2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-4410MEDIUM5.4IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, and 19.0.0.1 is vulnerable to cross-site scripting. This ...
CVE-2019-4386MEDIUM6.5IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1 could allow an authenticated user to execute a fu...
CVE-2019-4383MEDIUM6.7When using IBM Spectrum Protect Plus 10.1.0, 10.1.2, and 10.1.3 to protect Oracle or MongoDB databases, a redirected res...
CVE-2019-4357MEDIUM6.7When using IBM Spectrum Protect Plus 10.1.0, 10.1.2, and 10.1.3 to protect Oracle, DB2 or MongoDB databases, a redirecte...
CVE-2019-4337MEDIUM5.3IBM Robotic Process Automation with Automation Anywhere 11 could allow an attacker to obtain sensitive information due t...
CVE-2019-4336CRITICAL9.8IBM Robotic Process Automation with Automation Anywhere 11 uses an inadequate account lockout setting that could allow a...
CVE-2019-4322HIGH7.8IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer ov...
CVE-2019-4299MEDIUM5.5IBM Robotic Process Automation with Automation Anywhere 11 could allow a local user to obtain highly sensitive informati...
CVE-2019-4298HIGH7.1IBM Robotic Process Automation with Automation Anywhere 11 uses a high privileged PostgreSQL account for database access...
CVE-2019-4297MEDIUM5.4IBM Robotic Process Automation with Automation Anywhere 11 could allow a remote authenticated attacker to conduct an LDA...
CVE-2019-4296LOW3.3IBM Robotic Process Automation with Automation Anywhere 11 information disclosure could allow a local user to obtain e-m...
CVE-2019-4295MEDIUM4.9IBM Robotic Process Automation with Automation Anywhere 11 could allow an attacker with specialized access to obtain hig...
CVE-2019-4237MEDIUM5.4A Cross-Frame Scripting vulnerability in IBM InfoSphere Information Server 11.3, 11.5, and 11.7 can allow an attacker to...
CVE-2019-4154HIGH7.8IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer ov...
CVE-2019-4102MEDIUM5.9IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.0 uses weaker than expected cr...
CVE-2019-4101MEDIUM5.5IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.1, 10.5, and 11.1 is vulnerable to a denial of serv...
CVE-2019-4057MEDIUM6.7IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow malicious user w...
CVE-2019-13129On the Motorola router CX2L MWR04L 1.01, there is a stack consumption (infinite recursion) issue in scopd via TCP port 8...
CVE-2019-13128An issue was discovered on D-Link DIR-823G devices with firmware 1.02B03. There is a command injection in HNAP1 (exploit...
CVE-2019-13127An issue was discovered in mxGraph through 4.0.0, related to the "draw.io Diagrams" plugin before 8.3.14 for Confluence ...
CVE-2019-13125HaboMalHunter through 2.0.0.3 in Tencent Habo allows attackers to evade dynamic malware analysis via PIE compilation.
CVE-2019-12781An issue was discovered in Django 1.11 before 1.11.22, 2.1 before 2.1.10, and 2.2 before 2.2.3. An HTTP request is not r...
CVE-2019-12970XSS was discovered in SquirrelMail through 1.4.22 and 1.5.x through 1.5.2. Due to improper handling of RCDATA and RAWTEX...
CVE-2019-13118MEDIUM5.3In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an in...
CVE-2019-13117MEDIUM5.3In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumb...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now