2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-0330CRITICAL9.1The OS Command Plugin in the transaction GPA_ADMIN and the OSCommand Console of SAP Diagnostic Agent (LM-Service), versi...
CVE-2019-0329SAP Information Steward, version 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scrip...
CVE-2019-0328ABAP Tests Modules (SAP Basis, versions 7.0, 7.1, 7.3, 7.31, 7.4, 7.5) of SAP NetWeaver Process Integration enables an a...
CVE-2019-0327SAP NetWeaver for Java Application Server - Web Container, (engineapi, versions 7.1, 7.2, 7.3, 7.31, 7.4 and 7.5), (serv...
CVE-2019-0326SAP BusinessObjects Business Intelligence Platform (BI Workspace) (Enterprise), versions 4.1, 4.2, 4.3, does not suffici...
CVE-2019-0325SAP ERP HCM (SAP_HRCES) , version 3, does not perform necessary authorization checks for a report that reads payroll dat...
CVE-2019-13132CRITICAL9.8In ZeroMQ libzmq before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.3.2, a remote, unauthenticated client connecting t...
CVE-2019-11650MEDIUM5.9A potential Man in the Middle attack (MITM) was found in NetIQ Advanced Authentication Framework versions prior to 6.0.
CVE-2019-0322SAP Commerce Cloud (previously known as SAP Hybris Commerce), (HY_COM, versions 6.3, 6.4, 6.5, 6.6, 6.7, 1808, 1811), al...
CVE-2019-0321ABAP Server and ABAP Platform (SAP Basis), versions, 7.31, 7.4, 7.5, do not sufficiently encode user-controlled inputs, ...
CVE-2019-0319The SAP Gateway, versions 7.5, 7.51, 7.52 and 7.53, allows an attacker to inject content which is displayed in the form ...
CVE-2019-0318Under certain conditions SAP NetWeaver Application Server for Java (Startup Framework), versions 7.21, 7.22, 7.45, 7.49,...
CVE-2019-0281SAPUI5 and OpenUI5, before versions 1.38.39, 1.44.39, 1.52.25, 1.60.6 and 1.63.0, does not sufficiently encode user-cont...
CVE-2019-5221There is a path traversal vulnerability on Huawei Share. The software does not properly validate the path, an attacker c...
CVE-2019-5220There is a Factory Reset Protection (FRP) bypass vulnerability on several smartphones. The system does not sufficiently ...
CVE-2019-1873HIGH8.6A vulnerability in the cryptographic driver for Cisco Adaptive Security Appliance Software (ASA) and Firepower Threat De...
CVE-2019-10966MEDIUM5.3In GE Aestiva and Aespire versions 7100 and 7900, a vulnerability exists where serial devices are connected via an added...
CVE-2019-13279TRENDnet TEW-827DRU with firmware up to and including 2.04B03 contains multiple stack-based buffer overflows when proces...
CVE-2019-13278TRENDnet TEW-827DRU with firmware up to and including 2.04B03 contains multiple command injections when processing user ...
CVE-2019-13276TRENDnet TEW-827DRU with firmware up to and including 2.04B03 contains a stack-based buffer overflow in the ssi binary. ...
CVE-2019-13122A Cross Site Scripting (XSS) vulnerability exists in the template tag used to render message ids in Patchwork v1.1 throu...
CVE-2019-12470Wikimedia MediaWiki through 1.32.1 has Incorrect Access Control. Suppressed log in RevisionDelete page is exposed. Fixed...
CVE-2019-12469MediaWiki through 1.32.1 has Incorrect Access Control. Suppressed username or log in Special:EditTags are exposed. Fixed...
CVE-2019-12474Wikimedia MediaWiki 1.23.0 through 1.32.1 has an information leak. Privileged API responses that include whether a recen...
CVE-2019-12473Wikimedia MediaWiki 1.27.0 through 1.32.1 might allow DoS. Passing invalid titles to the API could cause a DoS by queryi...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now