2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-4730 | HIGH | 7.1 | 2.0% | Jun 1, 2021 | IBM Cognos Analytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML da... |
| CVE-2019-4724 | HIGH | 7.5 | 2.4% | Jun 1, 2021 | IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain credentials from a user's browser via incorre... |
| CVE-2019-4723 | HIGH | 7.5 | 2.4% | Jun 1, 2021 | IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain credentials from a user's browser via incorre... |
| CVE-2019-4722 | MEDIUM | 4.3 | 1.4% | Jun 1, 2021 | IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain sensitive information via a stack trace due t... |
| CVE-2019-4653 | MEDIUM | 5.4 | 0.8% | Jun 1, 2021 | IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbit... |
| CVE-2019-4471 | MEDIUM | 6.5 | 1.0% | Jun 1, 2021 | IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain sensitive information, caused by the failure ... |
| CVE-2019-25030 | MEDIUM | 5.5 | 0.2% | May 26, 2021 | In Versa Director, Versa Analytics and VOS, Passwords are not hashed using an adaptive cryptographic hash function or ke... |
| CVE-2019-25029 | CRITICAL | 9.8 | 2.7% | May 26, 2021 | In Versa Director, the command injection is an attack in which the goal is execution of arbitrary commands on the host o... |
| CVE-2019-4588 | HIGH | 7.8 | 0.3% | May 26, 2021 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local us... |
| CVE-2019-14836 | HIGH | 8.8 | 0.6% | May 26, 2021 | A vulnerability was found that the 3scale dev portal does not employ mechanisms for protection against login CSRF. An at... |
| CVE-2019-12348 | CRITICAL | 9.8 | 1.7% | May 24, 2021 | An issue was discovered in zzcms 2019. SQL Injection exists in user/ztconfig.php via the daohang or img POST parameter. |
| CVE-2019-14827 | MEDIUM | 6.1 | 0.7% | May 17, 2021 | A vulnerability was found in Moodle where javaScript injection was possible in some Mustache templates via recursive ren... |
| CVE-2019-25044 | HIGH | 7.8 | 0.6% | May 14, 2021 | The block subsystem in the Linux kernel before 5.2 has a use-after-free that can lead to arbitrary code execution in the... |
| CVE-2019-10062 | MEDIUM | 6.1 | 1.4% | May 13, 2021 | The HTMLSanitizer class in html-sanitizer.ts in all released versions of the Aurelia framework 1.x repository is vulnera... |
| CVE-2019-19276 | MEDIUM | 5.3 | 1.0% | May 12, 2021 | A vulnerability has been identified in SIMATIC HMI Comfort Panels 1st Generation (incl. SIPLUS variants) (All versions <... |
| CVE-2019-25043 | MEDIUM | 5.3 | 1.2% | May 6, 2021 | ModSecurity 3.x before 3.0.4 mishandles key-value pair parsing, as demonstrated by a "string index out of range" error a... |
| CVE-2019-25042 | CRITICAL | 9.8 | 2.0% | Apr 27, 2021 | Unbound before 1.9.5 allows an out-of-bounds write via a compressed name in rdata_copy. NOTE: The vendor disputes that t... |
| CVE-2019-25041 | HIGH | 7.5 | 2.1% | Apr 27, 2021 | Unbound before 1.9.5 allows an assertion failure via a compressed name in dname_pkt_copy. NOTE: The vendor disputes that... |
| CVE-2019-25040 | HIGH | 7.5 | 2.0% | Apr 27, 2021 | Unbound before 1.9.5 allows an infinite loop via a compressed name in dname_pkt_copy. NOTE: The vendor disputes that thi... |
| CVE-2019-25039 | CRITICAL | 9.8 | 2.0% | Apr 27, 2021 | Unbound before 1.9.5 allows an integer overflow in a size calculation in respip/respip.c. NOTE: The vendor disputes that... |
| CVE-2019-25038 | CRITICAL | 9.8 | 2.0% | Apr 27, 2021 | Unbound before 1.9.5 allows an integer overflow in a size calculation in dnscrypt/dnscrypt.c. NOTE: The vendor disputes ... |
| CVE-2019-25037 | HIGH | 7.5 | 2.1% | Apr 27, 2021 | Unbound before 1.9.5 allows an assertion failure and denial of service in dname_pkt_copy via an invalid packet. NOTE: Th... |
| CVE-2019-25036 | HIGH | 7.5 | 2.0% | Apr 27, 2021 | Unbound before 1.9.5 allows an assertion failure and denial of service in synth_cname. NOTE: The vendor disputes that th... |
| CVE-2019-25035 | CRITICAL | 9.8 | 2.0% | Apr 27, 2021 | Unbound before 1.9.5 allows an out-of-bounds write in sldns_bget_token_par. NOTE: The vendor disputes that this is a vul... |
| CVE-2019-25034 | CRITICAL | 9.8 | 2.0% | Apr 27, 2021 | Unbound before 1.9.5 allows an integer overflow in sldns_str2wire_dname_buf_origin, leading to an out-of-bounds write. N... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now