2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-20391 | MEDIUM | 6.5 | 1.9% | Jan 22, 2020 | An invalid memory access flaw is present in libyang before v1.0-r3 in the function resolve_feature_value() when an if-fe... |
| CVE-2019-6146 | MEDIUM | 6.1 | 3.0% | Jan 22, 2020 | It has been reported that cross-site scripting (XSS) is possible in Forcepoint Web Security, version 8.x, via host heade... |
| CVE-2019-12490 | MEDIUM | 6.5 | 1.6% | Jan 22, 2020 | An issue was discovered in Simple Machines Forum (SMF) before 2.0.16. Reverse tabnabbing can occur because of use of _bl... |
| CVE-2019-16791 | MEDIUM | 5.9 | 0.7% | Jan 22, 2020 | In postfix-mta-sts-resolver before 0.5.1, All users can receive incorrect response from daemon under rare conditions, re... |
| CVE-2019-19592 | MEDIUM | 6.1 | 0.7% | Jan 21, 2020 | Jama Connect 8.44.0 is vulnerable to stored Cross-Site Scripting |
| CVE-2019-17357 | MEDIUM | 6.5 | 35.0% | Jan 21, 2020 | Cacti through 1.2.7 is affected by a graphs.php?template_id= SQL injection vulnerability affecting how template identifi... |
| CVE-2019-19344 | MEDIUM | 6.5 | 3.1% | Jan 21, 2020 | There is a use-after-free issue in all samba 4.9.x versions before 4.9.18, all samba 4.10.x versions before 4.10.12 and ... |
| CVE-2019-14907 | MEDIUM | 6.5 | 3.2% | Jan 21, 2020 | All samba versions 4.9.x before 4.9.18, 4.10.x before 4.10.12 and 4.11.x before 4.11.5 have an issue where if it is set ... |
| CVE-2019-14902 | MEDIUM | 5.4 | 1.5% | Jan 21, 2020 | There is an issue in all samba 4.11.x versions before 4.11.5, all samba 4.10.x versions before 4.10.12 and all samba 4.9... |
| CVE-2019-14766 | MEDIUM | 6.5 | 1.1% | Jan 21, 2020 | Path Traversal in the file browser of DIMO YellowBox CRM before 6.3.4 allows a standard authenticated user to browse the... |
| CVE-2019-10561 | MEDIUM | 5.5 | 0.4% | Jan 21, 2020 | Improper initialization of local variables which are parameters to sfs api may cause invalid pointer dereference and lea... |
| CVE-2019-20384 | MEDIUM | 5.5 | 0.3% | Jan 21, 2020 | Gentoo Portage through 2.3.84 allows local users to place a Trojan horse plugin in the /usr/lib64/nagios/plugins directo... |
| CVE-2019-20381 | MEDIUM | 6.1 | 0.9% | Jan 20, 2020 | TestLink before 1.9.20 allows XSS via non-lowercase javascript: in the index.php reqURI parameter. NOTE: this issue exis... |
| CVE-2019-19697 | MEDIUM | 6.7 | 0.8% | Jan 18, 2020 | An arbitrary code execution vulnerability exists in the Trend Micro Security 2019 (v15) consumer family of products whic... |
| CVE-2019-19696 | MEDIUM | 5.5 | 0.5% | Jan 18, 2020 | A RootCA vulnerability found in Trend Micro Password Manager for Windows and macOS exists where the localhost.key of Roo... |
| CVE-2019-15625 | MEDIUM | 5.5 | 1.0% | Jan 18, 2020 | A memory usage vulnerability exists in Trend Micro Password Manager 3.8 that could allow an attacker with access and per... |
| CVE-2019-19339 | MEDIUM | 6.5 | 0.3% | Jan 17, 2020 | It was found that the Red Hat Enterprise Linux 8 kpatch update did not include the complete fix for CVE-2018-12207. A fl... |
| CVE-2019-17127 | MEDIUM | 6.1 | 1.9% | Jan 17, 2020 | A Stored Client Side Template Injection (CSTI) with Angular was discovered in the SolarWinds Orion Platform 2019.2 HF1 i... |
| CVE-2019-17125 | MEDIUM | 6.1 | 1.5% | Jan 17, 2020 | A Reflected Client Side Template Injection (CSTI) with Angular was discovered in the SolarWinds Orion Platform 2019.2 HF... |
| CVE-2019-14629 | MEDIUM | 5.5 | 0.3% | Jan 17, 2020 | Improper permissions in Intel(R) DAAL before version 2020 Gold may allow an authenticated user to potentially enable inf... |
| CVE-2019-14615 | MEDIUM | 5.5 | 1.4% | Jan 17, 2020 | Insufficient control flow in certain data structures for some Intel(R) Processors with Intel(R) Processor Graphics may a... |
| CVE-2019-14600 | MEDIUM | 6.7 | 0.3% | Jan 17, 2020 | Uncontrolled search path element in the installer for Intel(R) SNMP Subagent Stand-Alone for Windows* may allow an authe... |
| CVE-2019-14596 | MEDIUM | 5.5 | 0.3% | Jan 17, 2020 | Improper access control in the installer for Intel(R) Chipset Device Software INF Utility before version 10.1.18 may all... |
| CVE-2019-10957 | MEDIUM | 4.8 | 0.9% | Jan 17, 2020 | Geutebruck IP Cameras G-Code(EEC-2xxx), G-Cam(EBC-21xx/EFD-22xx/ETHC-22xx/EWPC-22xx): All versions 1.12.0.25 and prior m... |
| CVE-2019-20003 | MEDIUM | 6.1 | 0.7% | Jan 17, 2020 | Feldtech easescreen Crystal 9.0 Web-Services 9.0.1.16265 allows Stored XSS via the Debug-Log and Display-Log components.... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now