2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-10782 | MEDIUM | 5.3 | 1.5% | Jan 30, 2020 | All versions of com.puppycrawl.tools:checkstyle before 8.29 are vulnerable to XML External Entity (XXE) Injection due to... |
| CVE-2019-17273 | MEDIUM | 6.5 | 0.7% | Jan 30, 2020 | E-Series SANtricity OS Controller Software version 11.60.0 is susceptible to a vulnerability which allows an attacker to... |
| CVE-2019-20050 | MEDIUM | 6.8 | 3.4% | Jan 30, 2020 | Pandora FMS ≤ 7.42 suffers from a remote code execution vulnerability. To exploit the vulnerability, an authenticated us... |
| CVE-2019-7655 | MEDIUM | 5.4 | 0.9% | Jan 29, 2020 | Wowza Streaming Engine 4.8.0 and earlier from multiple authenticated XSS vulnerabilities via the (1) customList%5B0%5D.v... |
| CVE-2019-7654 | MEDIUM | 6.5 | 0.9% | Jan 29, 2020 | Wowza Streaming Engine 4.8.0 and earlier suffers from multiple CSRF vulnerabilities. For example, an administrator, by f... |
| CVE-2019-4679 | MEDIUM | 4.3 | 0.8% | Jan 28, 2020 | IBM Content Navigator 3.0CD could allow an authenticated user to gain information about the hosting operating system and... |
| CVE-2019-4637 | MEDIUM | 4.3 | 0.7% | Jan 28, 2020 | IBM Security Secret Server 10.7 uses incomplete blacklisting for input validation which allows attackers to bypass appli... |
| CVE-2019-4633 | MEDIUM | 4.3 | 0.9% | Jan 28, 2020 | IBM Security Secret Server 10.7 could allow an attacker to obtain sensitive information due to an overly permissive CORS... |
| CVE-2019-4632 | MEDIUM | 6.1 | 0.7% | Jan 28, 2020 | IBM Security Secret Server 10.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrar... |
| CVE-2019-4631 | MEDIUM | 6.1 | 0.8% | Jan 28, 2020 | IBM Security Secret Server 10.7 could allow a remote attacker to conduct phishing attacks, using an open redirect attack... |
| CVE-2019-4614 | MEDIUM | 6.5 | 1.5% | Jan 28, 2020 | IBM MQ and IBM MQ Appliance 8.0 and 9.0 LTS client connecting to a Queue Manager could cause a SIGSEGV denial of service... |
| CVE-2019-4568 | MEDIUM | 5.9 | 1.3% | Jan 28, 2020 | IBM MQ and IBM MQ Appliance 8.0 and 9.0 LTS could allow a remote attacker with intimate knowledge of the server to cause... |
| CVE-2019-17338 | MEDIUM | 5.4 | 0.6% | Jan 28, 2020 | The user interface component of TIBCO Software Inc.'s TIBCO Patterns - Search contains multiple vulnerabilities that the... |
| CVE-2019-5474 | MEDIUM | 6.5 | 1.1% | Jan 28, 2020 | An authorization issue was discovered in GitLab EE < 12.1.2, < 12.0.4, and < 11.11.6 allowing the merge request approval... |
| CVE-2019-5466 | MEDIUM | 4.3 | 1.0% | Jan 28, 2020 | An IDOR was discovered in GitLab CE/EE 11.5 and later that allowed new merge requests endpoint to disclose label names. |
| CVE-2019-5465 | MEDIUM | 4.3 | 1.1% | Jan 28, 2020 | An information disclosure issue was discovered in GitLab CE/EE 8.14 and later, by using the move issue feature which cou... |
| CVE-2019-15607 | MEDIUM | 5.4 | 0.6% | Jan 28, 2020 | A stored XSS vulnerability is present within node-red (version: <= 0.20.7) npm package, which is a visual tool for wirin... |
| CVE-2019-15586 | MEDIUM | 6.1 | 0.8% | Jan 28, 2020 | A XSS exists in Gitlab CE/EE < 12.1.10 in the Mermaid plugin. |
| CVE-2019-15582 | MEDIUM | 5.3 | 0.9% | Jan 28, 2020 | An IDOR was discovered in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE... |
| CVE-2019-15581 | MEDIUM | 5.3 | 1.0% | Jan 28, 2020 | An IDOR exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) that a... |
| CVE-2019-15579 | MEDIUM | 5.3 | 1.0% | Jan 28, 2020 | An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise E... |
| CVE-2019-15578 | MEDIUM | 5.3 | 1.0% | Jan 28, 2020 | An information disclosure exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise E... |
| CVE-2019-20439 | MEDIUM | 4.8 | 1.0% | Jan 28, 2020 | An issue was discovered in WSO2 API Manager 2.6.0. A potential Reflected Cross-Site Scripting (XSS) vulnerability has be... |
| CVE-2019-20438 | MEDIUM | 4.8 | 0.8% | Jan 28, 2020 | An issue was discovered in WSO2 API Manager 2.6.0. A potential stored Cross-Site Scripting (XSS) vulnerability has been ... |
| CVE-2019-20437 | MEDIUM | 6.1 | 1.3% | Jan 28, 2020 | An issue was discovered in WSO2 API Manager 2.6.0, WSO2 IS as Key Manager 5.7.0, and WSO2 Identity Server 5.8.0. When a ... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now