2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-17151 | MEDIUM | 5.4 | 1.4% | Jan 7, 2020 | This vulnerability allows remote attackers redirect users to an external resource on affected installations of Tencent W... |
| CVE-2019-18652 | MEDIUM | 6.1 | 0.8% | Jan 7, 2020 | A DOM based XSS vulnerability has been identified on the WatchGuard XMT515 through 12.1.3, allowing a remote attacker to... |
| CVE-2019-6529 | MEDIUM | 4.9 | 1.0% | Jan 7, 2020 | An attacker could specially craft an FTP request that could crash the PR100088 Modbus gateway versions prior to release ... |
| CVE-2019-9465 | MEDIUM | 5.5 | 0.3% | Jan 7, 2020 | In the Titan M handling of cryptographic operations, there is a possible information disclosure due to an unusual root c... |
| CVE-2019-6700 | MEDIUM | 6.5 | 0.9% | Jan 7, 2020 | An information exposure vulnerability in the external authentication profile form of FortiSIEM 5.2.2 and earlier may all... |
| CVE-2019-16154 | MEDIUM | 6.1 | 0.7% | Jan 7, 2020 | An improper neutralization of input during web page generation in FortiAuthenticator WEB UI 6.0.0 may allow an unauthent... |
| CVE-2019-14879 | MEDIUM | 5.4 | 0.7% | Jan 7, 2020 | A vulnerability was found in Moodle versions 3.7.x before 3.7.3, 3.6.x before 3.6.7 and 3.5.x before 3.5.9. When a cohor... |
| CVE-2019-14854 | MEDIUM | 6.5 | 0.8% | Jan 7, 2020 | OpenShift Container Platform 4 does not sanitize secret data written to static pod logs when the log level in a given op... |
| CVE-2019-20348 | MEDIUM | 6.8 | 0.6% | Jan 6, 2020 | OKER G232V1 v1.03.02.20161129 devices provide a root terminal on a UART serial interface without proper access control. ... |
| CVE-2019-18842 | MEDIUM | 6.1 | 0.7% | Jan 6, 2020 | A cross-site scripting (XSS) vulnerability in the configuration web interface of the Jinan USR IOT USR-WIFI232-S/T/G2/H ... |
| CVE-2019-16271 | MEDIUM | 5.3 | 1.6% | Jan 6, 2020 | DTEN D5 and D7 before 1.3.2 devices allows remote attackers to read saved whiteboard image PDF documents via storage/emu... |
| CVE-2019-18179 | MEDIUM | 4.3 | 1.3% | Jan 6, 2020 | An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.12, and Community Edition 5.0.x through 5... |
| CVE-2019-16717 | MEDIUM | 6.1 | 1.5% | Jan 6, 2020 | OX App Suite through 7.10.2 has XSS. |
| CVE-2019-16716 | MEDIUM | 6.6 | 1.7% | Jan 6, 2020 | OX App Suite through 7.10.2 has Incorrect Access Control. |
| CVE-2019-9472 | MEDIUM | 5.5 | 0.1% | Jan 6, 2020 | In DCRYPTO_equals of compare.c, there is a possible timing attack due to improperly used crypto. This could lead to loca... |
| CVE-2019-9471 | MEDIUM | 6.7 | 0.2% | Jan 6, 2020 | In set_outbound_iatu of abc-pcie.c, there is a possible out of bounds write due to a missing bounds check. This could le... |
| CVE-2019-9470 | MEDIUM | 6.7 | 0.2% | Jan 6, 2020 | In dma_sblk_start of abc-pcie.c, there is a possible out of bounds write due to a missing bounds check. This could lead ... |
| CVE-2019-15603 | MEDIUM | 6.1 | 0.8% | Jan 6, 2020 | The seefl package v0.1.1 is vulnerable to a stored Cross-Site Scripting (XSS) vulnerability via a malicious filename ren... |
| CVE-2019-15602 | MEDIUM | 6.1 | 0.8% | Jan 6, 2020 | The fileview package v0.1.6 has inadequate output encoding and escaping, which leads to a stored Cross-Site Scripting (X... |
| CVE-2019-15999 | MEDIUM | 6.3 | 3.6% | Jan 6, 2020 | A vulnerability in the application environment of Cisco Data Center Network Manager (DCNM) could allow an authenticated,... |
| CVE-2019-15983 | MEDIUM | 4.9 | 1.3% | Jan 6, 2020 | A vulnerability in the SOAP API of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacke... |
| CVE-2019-5989 | MEDIUM | 6.1 | 0.8% | Jan 6, 2020 | DOM-based cross-site scripting vulnerability in Access analysis CGI An-Analyzer released in 2019 June 24 and earlier all... |
| CVE-2019-5988 | MEDIUM | 6.1 | 0.8% | Jan 6, 2020 | Stored cross-site scripting vulnerability in Access analysis CGI An-Analyzer released in 2019 June 24 and earlier allows... |
| CVE-2019-20354 | MEDIUM | 4.3 | 8.8% | Jan 6, 2020 | The web application component of piSignage before 2.6.4 allows a remote attacker (authenticated as a low-privilege user)... |
| CVE-2019-19265 | MEDIUM | 6.1 | 0.9% | Jan 6, 2020 | IceWarp WebMail Server 12.2.0 and 12.1.x before 12.2.1.1 (and probably earlier versions) allows XSS (issue 1 of 2) in no... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now