2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-11542 | HIGH | 7.2 | 66.6% | Apr 26, 2019 | In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1R... |
| CVE-2019-11541 | HIGH | 7.5 | 4.0% | Apr 26, 2019 | In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, and 8.2RX before 8.2R12.1, user... |
| CVE-2019-11540 | CRITICAL | 9.8 | 8.3% | Apr 26, 2019 | In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4 and 8.3RX before 8.3R7.1 and Pulse Policy Secure versi... |
| CVE-2019-11539 | HIGH | 7.2 | 98.6% | Apr 26, 2019 | In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1R... |
| CVE-2019-11538 | HIGH | 7.7 | 7.4% | Apr 26, 2019 | In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1R... |
| CVE-2019-3801 | CRITICAL | 9.8 | 0.6% | Apr 25, 2019 | Cloud Foundry cf-deployment, versions prior to 7.9.0, contain java components that are using an insecure protocol to fet... |
| CVE-2019-3788 | HIGH | 8.7 | 0.8% | Apr 25, 2019 | Cloud Foundry UAA Release, versions prior to 71.0, allows clients to be configured with an insecure redirect uri. Given ... |
| CVE-2019-3721 | HIGH | 7.5 | 2.6% | Apr 25, 2019 | Dell EMC Open Manage System Administrator (OMSA) versions prior to 9.3.0 contain an Improper Range Header Processing Vul... |
| CVE-2019-3720 | MEDIUM | 4.9 | 3.5% | Apr 25, 2019 | Dell EMC Open Manage System Administrator (OMSA) versions prior to 9.3.0 contain a Directory Traversal Vulnerability. A ... |
| CVE-2019-11489 | — | — | 2.6% | Apr 25, 2019 | Incorrect Access Control in the Administrative Management Interface in SimplyBook.me Enterprise before 2019-04-23 allows... |
| CVE-2019-11488 | — | — | 1.5% | Apr 25, 2019 | Incorrect Access Control in the Account Access / Password Reset Link in SimplyBook.me Enterprise before 2019-04-23 allow... |
| CVE-2019-9669 | — | — | 1.0% | Apr 25, 2019 | The Wordfence plugin 7.2.3 for WordPress allows XSS via a unique attack vector. NOTE: It has been asserted that this is ... |
| CVE-2019-11537 | MEDIUM | 6.1 | 4.6% | Apr 25, 2019 | In osTicket before 1.12, XSS exists via /upload/file.php, /upload/scp/users.php?do=import-users, and /upload/scp/ajax.ph... |
| CVE-2019-9139 | HIGH | 7.8 | 1.3% | Apr 25, 2019 | DaviewIndy 8.98.7 and earlier versions have a Integer overflow vulnerability, triggered when the user opens a malformed ... |
| CVE-2019-9138 | HIGH | 7.8 | 1.3% | Apr 25, 2019 | DaviewIndy 8.98.7 and earlier versions have a Integer overflow vulnerability, triggered when the user opens a malformed ... |
| CVE-2019-9137 | HIGH | 7.8 | 1.3% | Apr 25, 2019 | DaviewIndy 8.98.7 and earlier versions have a Integer overflow vulnerability, triggered when the user opens a malformed ... |
| CVE-2019-10955 | MEDIUM | 6.1 | 3.0% | Apr 25, 2019 | In Rockwell Automation MicroLogix 1400 Controllers Series A, All Versions Series B, v15.002 and earlier, MicroLogix 1100... |
| CVE-2019-9136 | HIGH | 7.8 | 1.2% | Apr 25, 2019 | DaviewIndy 8.98.7 and earlier versions have a Heap-based overflow vulnerability, triggered when the user opens a malform... |
| CVE-2019-9135 | HIGH | 7.8 | 1.3% | Apr 25, 2019 | DaviewIndy 8.98.7 and earlier versions have a Heap-based overflow vulnerability, triggered when the user opens a malform... |
| CVE-2019-9901 | MEDIUM | 6.5 | 2.7% | Apr 25, 2019 | Envoy 1.9.0 and before does not normalize HTTP URL paths. A remote attacker may craft a relative path, e.g., something/.... |
| CVE-2019-9900 | HIGH | 8.3 | 3.7% | Apr 25, 2019 | When parsing HTTP/1.x header values, Envoy 1.9.0 and before does not reject embedded zero characters (NUL, ASCII 0x0). T... |
| CVE-2019-4238 | MEDIUM | 5.4 | 0.7% | Apr 25, 2019 | IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site scripting. This vulnerability allows ... |
| CVE-2019-4222 | MEDIUM | 4.3 | 1.2% | Apr 25, 2019 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 and 6.0.0.1 could allow an authenticated user to view process defin... |
| CVE-2019-4148 | MEDIUM | 5.4 | 0.6% | Apr 25, 2019 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 and 6.0.0.1 is vulnerable to cross-site scripting. This vulnerabili... |
| CVE-2019-4146 | LOW | 3.1 | 1.1% | Apr 25, 2019 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 and 6.0.0.1 could allow an authenticated user to obtain sensitive d... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now