2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-20148 | MEDIUM | 5.3 | 0.9% | Jan 13, 2020 | An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 8.13 through 12.6.1. It has Incorre... |
| CVE-2019-20147 | MEDIUM | 5.3 | 0.9% | Jan 13, 2020 | An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 9.1 through 12.6.1. It has Incorrec... |
| CVE-2019-20146 | MEDIUM | 5.3 | 1.1% | Jan 13, 2020 | An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 11.0 through 12.6. It allows Uncont... |
| CVE-2019-20145 | MEDIUM | 4.3 | 0.7% | Jan 13, 2020 | An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 11.4 through 12.6.1. It has Incorre... |
| CVE-2019-19727 | MEDIUM | 5.5 | 0.4% | Jan 13, 2020 | SchedMD Slurm before 18.08.9 and 19.x before 19.05.5 has weak slurmdbd.conf permissions. |
| CVE-2019-20212 | MEDIUM | 6.1 | 2.6% | Jan 13, 2020 | The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Persiste... |
| CVE-2019-20211 | MEDIUM | 6.1 | 2.6% | Jan 13, 2020 | The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Persiste... |
| CVE-2019-20210 | MEDIUM | 6.1 | 3.1% | Jan 13, 2020 | The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Reflecte... |
| CVE-2019-19891 | MEDIUM | 5.9 | 0.3% | Jan 13, 2020 | An encryption key vulnerability on Mitel SIP-DECT wireless devices 8.0 and 8.1 could allow an attacker to launch a man-i... |
| CVE-2019-18893 | MEDIUM | 6.1 | 1.8% | Jan 13, 2020 | XSS in the Video Downloader component before 1.5 of Avast Secure Browser 77.1.1831.91 and AVG Secure Browser 77.0.1790.7... |
| CVE-2019-19547 | MEDIUM | 6.1 | 1.4% | Jan 13, 2020 | Symantec Endpoint Detection and Response (SEDR), prior to 4.3.0, may be susceptible to a cross site scripting (XSS) issu... |
| CVE-2019-20377 | MEDIUM | 6.1 | 0.6% | Jan 11, 2020 | TopList before 2019-09-03 allows XSS via a title. |
| CVE-2019-20379 | MEDIUM | 6.1 | 0.8% | Jan 11, 2020 | ganglia-web (aka Ganglia Web Frontend) through 3.7.5 allows XSS via the header.php cs parameter. |
| CVE-2019-20378 | MEDIUM | 6.1 | 1.0% | Jan 11, 2020 | ganglia-web (aka Ganglia Web Frontend) through 3.7.5 allows XSS via the header.php ce parameter. |
| CVE-2019-18588 | MEDIUM | 5.4 | 0.7% | Jan 10, 2020 | Dell EMC Unisphere for PowerMax versions prior to 9.1.0.9, Dell EMC Unisphere for PowerMax versions prior to 9.0.2.16, a... |
| CVE-2019-19819 | MEDIUM | 5.5 | 1.0% | Jan 10, 2020 | The JBIG2Globals library in npdf.dll in Nitro Free PDF Reader 12.0.0.112 has a CAPPDAnnotHandlerUtils::PDAnnotHandlerDes... |
| CVE-2019-19817 | MEDIUM | 5.5 | 1.0% | Jan 10, 2020 | The JBIG2Decode library in npdf.dll in Nitro Free PDF Reader 12.0.0.112 has a CAPPDAnnotHandlerUtils::PDAnnotHandlerDest... |
| CVE-2019-14302 | MEDIUM | 6.8 | 0.4% | Jan 10, 2020 | On Ricoh SP C250DN 1.06 devices, a debug port can be used. |
| CVE-2019-4559 | MEDIUM | 5.3 | 1.1% | Jan 10, 2020 | IBM QRadar SIEM 7.3.0 through 7.3.3 discloses sensitive information to unauthorized users. The information can be used t... |
| CVE-2019-20376 | MEDIUM | 6.1 | 0.8% | Jan 10, 2020 | A cross-site scripting (XSS) vulnerability in Electronic Logbook (ELOG) 3.1.4 allows remote attackers to inject arbitrar... |
| CVE-2019-20375 | MEDIUM | 6.1 | 0.8% | Jan 10, 2020 | A cross-site scripting (XSS) vulnerability in Electronic Logbook (ELOG) 3.1.4 allows remote attackers to inject arbitrar... |
| CVE-2019-20182 | MEDIUM | 4.8 | 0.7% | Jan 9, 2020 | The FooGallery plugin 1.8.12 for WordPress allow XSS via the post_title parameter. |
| CVE-2019-20181 | MEDIUM | 4.8 | 0.7% | Jan 9, 2020 | The awesome-support plugin 5.8.0 for WordPress allows XSS via the post_title parameter. |
| CVE-2019-20178 | MEDIUM | 6.5 | 0.4% | Jan 9, 2020 | Advisto PEEL Shopping 9.2.1 has CSRF via administrer/utilisateurs.php to delete a user. |
| CVE-2019-20372 | MEDIUM | 5.3 | 15.0% | Jan 9, 2020 | NGINX before 1.17.7, with certain error_page configurations, allows HTTP request smuggling, as demonstrated by the abili... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now