2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-19266MEDIUM5.4IceWarp WebMail Server 12.2.0 and 12.1.x before 12.2.1.1 (and probably earlier versions) allows XSS (issue 2 of 2) in no...
CVE-2019-20154MEDIUM6.1An issue was discovered in Determine (formerly Selectica) Contract Lifecycle Management (CLM) v5.4. A cross-site scripti...
CVE-2019-20153MEDIUM4.9An issue was discovered in Determine (formerly Selectica) Contract Lifecycle Management (CLM) in v5.4. An XML external e...
CVE-2019-20077MEDIUM4.3The Typesetter CMS 5.1 logout functionality is affected by a CSRF vulnerability. The logout function of the admin panel ...
CVE-2019-20336MEDIUM6.1In PHP Scripts Mall advanced-real-estate-script 4.0.9, the search-results.php searchtext parameter is vulnerable to XSS.
CVE-2019-19312MEDIUM5.8GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 has Incorrect Access Control. After a project changed to private, previo...
CVE-2019-20334MEDIUM5.5In Netwide Assembler (NASM) 2.14.02, stack consumption occurs in expr# functions in asm/eval.c. This potentially affects...
CVE-2019-5846MEDIUM6.5Out of bounds access in SwiftShader in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially expl...
CVE-2019-5845MEDIUM6.5Out of bounds access in SwiftShader in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially expl...
CVE-2019-5844MEDIUM6.5Out of bounds access in SwiftShader in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially expl...
CVE-2019-3768MEDIUM6.5RSA Authentication Manager versions prior to 8.4 P7 contain an XML Entity Injection Vulnerability. A remote authenticate...
CVE-2019-13766MEDIUM6.5Use-after-free in accessibility in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially exploit ...
CVE-2019-13765MEDIUM6.5Use-after-free in content delivery manager in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to potential...
CVE-2019-9542MEDIUM6.1: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in itemlookup.asp o...
CVE-2019-9541MEDIUM6.1: Information Exposure vulnerability in itemlookup.asp of Telos Automated Message Handling System allows a remote attack...
CVE-2019-9540MEDIUM6.1: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in prefs.asp of Tel...
CVE-2019-9539MEDIUM6.1: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ModalWindowPopup...
CVE-2019-9538MEDIUM6.1: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the LDAP cbURL p...
CVE-2019-9537MEDIUM6.1: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in uploaditem.asp o...
CVE-2019-19310MEDIUM4.9GitLab Enterprise Edition (EE) 9.0 and later through 12.5 allows Information Disclosure.
CVE-2019-19309MEDIUM4.3GitLab Enterprise Edition (EE) 8.90 and later through 12.5 has Incorrect Access Control.
CVE-2019-19263MEDIUM4.3GitLab Enterprise Edition (EE) 8.2 and later through 12.5 has Insecure Permissions.
CVE-2019-19262MEDIUM4.3GitLab Enterprise Edition (EE) 11.9 and later through 12.5 has Insecure Permissions.
CVE-2019-19260MEDIUM5.4GitLab Community Edition (CE) and Enterprise Edition (EE) through 12.5 has Incorrect Access Control (issue 2 of 2).
CVE-2019-19259MEDIUM4.3GitLab Enterprise Edition (EE) 11.3 and later through 12.5 allows an Insecure Direct Object Reference (IDOR).

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now