2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-19258 | MEDIUM | 5.3 | 0.9% | Jan 3, 2020 | GitLab Enterprise Edition (EE) 10.8 and later through 12.5 has Incorrect Access Control. |
| CVE-2019-19257 | MEDIUM | 5.3 | 0.9% | Jan 3, 2020 | GitLab Community Edition (CE) and Enterprise Edition (EE) through 12.5 has Incorrect Access Control (issue 1 of 2). |
| CVE-2019-19256 | MEDIUM | 5.3 | 0.9% | Jan 3, 2020 | GitLab Enterprise Edition (EE) 12.2 and later through 12.5 has Incorrect Access Control. |
| CVE-2019-19255 | MEDIUM | 4.3 | 0.8% | Jan 3, 2020 | GitLab Enterprise Edition (EE) 12.3 and later through 12.5 has Incorrect Access Control. |
| CVE-2019-19311 | MEDIUM | 5.4 | 0.7% | Jan 3, 2020 | GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 allows XSS in group and profile fields. |
| CVE-2019-19254 | MEDIUM | 5.3 | 1.1% | Jan 3, 2020 | GitLab Community Edition (CE) and Enterprise Edition (EE). 9.6 and later through 12.5 has Incorrect Access Control. |
| CVE-2019-19087 | MEDIUM | 4.3 | 0.7% | Jan 3, 2020 | Gitlab Enterprise Edition (EE) before 12.5.1 has Insecure Permissions (issue 2 of 2). |
| CVE-2019-19086 | MEDIUM | 4.3 | 0.7% | Jan 3, 2020 | Gitlab Enterprise Edition (EE) before 12.5.1 has Insecure Permissions (issue 1 of 2). |
| CVE-2019-19441 | MEDIUM | 6.5 | 0.3% | Jan 3, 2020 | HUAWEI P30 smart phones with versions earlier than 10.0.0.166(C00E66R1P11) have an information leak vulnerability. An at... |
| CVE-2019-10205 | MEDIUM | 6.3 | 0.3% | Jan 2, 2020 | A flaw was found in the way Red Hat Quay stores robot account tokens in plain text. An attacker able to perform database... |
| CVE-2019-20225 | MEDIUM | 6.1 | 0.6% | Jan 2, 2020 | MyBB before 1.8.22 allows an open redirect on login. |
| CVE-2019-14864 | MEDIUM | 6.5 | 1.9% | Jan 2, 2020 | Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the... |
| CVE-2019-14863 | MEDIUM | 6.1 | 1.4% | Jan 2, 2020 | There is a vulnerability in all angular versions before 1.5.0-beta.0, where after escaping the context of the web applic... |
| CVE-2019-14862 | MEDIUM | 6.1 | 2.0% | Jan 2, 2020 | There is a vulnerability in knockout before version 3.5.0-beta, where after escaping the context of the web application,... |
| CVE-2019-20223 | MEDIUM | 6.1 | 0.7% | Jan 2, 2020 | In Support Incident Tracker (SiT!) 3.67, the id parameter is affected by XSS on all endpoints that use this parameter, a... |
| CVE-2019-20222 | MEDIUM | 6.1 | 0.7% | Jan 2, 2020 | In Support Incident Tracker (SiT!) 3.67, the Short Application Name and Application Name inputs in the config.php page a... |
| CVE-2019-20221 | MEDIUM | 6.1 | 0.7% | Jan 2, 2020 | In Support Incident Tracker (SiT!) 3.67, Load Plugins input in the config.php page is affected by XSS. The XSS payload i... |
| CVE-2019-20220 | MEDIUM | 6.1 | 0.7% | Jan 2, 2020 | In Support Incident Tracker (SiT!) 3.67, the search_id parameter in the search_incidents_advanced.php page is affected b... |
| CVE-2019-20208 | MEDIUM | 5.5 | 1.5% | Jan 2, 2020 | dimC_Read in isomedia/box_code_3gpp.c in GPAC from 0.5.2 to 0.8.0 has a stack-based buffer overflow. |
| CVE-2019-20204 | MEDIUM | 5.4 | 3.4% | Jan 2, 2020 | The Postie plugin 1.9.40 for WordPress allows XSS, as demonstrated by a certain payload with jaVasCript:/* at the beginn... |
| CVE-2019-20203 | MEDIUM | 5.3 | 2.1% | Jan 2, 2020 | The Authorized Addresses feature in the Postie plugin 1.9.40 for WordPress allows remote attackers to publish posts by s... |
| CVE-2019-20202 | MEDIUM | 6.5 | 1.2% | Dec 31, 2019 | An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_char_content() tries to use realloc on a block ... |
| CVE-2019-20201 | MEDIUM | 6.5 | 1.2% | Dec 31, 2019 | An issue was discovered in ezXML 0.8.3 through 0.8.6. The ezxml_parse_* functions mishandle XML entities, leading to an ... |
| CVE-2019-20200 | MEDIUM | 6.5 | 1.2% | Dec 31, 2019 | An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_decode, while parsing crafted a XML file, perfo... |
| CVE-2019-20199 | MEDIUM | 6.5 | 1.2% | Dec 31, 2019 | An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_decode, while parsing a crafted XML file, perfo... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now