2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-12280 | — | — | 2.1% | Jun 25, 2019 | PC-Doctor Toolbox before 7.3 has an Uncontrolled Search Path Element. |
| CVE-2019-6329 | HIGH | 7.8 | 1.6% | Jun 25, 2019 | HP Support Assistant 8.7.50 and earlier allows a user to gain system privilege and allows unauthorized modification of d... |
| CVE-2019-6328 | — | — | 0.7% | Jun 25, 2019 | HP Support Assistant 8.7.50 and earlier allows a user to gain system privilege and allows unauthorized modification of d... |
| CVE-2019-4382 | MEDIUM | 5.3 | 7.8% | Jun 25, 2019 | IBM API Connect 5.0.0.0 through 5.0.8.6 could allow an unauthorized user to obtain sensitive information about the syste... |
| CVE-2019-4377 | MEDIUM | 4.3 | 1.3% | Jun 25, 2019 | IBM Sterling B2B Integrator 6.0.0.0 and 6.0.0.1 reveals sensitive information from a stack trace that could be used in f... |
| CVE-2019-4158 | MEDIUM | 5.4 | 0.7% | Jun 25, 2019 | IBM Security Access Manager 9.0.1 through 9.0.6 does not prove that a user's identity is correct which can lead to the e... |
| CVE-2019-4157 | MEDIUM | 6.1 | 0.9% | Jun 25, 2019 | IBM Security Access Manager 9.0.1 through 9.0.6 is vulnerable to cross-site scripting. This vulnerability allows users t... |
| CVE-2019-4156 | MEDIUM | 5.9 | 0.9% | Jun 25, 2019 | IBM Security Access Manager 9.0.1 through 9.0.6 uses weaker than expected cryptographic algorithms that could allow an a... |
| CVE-2019-4153 | MEDIUM | 6.8 | 1.0% | Jun 25, 2019 | IBM Security Access Manager 9.0.1 through 9.0.6 could allow a remote attacker to conduct phishing attacks, using an open... |
| CVE-2019-4152 | MEDIUM | 4.4 | 0.3% | Jun 25, 2019 | IBM Security Access Manager 9.0.1 through 9.0.6 does not invalidate session tokens in a timely manner. The lack of prope... |
| CVE-2019-4151 | MEDIUM | 5.9 | 0.9% | Jun 25, 2019 | IBM Security Access Manager 9.0.1 through 9.0.6 uses weaker than expected cryptographic algorithms that could allow an a... |
| CVE-2019-4150 | LOW | 3.7 | 0.6% | Jun 25, 2019 | IBM Security Access Manager 9.0.1 through 9.0.6 does not validate, or incorrectly validates, a certificate which could a... |
| CVE-2019-4145 | HIGH | 7.1 | 0.4% | Jun 25, 2019 | IBM Security Access Manager 9.0.1 through 9.0.6 could reveal highly sensitive in specialized conditions to a local user ... |
| CVE-2019-4135 | HIGH | 8.8 | 1.5% | Jun 25, 2019 | IBM Security Access Manager 9.0.1 through 9.0.6 is affected by a security vulnerability that could allow authenticated u... |
| CVE-2019-12964 | — | — | 0.8% | Jun 25, 2019 | LiveZilla Server before 8.0.1.1 is vulnerable to XSS in the ticket.php Subject. |
| CVE-2019-12963 | — | — | 0.8% | Jun 25, 2019 | LiveZilla Server before 8.0.1.1 is vulnerable to XSS in the chat.php Create Ticket Action. |
| CVE-2019-12962 | MEDIUM | 6.1 | 9.1% | Jun 25, 2019 | LiveZilla Server before 8.0.1.1 is vulnerable to XSS in mobile/index.php via the Accept-Language HTTP header. |
| CVE-2019-12961 | — | — | 1.4% | Jun 25, 2019 | LiveZilla Server before 8.0.1.1 is vulnerable to CSV Injection in the Export Function. |
| CVE-2019-12960 | — | — | 1.4% | Jun 25, 2019 | LiveZilla Server before 8.0.1.1 is vulnerable to SQL Injection in functions.internal.build.inc.php via the parameter p_d... |
| CVE-2019-12817 | HIGH | 7 | 0.4% | Jun 25, 2019 | arch/powerpc/mm/mmu_context_book3s64.c in the Linux kernel before 5.1.15 for powerpc has a bug where unrelated processes... |
| CVE-2019-12949 | — | — | 3.0% | Jun 25, 2019 | In pfSense 2.4.4-p2 and 2.4.4-p3, if it is possible to trick an authenticated administrator into clicking on a button on... |
| CVE-2019-12958 | — | — | 1.2% | Jun 25, 2019 | In Xpdf 4.01.01, a heap-based buffer over-read could be triggered in FoFiType1C::convertToType0 in fofi/FoFiType1C.cc wh... |
| CVE-2019-12957 | HIGH | 7.8 | 1.2% | Jun 25, 2019 | In Xpdf 4.01.01, a buffer over-read could be triggered in FoFiType1C::convertToType1 in fofi/FoFiType1C.cc when the inde... |
| CVE-2019-12951 | — | — | 2.0% | Jun 24, 2019 | An issue was discovered in Mongoose before 6.15. The parse_mqtt() function in mg_mqtt.c has a critical heap-based buffer... |
| CVE-2019-10689 | — | — | 0.7% | Jun 24, 2019 | VVX products using UCS software version 5.9.2 and earlier with Better Together over Ethernet Connector (BToE) applicatio... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now