2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-11295Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca...
CVE-2019-16961MEDIUM5.4SolarWinds Web Help Desk 12.7.0 allows XSS via a Schedule Name.
CVE-2019-4702HIGH8.1IBM Security Guardium Data Encryption (GDE) 3.0.0.2 specifies permissions for a security-critical resource in a way that...
CVE-2019-4687MEDIUM5.3IBM Security Guardium Data Encryption (GDE) 3.0.0.2 stores sensitive information in URL parameters. This may lead to inf...
CVE-2019-4160HIGH7.5IBM Security Guardium Data Encryption (GDE) 3.0.0.2 uses weaker than expected cryptographic algorithms that could allow ...
CVE-2019-3405MEDIUM5.3In the 3.1.3.64296 and lower version of 360F5, the third party can trigger the device to send a deauth frame by construc...
CVE-2019-18643CRITICAL9.8Rock RMS versions before 8.10 and versions 9.0 through 9.3 fails to properly validate files uploaded in the application....
CVE-2019-18642CRITICAL9.8Rock RMS version before 8.6 is vulnerable to account takeover by tampering with the user ID parameter in the profile upd...
CVE-2019-16962MEDIUM5.4Zoho ManageEngine Desktop Central 10.0.430 allows HTML injection via a modified Report Name in a New Custom Report.
CVE-2019-16954MEDIUM5.4SolarWinds Web Help Desk 12.7.0 allows HTML injection via a Comment in a Help Request ticket.
CVE-2019-20484HIGH8.1An issue was discovered in Viki Vera 4.9.1.26180. A user without access to a project could download or upload project fi...
CVE-2019-20483MEDIUM5.4An issue was discovered in Viki Vera 4.9.1.26180. An attacker could set a user's last name to an XSS Payload, and read a...
CVE-2019-4728HIGH8.8IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5_2, 6.0.0.0 through 6.0.3.2, and 6.1.0.0 could allow...
CVE-2019-25013MEDIUM5.9The iconv feature in the GNU C Library (aka glibc or libc6) through 2.32, when processing invalid multi-byte input seque...
CVE-2019-16960MEDIUM5.4SolarWinds Web Help Desk 12.7.0 allows XSS via a CSV template file with a crafted Location Name field.
CVE-2019-16956MEDIUM5.4SolarWinds Web Help Desk 12.7.0 allows XSS via the Request Type parameter of a ticket.
CVE-2019-25012HIGH7.5The Webform Report project 7.x-1.x-dev for Drupal allows remote attackers to view submissions by visiting the /rss.xml p...
CVE-2019-25011MEDIUM5.4NetBox through 2.6.2 allows an Authenticated User to conduct an XSS attack against an admin via a GFM-rendered field, as...
CVE-2019-25010CRITICAL9.8An issue was discovered in the failure crate through 2019-11-13 for Rust. Type confusion can occur when __private_get_ty...
CVE-2019-25009CRITICAL9.8An issue was discovered in the http crate before 0.1.20 for Rust. The HeaderMap::Drain API can use a raw pointer, defeat...
CVE-2019-25008Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-25574. Reason: This candidate is a duplicate of ...
CVE-2019-25007HIGH7.5An issue was discovered in the streebog crate before 0.8.0 for Rust. The Streebog hash function can cause a panic.
CVE-2019-25006HIGH7.5An issue was discovered in the streebog crate before 0.8.0 for Rust. The Streebog hash function can produce the wrong an...
CVE-2019-25005HIGH7.5An issue was discovered in the chacha20 crate before 0.2.3 for Rust. A ChaCha20 counter overflow makes it easier for att...
CVE-2019-25004CRITICAL9.8An issue was discovered in the flatbuffers crate before 0.6.1 for Rust. Arbitrary bytes can be reinterpreted as a bool, ...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now