2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-20391MEDIUM6.5An invalid memory access flaw is present in libyang before v1.0-r3 in the function resolve_feature_value() when an if-fe...
CVE-2019-6146MEDIUM6.1It has been reported that cross-site scripting (XSS) is possible in Forcepoint Web Security, version 8.x, via host heade...
CVE-2019-12490MEDIUM6.5An issue was discovered in Simple Machines Forum (SMF) before 2.0.16. Reverse tabnabbing can occur because of use of _bl...
CVE-2019-16791MEDIUM5.9In postfix-mta-sts-resolver before 0.5.1, All users can receive incorrect response from daemon under rare conditions, re...
CVE-2019-19592MEDIUM6.1Jama Connect 8.44.0 is vulnerable to stored Cross-Site Scripting
CVE-2019-17357MEDIUM6.5Cacti through 1.2.7 is affected by a graphs.php?template_id= SQL injection vulnerability affecting how template identifi...
CVE-2019-19344MEDIUM6.5There is a use-after-free issue in all samba 4.9.x versions before 4.9.18, all samba 4.10.x versions before 4.10.12 and ...
CVE-2019-14907MEDIUM6.5All samba versions 4.9.x before 4.9.18, 4.10.x before 4.10.12 and 4.11.x before 4.11.5 have an issue where if it is set ...
CVE-2019-14902MEDIUM5.4There is an issue in all samba 4.11.x versions before 4.11.5, all samba 4.10.x versions before 4.10.12 and all samba 4.9...
CVE-2019-14766MEDIUM6.5Path Traversal in the file browser of DIMO YellowBox CRM before 6.3.4 allows a standard authenticated user to browse the...
CVE-2019-10561MEDIUM5.5Improper initialization of local variables which are parameters to sfs api may cause invalid pointer dereference and lea...
CVE-2019-20384MEDIUM5.5Gentoo Portage through 2.3.84 allows local users to place a Trojan horse plugin in the /usr/lib64/nagios/plugins directo...
CVE-2019-20381MEDIUM6.1TestLink before 1.9.20 allows XSS via non-lowercase javascript: in the index.php reqURI parameter. NOTE: this issue exis...
CVE-2019-19697MEDIUM6.7An arbitrary code execution vulnerability exists in the Trend Micro Security 2019 (v15) consumer family of products whic...
CVE-2019-19696MEDIUM5.5A RootCA vulnerability found in Trend Micro Password Manager for Windows and macOS exists where the localhost.key of Roo...
CVE-2019-15625MEDIUM5.5A memory usage vulnerability exists in Trend Micro Password Manager 3.8 that could allow an attacker with access and per...
CVE-2019-19339MEDIUM6.5It was found that the Red Hat Enterprise Linux 8 kpatch update did not include the complete fix for CVE-2018-12207. A fl...
CVE-2019-17127MEDIUM6.1A Stored Client Side Template Injection (CSTI) with Angular was discovered in the SolarWinds Orion Platform 2019.2 HF1 i...
CVE-2019-17125MEDIUM6.1A Reflected Client Side Template Injection (CSTI) with Angular was discovered in the SolarWinds Orion Platform 2019.2 HF...
CVE-2019-14629MEDIUM5.5Improper permissions in Intel(R) DAAL before version 2020 Gold may allow an authenticated user to potentially enable inf...
CVE-2019-14615MEDIUM5.5Insufficient control flow in certain data structures for some Intel(R) Processors with Intel(R) Processor Graphics may a...
CVE-2019-14600MEDIUM6.7Uncontrolled search path element in the installer for Intel(R) SNMP Subagent Stand-Alone for Windows* may allow an authe...
CVE-2019-14596MEDIUM5.5Improper access control in the installer for Intel(R) Chipset Device Software INF Utility before version 10.1.18 may all...
CVE-2019-10957MEDIUM4.8Geutebruck IP Cameras G-Code(EEC-2xxx), G-Cam(EBC-21xx/EFD-22xx/ETHC-22xx/EWPC-22xx): All versions 1.12.0.25 and prior m...
CVE-2019-20003MEDIUM6.1Feldtech easescreen Crystal 9.0 Web-Services 9.0.1.16265 allows Stored XSS via the Debug-Log and Display-Log components....

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now