2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-20180MEDIUM6.8The TablePress plugin 1.9.2 for WordPress allows tablepress[data] CSV injection by Editor users. Note: The vendor disput...
CVE-2019-18859MEDIUM6.1Digi AnywhereUSB 14 allows XSS via a link for the Digi Page.
CVE-2019-6332MEDIUM4.8A potential security vulnerability has been identified with certain HP InkJet printers. The vulnerability could be explo...
CVE-2019-14918MEDIUM5.4XSS in the DHCP lease-status table in Billion Smart Energy Router SG600R2 Firmware v3.02.rc6 allows an attacker to injec...
CVE-2019-19332MEDIUM6.1An out-of-bounds memory write issue was found in the Linux Kernel, version 3.13 through 5.4, in the way the Linux kernel...
CVE-2019-11292MEDIUM6.5Pivotal Ops Manager, versions 2.4.x prior to 2.4.27, 2.5.x prior to 2.5.24, 2.6.x prior to 2.6.16, and 2.7.x prior to 2....
CVE-2019-17023MEDIUM6.5After a HelloRetryRequest has been sent, the client may negotiate a lower protocol that TLS 1.3, resulting in an invalid...
CVE-2019-17022MEDIUM6.1When pasting a <style> tag from the clipboard into a rich text editor, the CSS sanitizer does not escape < and ...
CVE-2019-17021MEDIUM5.3During the initialization of a new content process, a race condition occurs that can allow a content process to disclose...
CVE-2019-17020MEDIUM6.5If an XML file is served with a Content Security Policy and the XML file includes an XSL stylesheet, the Content Securit...
CVE-2019-17018MEDIUM5.3When in Private Browsing Mode on Windows 10, the Windows keyboard may retain word suggestions to improve the accuracy of...
CVE-2019-17016MEDIUM6.1When pasting a <style> tag from the clipboard into a rich text editor, the CSS sanitizer incorrectly rewrites a @n...
CVE-2019-17002MEDIUM4.3If upgrade-insecure-requests was specified in the Content Security Policy, and a link was dragged and dropped from that ...
CVE-2019-17001MEDIUM6.1A Content-Security-Policy that blocks in-line scripts could be bypassed using an object tag to execute JavaScript in the...
CVE-2019-17000MEDIUM6.1An object tag with a data URI did not correctly inherit the document's Content Security Policy. This allowed a CSP bypas...
CVE-2019-11765MEDIUM6.5A compromised content process could send a message to the parent process that would cause the 'Click to Play' permission...
CVE-2019-11763MEDIUM6.1Failure to correctly handle null bytes when processing HTML entities resulted in Firefox incorrectly parsing these entit...
CVE-2019-11762MEDIUM6.1If two same-origin documents set document.domain differently to become cross-origin, it was possible for them to call ar...
CVE-2019-11761MEDIUM5.4By using a form with a data URI it was possible to gain access to the privileged JSONView object that had been cloned in...
CVE-2019-20366MEDIUM6.1An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via isTrustStore to Manage Store Contents.
CVE-2019-20365MEDIUM6.1An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via search to the Users/Group search page.
CVE-2019-20364MEDIUM6.1An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via cacheName to SystemCacheDetails.jsp.
CVE-2019-20363MEDIUM6.1An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via alias to Manage Store Contents.
CVE-2019-5188MEDIUM6.7A code execution vulnerability exists in the directory rehashing functionality of E2fsprogs e2fsck 1.45.4. A specially c...
CVE-2019-14820MEDIUM4.3It was found that keycloak before version 8.0.0 exposes internal adapter endpoints in org.keycloak.constants.AdapterCons...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now