2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-20148MEDIUM5.3An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 8.13 through 12.6.1. It has Incorre...
CVE-2019-20147MEDIUM5.3An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 9.1 through 12.6.1. It has Incorrec...
CVE-2019-20146MEDIUM5.3An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 11.0 through 12.6. It allows Uncont...
CVE-2019-20145MEDIUM4.3An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 11.4 through 12.6.1. It has Incorre...
CVE-2019-19727MEDIUM5.5SchedMD Slurm before 18.08.9 and 19.x before 19.05.5 has weak slurmdbd.conf permissions.
CVE-2019-20212MEDIUM6.1The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Persiste...
CVE-2019-20211MEDIUM6.1The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Persiste...
CVE-2019-20210MEDIUM6.1The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Reflecte...
CVE-2019-19891MEDIUM5.9An encryption key vulnerability on Mitel SIP-DECT wireless devices 8.0 and 8.1 could allow an attacker to launch a man-i...
CVE-2019-18893MEDIUM6.1XSS in the Video Downloader component before 1.5 of Avast Secure Browser 77.1.1831.91 and AVG Secure Browser 77.0.1790.7...
CVE-2019-19547MEDIUM6.1Symantec Endpoint Detection and Response (SEDR), prior to 4.3.0, may be susceptible to a cross site scripting (XSS) issu...
CVE-2019-20377MEDIUM6.1TopList before 2019-09-03 allows XSS via a title.
CVE-2019-20379MEDIUM6.1ganglia-web (aka Ganglia Web Frontend) through 3.7.5 allows XSS via the header.php cs parameter.
CVE-2019-20378MEDIUM6.1ganglia-web (aka Ganglia Web Frontend) through 3.7.5 allows XSS via the header.php ce parameter.
CVE-2019-18588MEDIUM5.4Dell EMC Unisphere for PowerMax versions prior to 9.1.0.9, Dell EMC Unisphere for PowerMax versions prior to 9.0.2.16, a...
CVE-2019-19819MEDIUM5.5The JBIG2Globals library in npdf.dll in Nitro Free PDF Reader 12.0.0.112 has a CAPPDAnnotHandlerUtils::PDAnnotHandlerDes...
CVE-2019-19817MEDIUM5.5The JBIG2Decode library in npdf.dll in Nitro Free PDF Reader 12.0.0.112 has a CAPPDAnnotHandlerUtils::PDAnnotHandlerDest...
CVE-2019-14302MEDIUM6.8On Ricoh SP C250DN 1.06 devices, a debug port can be used.
CVE-2019-4559MEDIUM5.3IBM QRadar SIEM 7.3.0 through 7.3.3 discloses sensitive information to unauthorized users. The information can be used t...
CVE-2019-20376MEDIUM6.1A cross-site scripting (XSS) vulnerability in Electronic Logbook (ELOG) 3.1.4 allows remote attackers to inject arbitrar...
CVE-2019-20375MEDIUM6.1A cross-site scripting (XSS) vulnerability in Electronic Logbook (ELOG) 3.1.4 allows remote attackers to inject arbitrar...
CVE-2019-20182MEDIUM4.8The FooGallery plugin 1.8.12 for WordPress allow XSS via the post_title parameter.
CVE-2019-20181MEDIUM4.8The awesome-support plugin 5.8.0 for WordPress allows XSS via the post_title parameter.
CVE-2019-20178MEDIUM6.5Advisto PEEL Shopping 9.2.1 has CSRF via administrer/utilisateurs.php to delete a user.
CVE-2019-20372MEDIUM5.3NGINX before 1.17.7, with certain error_page configurations, allows HTTP request smuggling, as demonstrated by the abili...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now