able to fill ... |
| CVE-2019-3968 | — | — | 9.6% | Aug 20, 2019 | In OpenEMR 5.0.1 and earlier, an authenticated attacker can execute arbitrary commands on the host system via the Scanne... |
| CVE-2019-3753 | MEDIUM | 6.5 | 0.6% | Aug 20, 2019 | Dell EMC PowerConnect 8024, 7000, M6348, M6220, M8024 and M8024-K running firmware versions prior to 5.1.15.2 contain a ... |
| CVE-2019-10745 | HIGH | 7.5 | 1.1% | Aug 20, 2019 | assign-deep is vulnerable to Prototype Pollution in versions before 0.4.8 and version 1.0.0. The function assign-deep co... |
| CVE-2019-3967 | — | — | 30.3% | Aug 20, 2019 | In OpenEMR 5.0.1 and earlier, the patient file download interface contains a directory traversal flaw that allows authen... |
| CVE-2019-3966 | — | — | 1.3% | Aug 20, 2019 | In OpenEMR 5.0.1 and earlier, controller.php contains a reflected XSS vulnerability in the foreign_id parameter. This co... |
| CVE-2019-3965 | — | — | 1.3% | Aug 20, 2019 | In OpenEMR 5.0.1 and earlier, controller.php contains a reflected XSS vulnerability in the document_id parameter. This c... |
| CVE-2019-3964 | — | — | 53.5% | Aug 20, 2019 | In OpenEMR 5.0.1 and earlier, controller.php contains a reflected XSS vulnerability in the doc_id parameter. This could ... |
| CVE-2019-3963 | — | — | 53.7% | Aug 20, 2019 | In OpenEMR 5.0.1 and earlier, controller.php contains a reflected XSS vulnerability in the patient_id parameter. This co... |
| CVE-2019-11209 | HIGH | 8.8 | 1.4% | Aug 20, 2019 | The realm configuration component of TIBCO Software Inc.'s TIBCO FTL Community Edition, TIBCO FTL Developer Edition, TIB... |
| CVE-2019-15238 | — | — | 0.7% | Aug 20, 2019 | The cforms2 plugin before 15.0.2 for WordPress has CSRF related to the IP address field. |
| CVE-2019-15291 | — | — | 0.7% | Aug 20, 2019 | An issue was discovered in the Linux kernel through 5.2.9. There is a NULL pointer dereference caused by a malicious USB... |
| CVE-2019-15290 | — | — | — | Aug 20, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-15098. Reason: This candidate is a duplicate of ... |
| CVE-2019-15233 | MEDIUM | 6.1 | 1.2% | Aug 20, 2019 | The Live:Text Box macro in the Old Street Live Input Macros app before 2.11 for Confluence has XSS, leading to theft of ... |
| CVE-2019-15082 | — | — | 0.9% | Aug 20, 2019 | The 360-product-rotation plugin before 1.4.8 for WordPress has reflected XSS. |
| CVE-2019-14687 | — | — | 1.6% | Aug 20, 2019 | A DLL hijacking vulnerability exists in Trend Micro Password Manager 5.0 in which, if exploited, would allow an attacker... |
| CVE-2019-14684 | — | — | 1.5% | Aug 20, 2019 | A DLL hijacking vulnerability exists in Trend Micro Password Manager 5.0 in which, if exploited, would allow an attacker... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now