2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-17151MEDIUM5.4This vulnerability allows remote attackers redirect users to an external resource on affected installations of Tencent W...
CVE-2019-18652MEDIUM6.1A DOM based XSS vulnerability has been identified on the WatchGuard XMT515 through 12.1.3, allowing a remote attacker to...
CVE-2019-6529MEDIUM4.9An attacker could specially craft an FTP request that could crash the PR100088 Modbus gateway versions prior to release ...
CVE-2019-9465MEDIUM5.5In the Titan M handling of cryptographic operations, there is a possible information disclosure due to an unusual root c...
CVE-2019-6700MEDIUM6.5An information exposure vulnerability in the external authentication profile form of FortiSIEM 5.2.2 and earlier may all...
CVE-2019-16154MEDIUM6.1An improper neutralization of input during web page generation in FortiAuthenticator WEB UI 6.0.0 may allow an unauthent...
CVE-2019-14879MEDIUM5.4A vulnerability was found in Moodle versions 3.7.x before 3.7.3, 3.6.x before 3.6.7 and 3.5.x before 3.5.9. When a cohor...
CVE-2019-14854MEDIUM6.5OpenShift Container Platform 4 does not sanitize secret data written to static pod logs when the log level in a given op...
CVE-2019-20348MEDIUM6.8OKER G232V1 v1.03.02.20161129 devices provide a root terminal on a UART serial interface without proper access control. ...
CVE-2019-18842MEDIUM6.1A cross-site scripting (XSS) vulnerability in the configuration web interface of the Jinan USR IOT USR-WIFI232-S/T/G2/H ...
CVE-2019-16271MEDIUM5.3DTEN D5 and D7 before 1.3.2 devices allows remote attackers to read saved whiteboard image PDF documents via storage/emu...
CVE-2019-18179MEDIUM4.3An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.12, and Community Edition 5.0.x through 5...
CVE-2019-16717MEDIUM6.1OX App Suite through 7.10.2 has XSS.
CVE-2019-16716MEDIUM6.6OX App Suite through 7.10.2 has Incorrect Access Control.
CVE-2019-9472MEDIUM5.5In DCRYPTO_equals of compare.c, there is a possible timing attack due to improperly used crypto. This could lead to loca...
CVE-2019-9471MEDIUM6.7In set_outbound_iatu of abc-pcie.c, there is a possible out of bounds write due to a missing bounds check. This could le...
CVE-2019-9470MEDIUM6.7In dma_sblk_start of abc-pcie.c, there is a possible out of bounds write due to a missing bounds check. This could lead ...
CVE-2019-15603MEDIUM6.1The seefl package v0.1.1 is vulnerable to a stored Cross-Site Scripting (XSS) vulnerability via a malicious filename ren...
CVE-2019-15602MEDIUM6.1The fileview package v0.1.6 has inadequate output encoding and escaping, which leads to a stored Cross-Site Scripting (X...
CVE-2019-15999MEDIUM6.3A vulnerability in the application environment of Cisco Data Center Network Manager (DCNM) could allow an authenticated,...
CVE-2019-15983MEDIUM4.9A vulnerability in the SOAP API of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacke...
CVE-2019-5989MEDIUM6.1DOM-based cross-site scripting vulnerability in Access analysis CGI An-Analyzer released in 2019 June 24 and earlier all...
CVE-2019-5988MEDIUM6.1Stored cross-site scripting vulnerability in Access analysis CGI An-Analyzer released in 2019 June 24 and earlier allows...
CVE-2019-20354MEDIUM4.3The web application component of piSignage before 2.6.4 allows a remote attacker (authenticated as a low-privilege user)...
CVE-2019-19265MEDIUM6.1IceWarp WebMail Server 12.2.0 and 12.1.x before 12.2.1.1 (and probably earlier versions) allows XSS (issue 1 of 2) in no...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now