2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-10782MEDIUM5.3All versions of com.puppycrawl.tools:checkstyle before 8.29 are vulnerable to XML External Entity (XXE) Injection due to...
CVE-2019-17273MEDIUM6.5E-Series SANtricity OS Controller Software version 11.60.0 is susceptible to a vulnerability which allows an attacker to...
CVE-2019-20050MEDIUM6.8Pandora FMS ≤ 7.42 suffers from a remote code execution vulnerability. To exploit the vulnerability, an authenticated us...
CVE-2019-7655MEDIUM5.4Wowza Streaming Engine 4.8.0 and earlier from multiple authenticated XSS vulnerabilities via the (1) customList%5B0%5D.v...
CVE-2019-7654MEDIUM6.5Wowza Streaming Engine 4.8.0 and earlier suffers from multiple CSRF vulnerabilities. For example, an administrator, by f...
CVE-2019-4679MEDIUM4.3IBM Content Navigator 3.0CD could allow an authenticated user to gain information about the hosting operating system and...
CVE-2019-4637MEDIUM4.3IBM Security Secret Server 10.7 uses incomplete blacklisting for input validation which allows attackers to bypass appli...
CVE-2019-4633MEDIUM4.3IBM Security Secret Server 10.7 could allow an attacker to obtain sensitive information due to an overly permissive CORS...
CVE-2019-4632MEDIUM6.1IBM Security Secret Server 10.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrar...
CVE-2019-4631MEDIUM6.1IBM Security Secret Server 10.7 could allow a remote attacker to conduct phishing attacks, using an open redirect attack...
CVE-2019-4614MEDIUM6.5IBM MQ and IBM MQ Appliance 8.0 and 9.0 LTS client connecting to a Queue Manager could cause a SIGSEGV denial of service...
CVE-2019-4568MEDIUM5.9IBM MQ and IBM MQ Appliance 8.0 and 9.0 LTS could allow a remote attacker with intimate knowledge of the server to cause...
CVE-2019-17338MEDIUM5.4The user interface component of TIBCO Software Inc.'s TIBCO Patterns - Search contains multiple vulnerabilities that the...
CVE-2019-5474MEDIUM6.5An authorization issue was discovered in GitLab EE < 12.1.2, < 12.0.4, and < 11.11.6 allowing the merge request approval...
CVE-2019-5466MEDIUM4.3An IDOR was discovered in GitLab CE/EE 11.5 and later that allowed new merge requests endpoint to disclose label names.
CVE-2019-5465MEDIUM4.3An information disclosure issue was discovered in GitLab CE/EE 8.14 and later, by using the move issue feature which cou...
CVE-2019-15607MEDIUM5.4A stored XSS vulnerability is present within node-red (version: <= 0.20.7) npm package, which is a visual tool for wirin...
CVE-2019-15586MEDIUM6.1A XSS exists in Gitlab CE/EE < 12.1.10 in the Mermaid plugin.
CVE-2019-15582MEDIUM5.3An IDOR was discovered in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE...
CVE-2019-15581MEDIUM5.3An IDOR exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) that a...
CVE-2019-15579MEDIUM5.3An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise E...
CVE-2019-15578MEDIUM5.3An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise E...
CVE-2019-20439MEDIUM4.8An issue was discovered in WSO2 API Manager 2.6.0. A potential Reflected Cross-Site Scripting (XSS) vulnerability has be...
CVE-2019-20438MEDIUM4.8An issue was discovered in WSO2 API Manager 2.6.0. A potential stored Cross-Site Scripting (XSS) vulnerability has been ...
CVE-2019-20437MEDIUM6.1An issue was discovered in WSO2 API Manager 2.6.0, WSO2 IS as Key Manager 5.7.0, and WSO2 Identity Server 5.8.0. When a ...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now