2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-18388MEDIUM5.5A NULL pointer dereference in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of...
CVE-2019-19930MEDIUM6.5In libIEC61850 1.4.0, MmsValue_newOctetString in mms/iso_mms/common/mms_value.c has an integer signedness error that can...
CVE-2019-11050MEDIUM6.5When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7...
CVE-2019-11047MEDIUM6.5When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7...
CVE-2019-11046MEDIUM5.3In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP bcmath extension functions on some systems, includ...
CVE-2019-11045MEDIUM5.9In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP DirectoryIterator class accepts filenames with emb...
CVE-2019-19922MEDIUM5.5kernel/sched/fair.c in the Linux kernel before 5.3.9, when cpu.cfs_quota_us is used (e.g., with Kubernetes), allows atta...
CVE-2019-15584MEDIUM6.5A denial of service exists in gitlab <v12.3.2, <v12.2.6, and <v12.1.10 that would let an attacker bypass input validatio...
CVE-2019-4744MEDIUM6.1IBM Financial Transaction Manager 3.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed ar...
CVE-2019-4743MEDIUM4.3IBM Financial Transaction Manager 3.0 does not set the secure attribute on authorization tokens or session cookies. Atta...
CVE-2019-4742MEDIUM6.1IBM Financial Transaction Manager 3.0 could allow a remote attacker to hijack the clicking action of the victim. By pers...
CVE-2019-4736MEDIUM4.3IBM Financial Transaction Manager 3.0 is vulnerable to cross-site request forgery which could allow an attacker to execu...
CVE-2019-4555MEDIUM5.4IBM Cognos Analytics 11.0 and 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbit...
CVE-2019-4231MEDIUM4.3IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute ...
CVE-2019-19916MEDIUM6.1In Midori Browser 0.5.11 (on Windows 10), Content Security Policy (CSP) is not applied correctly to all parts of multipa...
CVE-2019-19692MEDIUM6.1Trend Micro Apex One (2019) is affected by a cross-site scripting (XSS) vulnerability on the product console. Note that ...
CVE-2019-19691MEDIUM4.9A vulnerability in Trend Micro Apex One and OfficeScan XG could allow an attacker to expose a masked credential key by m...
CVE-2019-18263MEDIUM6.5An issue was found in Philips Veradius Unity, Pulsera, and Endura Dual WAN Router, Veradius Unity (718132) with wireless...
CVE-2019-19908MEDIUM6.1phpMyChat-Plus 1.98 is vulnerable to reflected XSS via JavaScript injection into the password reset URL. In the URL, the...
CVE-2019-19789MEDIUM6.53S-Smart CODESYS SP Realtime NT before V2.3.7.28, CODESYS Runtime Toolkit 32 bit full before V2.4.7.54, and CODESYS PLCW...
CVE-2019-19342MEDIUM5.3A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2 and 3.5.x before 3.5.4, when /websocket is requested and ...
CVE-2019-19341MEDIUM5.5A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2, where files in '/var/backup/tower' are left world-readab...
CVE-2019-11294MEDIUM4.3Cloud Foundry Cloud Controller API (CAPI), version 1.88.0, allows space developers to list all global service brokers, i...
CVE-2019-19910MEDIUM6.1The MinervaNeue Skin in MediaWiki from 2019-11-05 to 2019-12-13 (1.35 and/or 1.34) mishandles certain HTML attributes, a...
CVE-2019-18955MEDIUM6.1The web console in Lansweeper 7.2.105.2 has XSS via the URL path. Product vulnerability has been fixed and disclosed wit...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now