2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-0330 | CRITICAL | 9.1 | 2.2% | Jul 10, 2019 | The OS Command Plugin in the transaction GPA_ADMIN and the OSCommand Console of SAP Diagnostic Agent (LM-Service), versi... |
| CVE-2019-0329 | — | — | 1.3% | Jul 10, 2019 | SAP Information Steward, version 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scrip... |
| CVE-2019-0328 | — | — | 3.4% | Jul 10, 2019 | ABAP Tests Modules (SAP Basis, versions 7.0, 7.1, 7.3, 7.31, 7.4, 7.5) of SAP NetWeaver Process Integration enables an a... |
| CVE-2019-0327 | — | — | 2.1% | Jul 10, 2019 | SAP NetWeaver for Java Application Server - Web Container, (engineapi, versions 7.1, 7.2, 7.3, 7.31, 7.4 and 7.5), (serv... |
| CVE-2019-0326 | — | — | 1.3% | Jul 10, 2019 | SAP BusinessObjects Business Intelligence Platform (BI Workspace) (Enterprise), versions 4.1, 4.2, 4.3, does not suffici... |
| CVE-2019-0325 | — | — | 0.8% | Jul 10, 2019 | SAP ERP HCM (SAP_HRCES) , version 3, does not perform necessary authorization checks for a report that reads payroll dat... |
| CVE-2019-13132 | CRITICAL | 9.8 | 42.5% | Jul 10, 2019 | In ZeroMQ libzmq before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.3.2, a remote, unauthenticated client connecting t... |
| CVE-2019-11650 | MEDIUM | 5.9 | 0.8% | Jul 10, 2019 | A potential Man in the Middle attack (MITM) was found in NetIQ Advanced Authentication Framework versions prior to 6.0. |
| CVE-2019-0322 | — | — | 2.6% | Jul 10, 2019 | SAP Commerce Cloud (previously known as SAP Hybris Commerce), (HY_COM, versions 6.3, 6.4, 6.5, 6.6, 6.7, 1808, 1811), al... |
| CVE-2019-0321 | — | — | 1.3% | Jul 10, 2019 | ABAP Server and ABAP Platform (SAP Basis), versions, 7.31, 7.4, 7.5, do not sufficiently encode user-controlled inputs, ... |
| CVE-2019-0319 | — | — | 2.5% | Jul 10, 2019 | The SAP Gateway, versions 7.5, 7.51, 7.52 and 7.53, allows an attacker to inject content which is displayed in the form ... |
| CVE-2019-0318 | — | — | 1.4% | Jul 10, 2019 | Under certain conditions SAP NetWeaver Application Server for Java (Startup Framework), versions 7.21, 7.22, 7.45, 7.49,... |
| CVE-2019-0281 | — | — | 1.3% | Jul 10, 2019 | SAPUI5 and OpenUI5, before versions 1.38.39, 1.44.39, 1.52.25, 1.60.6 and 1.63.0, does not sufficiently encode user-cont... |
| CVE-2019-5221 | — | — | 0.5% | Jul 10, 2019 | There is a path traversal vulnerability on Huawei Share. The software does not properly validate the path, an attacker c... |
| CVE-2019-5220 | — | — | 0.2% | Jul 10, 2019 | There is a Factory Reset Protection (FRP) bypass vulnerability on several smartphones. The system does not sufficiently ... |
| CVE-2019-1873 | HIGH | 8.6 | 2.5% | Jul 10, 2019 | A vulnerability in the cryptographic driver for Cisco Adaptive Security Appliance Software (ASA) and Firepower Threat De... |
| CVE-2019-10966 | MEDIUM | 5.3 | 1.3% | Jul 10, 2019 | In GE Aestiva and Aespire versions 7100 and 7900, a vulnerability exists where serial devices are connected via an added... |
| CVE-2019-13279 | — | — | 2.7% | Jul 10, 2019 | TRENDnet TEW-827DRU with firmware up to and including 2.04B03 contains multiple stack-based buffer overflows when proces... |
| CVE-2019-13278 | — | — | 8.8% | Jul 10, 2019 | TRENDnet TEW-827DRU with firmware up to and including 2.04B03 contains multiple command injections when processing user ... |
| CVE-2019-13276 | — | — | 2.8% | Jul 10, 2019 | TRENDnet TEW-827DRU with firmware up to and including 2.04B03 contains a stack-based buffer overflow in the ssi binary. ... |
| CVE-2019-13122 | — | — | 1.3% | Jul 10, 2019 | A Cross Site Scripting (XSS) vulnerability exists in the template tag used to render message ids in Patchwork v1.1 throu... |
| CVE-2019-12470 | — | — | 1.4% | Jul 10, 2019 | Wikimedia MediaWiki through 1.32.1 has Incorrect Access Control. Suppressed log in RevisionDelete page is exposed. Fixed... |
| CVE-2019-12469 | — | — | 1.4% | Jul 10, 2019 | MediaWiki through 1.32.1 has Incorrect Access Control. Suppressed username or log in Special:EditTags are exposed. Fixed... |
| CVE-2019-12474 | — | — | 2.0% | Jul 10, 2019 | Wikimedia MediaWiki 1.23.0 through 1.32.1 has an information leak. Privileged API responses that include whether a recen... |
| CVE-2019-12473 | — | — | 2.3% | Jul 10, 2019 | Wikimedia MediaWiki 1.27.0 through 1.32.1 might allow DoS. Passing invalid titles to the API could cause a DoS by queryi... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now