2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-4420MEDIUM6.2IBM Intelligent Operations Center V5.1.0 through V5.2.0 could disclose detailed error messages, revealing sensitive info...
CVE-2019-4419HIGH8.2IBM Intelligent Operations Center V5.1.0 through V5.2.0 is vulnerable to an XML External Entity Injection (XXE) attack w...
CVE-2019-4402HIGH7.5IBM API Connect 2018.1 through 2018.4.1.6 developer portal could allow an unauthorized user to cause a denial of service...
CVE-2019-4310HIGH7.5IBM Security Guardium Big Data Intelligence 4.0 (SonarG) uses an inadequate account lockout setting that could allow a r...
CVE-2019-4308MEDIUM4.3IBM Emptoris Sourcing 10.1.0 through 10.1.3, IBM Contract Management 10.1.0 through 10.1.3, and IBM Emptoris Spend Analy...
CVE-2019-4294HIGH7.8IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.6, 7.6.0.0 through 7.6.0.15 and IBM MQ Appliance 8.0.0.0 through 8.0.0...
CVE-2019-4253HIGH7.8IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local privileged Informix user to load a malicious sha...
CVE-2019-4117HIGH8.8IBM Cloud Private 3.1.1 and 3.1.2 is vulnerable to cross-site request forgery which could allow an attacker to execute m...
CVE-2019-4049MEDIUM5.5IBM MQ 9.1.0.0, 9.1.0.1, 9.1.1, and 9.1.0.2 is vulnerable to a denial of service due to a local user being able to fill ...
CVE-2019-3968In OpenEMR 5.0.1 and earlier, an authenticated attacker can execute arbitrary commands on the host system via the Scanne...
CVE-2019-3753MEDIUM6.5Dell EMC PowerConnect 8024, 7000, M6348, M6220, M8024 and M8024-K running firmware versions prior to 5.1.15.2 contain a ...
CVE-2019-10745HIGH7.5assign-deep is vulnerable to Prototype Pollution in versions before 0.4.8 and version 1.0.0. The function assign-deep co...
CVE-2019-3967In OpenEMR 5.0.1 and earlier, the patient file download interface contains a directory traversal flaw that allows authen...
CVE-2019-3966In OpenEMR 5.0.1 and earlier, controller.php contains a reflected XSS vulnerability in the foreign_id parameter. This co...
CVE-2019-3965In OpenEMR 5.0.1 and earlier, controller.php contains a reflected XSS vulnerability in the document_id parameter. This c...
CVE-2019-3964In OpenEMR 5.0.1 and earlier, controller.php contains a reflected XSS vulnerability in the doc_id parameter. This could ...
CVE-2019-3963In OpenEMR 5.0.1 and earlier, controller.php contains a reflected XSS vulnerability in the patient_id parameter. This co...
CVE-2019-11209HIGH8.8The realm configuration component of TIBCO Software Inc.'s TIBCO FTL Community Edition, TIBCO FTL Developer Edition, TIB...
CVE-2019-15238The cforms2 plugin before 15.0.2 for WordPress has CSRF related to the IP address field.
CVE-2019-15291An issue was discovered in the Linux kernel through 5.2.9. There is a NULL pointer dereference caused by a malicious USB...
CVE-2019-15290Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-15098. Reason: This candidate is a duplicate of ...
CVE-2019-15233MEDIUM6.1The Live:Text Box macro in the Old Street Live Input Macros app before 2.11 for Confluence has XSS, leading to theft of ...
CVE-2019-15082The 360-product-rotation plugin before 1.4.8 for WordPress has reflected XSS.
CVE-2019-14687A DLL hijacking vulnerability exists in Trend Micro Password Manager 5.0 in which, if exploited, would allow an attacker...
CVE-2019-14684A DLL hijacking vulnerability exists in Trend Micro Password Manager 5.0 in which, if exploited, would allow an attacker...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now