2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-4410 | MEDIUM | 5.4 | 1.0% | Jul 1, 2019 | IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, and 19.0.0.1 is vulnerable to cross-site scripting. This ... |
| CVE-2019-4386 | MEDIUM | 6.5 | 2.1% | Jul 1, 2019 | IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1 could allow an authenticated user to execute a fu... |
| CVE-2019-4383 | MEDIUM | 6.7 | 0.4% | Jul 1, 2019 | When using IBM Spectrum Protect Plus 10.1.0, 10.1.2, and 10.1.3 to protect Oracle or MongoDB databases, a redirected res... |
| CVE-2019-4357 | MEDIUM | 6.7 | 0.5% | Jul 1, 2019 | When using IBM Spectrum Protect Plus 10.1.0, 10.1.2, and 10.1.3 to protect Oracle, DB2 or MongoDB databases, a redirecte... |
| CVE-2019-4337 | MEDIUM | 5.3 | 1.4% | Jul 1, 2019 | IBM Robotic Process Automation with Automation Anywhere 11 could allow an attacker to obtain sensitive information due t... |
| CVE-2019-4336 | CRITICAL | 9.8 | 2.0% | Jul 1, 2019 | IBM Robotic Process Automation with Automation Anywhere 11 uses an inadequate account lockout setting that could allow a... |
| CVE-2019-4322 | HIGH | 7.8 | 0.5% | Jul 1, 2019 | IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer ov... |
| CVE-2019-4299 | MEDIUM | 5.5 | 0.3% | Jul 1, 2019 | IBM Robotic Process Automation with Automation Anywhere 11 could allow a local user to obtain highly sensitive informati... |
| CVE-2019-4298 | HIGH | 7.1 | 0.3% | Jul 1, 2019 | IBM Robotic Process Automation with Automation Anywhere 11 uses a high privileged PostgreSQL account for database access... |
| CVE-2019-4297 | MEDIUM | 5.4 | 1.1% | Jul 1, 2019 | IBM Robotic Process Automation with Automation Anywhere 11 could allow a remote authenticated attacker to conduct an LDA... |
| CVE-2019-4296 | LOW | 3.3 | 0.3% | Jul 1, 2019 | IBM Robotic Process Automation with Automation Anywhere 11 information disclosure could allow a local user to obtain e-m... |
| CVE-2019-4295 | MEDIUM | 4.9 | 1.1% | Jul 1, 2019 | IBM Robotic Process Automation with Automation Anywhere 11 could allow an attacker with specialized access to obtain hig... |
| CVE-2019-4237 | MEDIUM | 5.4 | 0.7% | Jul 1, 2019 | A Cross-Frame Scripting vulnerability in IBM InfoSphere Information Server 11.3, 11.5, and 11.7 can allow an attacker to... |
| CVE-2019-4154 | HIGH | 7.8 | 0.5% | Jul 1, 2019 | IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer ov... |
| CVE-2019-4102 | MEDIUM | 5.9 | 1.2% | Jul 1, 2019 | IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.0 uses weaker than expected cr... |
| CVE-2019-4101 | MEDIUM | 5.5 | 0.4% | Jul 1, 2019 | IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.1, 10.5, and 11.1 is vulnerable to a denial of serv... |
| CVE-2019-4057 | MEDIUM | 6.7 | 0.5% | Jul 1, 2019 | IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow malicious user w... |
| CVE-2019-13129 | — | — | 1.4% | Jul 1, 2019 | On the Motorola router CX2L MWR04L 1.01, there is a stack consumption (infinite recursion) issue in scopd via TCP port 8... |
| CVE-2019-13128 | — | — | 7.7% | Jul 1, 2019 | An issue was discovered on D-Link DIR-823G devices with firmware 1.02B03. There is a command injection in HNAP1 (exploit... |
| CVE-2019-13127 | — | — | 1.5% | Jul 1, 2019 | An issue was discovered in mxGraph through 4.0.0, related to the "draw.io Diagrams" plugin before 8.3.14 for Confluence ... |
| CVE-2019-13125 | — | — | 1.0% | Jul 1, 2019 | HaboMalHunter through 2.0.0.3 in Tencent Habo allows attackers to evade dynamic malware analysis via PIE compilation. |
| CVE-2019-12781 | — | — | 1.7% | Jul 1, 2019 | An issue was discovered in Django 1.11 before 1.11.22, 2.1 before 2.1.10, and 2.2 before 2.2.3. An HTTP request is not r... |
| CVE-2019-12970 | — | — | 1.8% | Jul 1, 2019 | XSS was discovered in SquirrelMail through 1.4.22 and 1.5.x through 1.5.2. Due to improper handling of RCDATA and RAWTEX... |
| CVE-2019-13118 | MEDIUM | 5.3 | 5.1% | Jul 1, 2019 | In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an in... |
| CVE-2019-13117 | MEDIUM | 5.3 | 6.5% | Jul 1, 2019 | In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumb... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now