2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-19258MEDIUM5.3GitLab Enterprise Edition (EE) 10.8 and later through 12.5 has Incorrect Access Control.
CVE-2019-19257MEDIUM5.3GitLab Community Edition (CE) and Enterprise Edition (EE) through 12.5 has Incorrect Access Control (issue 1 of 2).
CVE-2019-19256MEDIUM5.3GitLab Enterprise Edition (EE) 12.2 and later through 12.5 has Incorrect Access Control.
CVE-2019-19255MEDIUM4.3GitLab Enterprise Edition (EE) 12.3 and later through 12.5 has Incorrect Access Control.
CVE-2019-19311MEDIUM5.4GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 allows XSS in group and profile fields.
CVE-2019-19254MEDIUM5.3GitLab Community Edition (CE) and Enterprise Edition (EE). 9.6 and later through 12.5 has Incorrect Access Control.
CVE-2019-19087MEDIUM4.3Gitlab Enterprise Edition (EE) before 12.5.1 has Insecure Permissions (issue 2 of 2).
CVE-2019-19086MEDIUM4.3Gitlab Enterprise Edition (EE) before 12.5.1 has Insecure Permissions (issue 1 of 2).
CVE-2019-19441MEDIUM6.5HUAWEI P30 smart phones with versions earlier than 10.0.0.166(C00E66R1P11) have an information leak vulnerability. An at...
CVE-2019-10205MEDIUM6.3A flaw was found in the way Red Hat Quay stores robot account tokens in plain text. An attacker able to perform database...
CVE-2019-20225MEDIUM6.1MyBB before 1.8.22 allows an open redirect on login.
CVE-2019-14864MEDIUM6.5Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the...
CVE-2019-14863MEDIUM6.1There is a vulnerability in all angular versions before 1.5.0-beta.0, where after escaping the context of the web applic...
CVE-2019-14862MEDIUM6.1There is a vulnerability in knockout before version 3.5.0-beta, where after escaping the context of the web application,...
CVE-2019-20223MEDIUM6.1In Support Incident Tracker (SiT!) 3.67, the id parameter is affected by XSS on all endpoints that use this parameter, a...
CVE-2019-20222MEDIUM6.1In Support Incident Tracker (SiT!) 3.67, the Short Application Name and Application Name inputs in the config.php page a...
CVE-2019-20221MEDIUM6.1In Support Incident Tracker (SiT!) 3.67, Load Plugins input in the config.php page is affected by XSS. The XSS payload i...
CVE-2019-20220MEDIUM6.1In Support Incident Tracker (SiT!) 3.67, the search_id parameter in the search_incidents_advanced.php page is affected b...
CVE-2019-20208MEDIUM5.5dimC_Read in isomedia/box_code_3gpp.c in GPAC from 0.5.2 to 0.8.0 has a stack-based buffer overflow.
CVE-2019-20204MEDIUM5.4The Postie plugin 1.9.40 for WordPress allows XSS, as demonstrated by a certain payload with jaVasCript:/* at the beginn...
CVE-2019-20203MEDIUM5.3The Authorized Addresses feature in the Postie plugin 1.9.40 for WordPress allows remote attackers to publish posts by s...
CVE-2019-20202MEDIUM6.5An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_char_content() tries to use realloc on a block ...
CVE-2019-20201MEDIUM6.5An issue was discovered in ezXML 0.8.3 through 0.8.6. The ezxml_parse_* functions mishandle XML entities, leading to an ...
CVE-2019-20200MEDIUM6.5An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_decode, while parsing crafted a XML file, perfo...
CVE-2019-20199MEDIUM6.5An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_decode, while parsing a crafted XML file, perfo...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now