2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-11000MEDIUM6.5An issue was discovered in GitLab Enterprise Edition before 11.7.11, 11.8.x before 11.8.7, and 11.9.x before 11.9.7. It ...
CVE-2019-5494OnCommand Unified Manager 7-Mode prior to version 5.2.4 shipped without certain HTTP Security headers configured which c...
CVE-2019-5018HIGH8.1An exploitable use after free vulnerability exists in the window function functionality of Sqlite3 3.26.0. A specially c...
CVE-2019-11879The WEBrick gem 1.4.2 for Ruby allows directory traversal if the attacker once had local access to create a symlink to a...
CVE-2019-11082core/api/datasets/internal/actions/Explode.java in the Dataset API in DKPro Core through 1.10.0 allows Directory Travers...
CVE-2019-4204MEDIUM5.4IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, and 19.0.0.1 is vulnerable to cross-site scripting. This ...
CVE-2019-11878An issue was discovered on XiongMai Besder IP20H1 V4.02.R12.00035520.12012.047500.00200 cameras. An attacker on the same...
CVE-2019-1867CRITICAL10A vulnerability in the REST API of Cisco Elastic Services Controller (ESC) could allow an unauthenticated, remote attack...
CVE-2019-11871The Custom Field Suite plugin before 2.5.15 for WordPress has XSS for editors or admins.
CVE-2019-11870Serendipity before 2.1.5 has XSS via EXIF data that is mishandled in the templates/2k11/admin/media_choose.tpl Editor Pr...
CVE-2019-11869The Yuzo Related Posts plugin 5.12.94 for WordPress has XSS because it mistakenly expects that is_admin() verifies that ...
CVE-2019-7652TheHive Project UnshortenLink analyzer before 1.1, included in Cortex-Analyzers before 1.15.2, has SSRF. To exploit the ...
CVE-2019-11563Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2019-1568Cross-site scripting (XSS) vulnerability in Palo Alto Networks Demisto 4.5 build 40249 may allow an unauthenticated atta...
CVE-2019-11842An issue was discovered in Matrix Sydent before 1.0.3 and Synapse before 0.99.3.1. Random number generation is mishandle...
CVE-2019-11840MEDIUM5.9An issue was discovered in the supplementary Go cryptography library, golang.org/x/crypto, before v0.0.0-20190320223903-...
CVE-2019-7181Buffer Overflow vulnerability in myQNAPcloud Connect 1.3.3.0925 and earlier could allow remote attackers to crash the pr...
CVE-2019-6566HIGH7.8GE Communicator, all versions prior to 4.0.517, allows a non-administrative user to replace the uninstaller with a malic...
CVE-2019-6564HIGH7.8GE Communicator, all versions prior to 4.0.517, allows a non-administrative user to place malicious files within the ins...
CVE-2019-6548CRITICAL9.8GE Communicator, all versions prior to 4.0.517, contains two backdoor accounts with hardcoded credentials, which may all...
CVE-2019-6546HIGH7.8GE Communicator, all versions prior to 4.0.517, allows an attacker to place malicious files within the working directory...
CVE-2019-6544MEDIUM5.6GE Communicator, all versions prior to 4.0.517, has a service running with system privileges that may allow an unprivile...
CVE-2019-4072MEDIUM6.3IBM Tivoli Storage Productivity Center (IBM Spectrum Control Standard Edition 5.2.1 through 5.2.17) allows users to rema...
CVE-2019-4071HIGH8.8IBM Tivoli Storage Productivity Center (IBM Spectrum Control Standard Edition 5.2.1 through 5.2.17) could allow a remote...
CVE-2019-9847A vulnerability in LibreOffice hyperlink processing allows an attacker to construct documents containing hyperlinks poin...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now