2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-20141 | MEDIUM | 6.1 | 4.3% | Dec 30, 2019 | An XSS issue was discovered in the Laborator Neon theme 2.0 for WordPress via the data/autosuggest-remote.php q paramete... |
| CVE-2019-19806 | MEDIUM | 5.3 | 1.0% | Dec 30, 2019 | _account_forgot_password.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 displays a message indicating whether an em... |
| CVE-2019-19805 | MEDIUM | 5.3 | 1.0% | Dec 30, 2019 | _account_forgot_password.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 takes a different amount of time to return ... |
| CVE-2019-19738 | MEDIUM | 6.1 | 0.7% | Dec 30, 2019 | log_file_viewer.php in MFScripts YetiShare 3.5.2 through 4.5.3 does not sanitize or encode the output from the lFile par... |
| CVE-2019-19736 | MEDIUM | 6.1 | 0.6% | Dec 30, 2019 | MFScripts YetiShare 3.5.2 through 4.5.3 does not set the HttpOnly flag on session cookies, allowing the cookie to be rea... |
| CVE-2019-19733 | MEDIUM | 6.1 | 0.7% | Dec 30, 2019 | _get_all_file_server_paths.ajax.php (aka get_all_file_server_paths.ajax.php) in MFScripts YetiShare 3.5.2 through 4.5.3 ... |
| CVE-2019-4655 | MEDIUM | 4.3 | 1.2% | Dec 30, 2019 | IBM MQ 9.1.0.0, 9.1.0.1, 9.1.0.2, 9.1.0.3, 9.1.1, 9.1.2, and 9.1.3 is vulnerable to a denial of service attack that woul... |
| CVE-2019-4623 | MEDIUM | 5.4 | 0.7% | Dec 30, 2019 | IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbit... |
| CVE-2019-4343 | MEDIUM | 6.5 | 1.5% | Dec 30, 2019 | IBM Cognos Analytics 11.0 and 11.1 allows overly permissive cross-origin resource sharing which could allow an attacker ... |
| CVE-2019-4335 | MEDIUM | 5.5 | 0.3% | Dec 30, 2019 | IBM Watson Studio Local 1.2.3 stores key files in the user's home directory which could be obtained by another local use... |
| CVE-2019-20139 | MEDIUM | 5.4 | 26.1% | Dec 30, 2019 | In Nagios XI 5.6.9, XSS exists via the nocscreenapi.php host, hostgroup, or servicegroup parameter, or the schedulerepor... |
| CVE-2019-15024 | MEDIUM | 6.5 | 0.9% | Dec 30, 2019 | In all versions of ClickHouse before 19.14.3, an attacker having write access to ZooKeeper and who is able to run a cust... |
| CVE-2019-20096 | MEDIUM | 5.5 | 1.0% | Dec 30, 2019 | In the Linux kernel before 5.1, there is a memory leak in __feat_register_sp() in net/dccp/feat.c, which may cause denia... |
| CVE-2019-20095 | MEDIUM | 5.5 | 0.4% | Dec 30, 2019 | mwifiex_tm_cmd in drivers/net/wireless/marvell/mwifiex/cfg80211.c in the Linux kernel before 5.1.6 has some error-handli... |
| CVE-2019-20093 | MEDIUM | 5.5 | 1.4% | Dec 30, 2019 | The PoDoFo::PdfVariant::DelayedLoad function in PdfVariant.h in PoDoFo 0.9.6 allows remote attackers to cause a denial o... |
| CVE-2019-20092 | MEDIUM | 5.5 | 0.8% | Dec 30, 2019 | An issue was discovered in Bento4 1.5.1.0. There is a NULL pointer dereference in AP4_Descriptor::GetTag in mp42ts when ... |
| CVE-2019-20091 | MEDIUM | 5.5 | 0.8% | Dec 30, 2019 | An issue was discovered in Bento4 1.5.1.0. There is a NULL pointer dereference in AP4_Descriptor::GetTag in mp42ts when ... |
| CVE-2019-20076 | MEDIUM | 6.1 | 1.4% | Dec 30, 2019 | On Netis DL4323 devices, XSS exists via the form2Ddns.cgi username parameter (DynDns settings of the Dynamic DNS Configu... |
| CVE-2019-20075 | MEDIUM | 6.1 | 1.5% | Dec 30, 2019 | On Netis DL4323 devices, pingrtt_v6.html has XSS (Ping6 Diagnostic). |
| CVE-2019-20073 | MEDIUM | 6.1 | 1.5% | Dec 30, 2019 | On Netis DL4323 devices, XSS exists via the form2userconfig.cgi username parameter (User Account Configuration). |
| CVE-2019-20072 | MEDIUM | 6.1 | 1.4% | Dec 30, 2019 | On Netis DL4323 devices, XSS exists via the form2Ddns.cgi hostname parameter (Dynamic DNS Configuration). |
| CVE-2019-20071 | MEDIUM | 6.5 | 0.7% | Dec 30, 2019 | On Netis DL4323 devices, CSRF exists via form2logaction.cgi to delete all logs. |
| CVE-2019-20070 | MEDIUM | 6.1 | 1.4% | Dec 30, 2019 | On Netis DL4323 devices, XSS exists via the urlFQDN parameter to form2url.cgi (aka the Keyword field of the URL Blocking... |
| CVE-2019-20058 | MEDIUM | 6.1 | 0.7% | Dec 29, 2019 | Bolt 3.7.0, if Symfony Web Profiler is used, allows XSS because unsanitized search?search= input is shown on the _profil... |
| CVE-2019-20056 | MEDIUM | 6.5 | 0.9% | Dec 29, 2019 | stb_image.h (aka the stb image loader) 2.23, as used in libsixel and other products, has an assertion failure in stbi__s... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now