2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-15621 | MEDIUM | 6.5 | 1.1% | Feb 4, 2020 | Improper permissions preservation in Nextcloud Server 16.0.1 causes sharees to be able to reshare with write permissions... |
| CVE-2019-15619 | MEDIUM | 4.8 | 0.8% | Feb 4, 2020 | Improper neutralization of file names, conversation names and board names in Nextcloud Server 16.0.3, Nextcloud Talk 6.0... |
| CVE-2019-15618 | MEDIUM | 4.8 | 0.7% | Feb 4, 2020 | Missing escaping of HTML in the Updater of Nextcloud 15.0.5 allowed a reflected XSS when starting the updater from a mal... |
| CVE-2019-15617 | MEDIUM | 5.4 | 0.6% | Feb 4, 2020 | A missing check in Nextcloud Server 17.0.0 allowed an attacker to set up a new second factor when trying to login. |
| CVE-2019-15616 | MEDIUM | 4.3 | 0.8% | Feb 4, 2020 | Dangling remote share attempts in Nextcloud 16 allow a DNS pollution when running long. |
| CVE-2019-15615 | MEDIUM | 6.1 | 0.4% | Feb 4, 2020 | A wrong check for the system time in the Android App 3.9.0 causes a bypass of the lock protection when changing the time... |
| CVE-2019-15614 | MEDIUM | 5.4 | 0.8% | Feb 4, 2020 | Missing sanitization in the iOS App 2.24.4 causes an XSS when opening malicious HTML files. |
| CVE-2019-15612 | MEDIUM | 5.9 | 0.3% | Feb 4, 2020 | A bug in Nextcloud Server 15.0.2 causes pending 2FA logins to not be correctly expired when the password of the user is ... |
| CVE-2019-15611 | MEDIUM | 4.9 | 1.1% | Feb 4, 2020 | Violation of Secure Design Principles in the iOS App 2.23.0 causes the app to leak its login and token to other Nextclou... |
| CVE-2019-15610 | MEDIUM | 4.3 | 0.8% | Feb 4, 2020 | Improper authorization in the Circles app 0.17.7 causes retaining access when an email address was removed from a circle... |
| CVE-2019-4674 | MEDIUM | 4.9 | 1.9% | Feb 4, 2020 | IBM Security Identity Manager 7.0.1 could allow a remote attacker to traverse directories on the system. An attacker cou... |
| CVE-2019-4562 | MEDIUM | 5.3 | 1.0% | Feb 4, 2020 | IBM Security Directory Server 6.4.0 stores sensitive information in URLs. This may lead to information disclosure if una... |
| CVE-2019-4551 | MEDIUM | 5.3 | 1.3% | Feb 4, 2020 | IBM Security Directory Server 6.4.0 does not perform an authentication check for a critical resource or functionality al... |
| CVE-2019-4550 | MEDIUM | 5.3 | 1.1% | Feb 4, 2020 | IBM Security Directory Server 6.4.0 is deployed with active debugging code that can create unintended entry points. IBM ... |
| CVE-2019-4548 | MEDIUM | 6.1 | 0.9% | Feb 4, 2020 | IBM Security Directory Server 6.4.0 could allow a remote attacker to hijack the clicking action of the victim. By persua... |
| CVE-2019-4451 | MEDIUM | 5.4 | 0.6% | Feb 4, 2020 | IBM Security Identity Manager 6.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbi... |
| CVE-2019-19968 | MEDIUM | 5.4 | 0.8% | Feb 4, 2020 | PandoraFMS 742 suffers from multiple XSS vulnerabilities, affecting the Agent Management, Report Builder, and Graph Buil... |
| CVE-2019-20174 | MEDIUM | 6.1 | 0.7% | Feb 3, 2020 | Auth0 Lock before 11.21.0 allows XSS when additionalSignUpFields is used with an untrusted placeholder. |
| CVE-2019-18567 | MEDIUM | 6.3 | 0.5% | Feb 3, 2020 | Bromium client version 4.0.3.2060 and prior to 4.1.7 Update 1 has an out of bound read results in race condition causing... |
| CVE-2019-4732 | MEDIUM | 6.5 | 0.6% | Feb 3, 2020 | IBM SDK, Java Technology Edition Version 7.0.0.0 through 7.0.10.55, 7.1.0.0 through 7.1.4.55, and 8.0.0.0 through 8.0.6.... |
| CVE-2019-11251 | MEDIUM | 5.7 | 2.3% | Feb 3, 2020 | The Kubernetes kubectl cp command in versions 1.1-1.12, and versions prior to 1.13.11, 1.14.7, and 1.15.4 allows a combi... |
| CVE-2019-19119 | MEDIUM | 5.5 | 0.3% | Feb 3, 2020 | An issue was discovered in PRTG 7.x through 19.4.53. Due to insufficient access control on local registry keys for the C... |
| CVE-2019-20446 | MEDIUM | 6.5 | 2.1% | Feb 2, 2020 | In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nested patterns can cause denial of service when passe... |
| CVE-2019-3016 | MEDIUM | 4.7 | 0.6% | Jan 31, 2020 | In a Linux KVM guest that has PV TLB enabled, a process in the guest kernel may be able to read memory locations from an... |
| CVE-2019-18913 | MEDIUM | 6.8 | 0.6% | Jan 31, 2020 | A potential security vulnerability with pre-boot DMA may allow unauthorized UEFI code execution using open-case attacks.... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now