2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-4092 | MEDIUM | 6.1 | 0.8% | Apr 25, 2019 | IBM Content Navigator 2.0.3 and 3.0CD could allow a remote attacker to conduct phishing attacks, using an open redirect ... |
| CVE-2019-4077 | MEDIUM | 5.4 | 0.7% | Apr 25, 2019 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 and 6.0.0.1 is vulnerable to cross-site scripting. This vulnerabili... |
| CVE-2019-4076 | MEDIUM | 5.4 | 0.7% | Apr 25, 2019 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 and 6.0.0.1 is vulnerable to cross-site scripting. This vulnerabili... |
| CVE-2019-4075 | MEDIUM | 5.4 | 0.7% | Apr 25, 2019 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 and 6.0.0.1 is vulnerable to cross-site scripting. This vulnerabili... |
| CVE-2019-4074 | MEDIUM | 5.4 | 0.7% | Apr 25, 2019 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 and 6.0.0.1 is vulnerable to cross-site scripting. This vulnerabili... |
| CVE-2019-4073 | MEDIUM | 5.4 | 0.7% | Apr 25, 2019 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 and 6.0.0.1 is vulnerable to cross-site scripting. This vulnerabili... |
| CVE-2019-4033 | MEDIUM | 5.4 | 0.7% | Apr 25, 2019 | IBM Content Navigator 2.0.3 and 3.0CD is vulnerable to cross-site scripting. This vulnerability allows users to embed ar... |
| CVE-2019-3900 | HIGH | 7.7 | 4.4% | Apr 25, 2019 | An infinite loop issue was found in the vhost_net kernel module in Linux Kernel up to and including v5.1-rc6, while hand... |
| CVE-2019-11519 | — | — | 1.2% | Apr 25, 2019 | Libraries/Nop.Services/Localization/LocalizationService.cs in nopCommerce through 4.10 allows XXE via the "Configuration... |
| CVE-2019-11518 | — | — | 1.3% | Apr 25, 2019 | An issue was discovered in SEMCMS 3.8. SEMCMS_Inquiry.php allows AID[] SQL Injection because the class.phpmailer.php inj... |
| CVE-2019-11515 | — | — | 2.1% | Apr 25, 2019 | core/classes/db_backup.php in Gila CMS 1.10.1 allows admin/db_backup?download= absolute path traversal to read arbitrary... |
| CVE-2019-11514 | — | — | 1.3% | Apr 25, 2019 | User/Command/ConfirmEmailHandler.php in Flarum before 0.1.0-beta.8 mishandles invalidation of user email tokens. |
| CVE-2019-11513 | — | — | 0.6% | Apr 25, 2019 | The File Manager in CMS Made Simple through 2.2.10 has Reflected XSS via the "New name" field in a Rename action. |
| CVE-2019-11511 | — | — | 2.1% | Apr 25, 2019 | Zoho ManageEngine ADSelfService Plus before build 5708 has XSS via the mobile app API. |
| CVE-2019-8995 | MEDIUM | 6.1 | 1.1% | Apr 24, 2019 | The workspace client, openspace client, and app development client of TIBCO Software Inc.'s TIBCO ActiveMatrix BPM, TIBC... |
| CVE-2019-8994 | MEDIUM | 4.6 | 0.8% | Apr 24, 2019 | The workspace client of TIBCO Software Inc.'s TIBCO ActiveMatrix BPM, TIBCO ActiveMatrix BPM Distribution for TIBCO Silv... |
| CVE-2019-8993 | CRITICAL | 9.8 | 2.5% | Apr 24, 2019 | The administrative web server component of TIBCO Software Inc.'s TIBCO ActiveMatrix BPM, TIBCO ActiveMatrix BPM Distribu... |
| CVE-2019-8992 | HIGH | 8.8 | 2.2% | Apr 24, 2019 | The administrative server component of TIBCO Software Inc.'s TIBCO ActiveMatrix BPM, TIBCO ActiveMatrix BPM Distribution... |
| CVE-2019-8991 | HIGH | 8.8 | 0.9% | Apr 24, 2019 | The administrator web interface of TIBCO Software Inc.'s TIBCO ActiveMatrix BPM, TIBCO ActiveMatrix BPM Distribution for... |
| CVE-2019-11506 | HIGH | 8.8 | 2.6% | Apr 24, 2019 | In GraphicsMagick from version 1.3.30 to 1.4 snapshot-20190403 Q8, there is a heap-based buffer overflow in the function... |
| CVE-2019-11505 | HIGH | 8.8 | 2.9% | Apr 24, 2019 | In GraphicsMagick from version 1.3.8 to 1.4 snapshot-20190403 Q8, there is a heap-based buffer overflow in the function ... |
| CVE-2019-11504 | — | — | 2.5% | Apr 24, 2019 | Zotonic before version 0.47 has mod_admin XSS. |
| CVE-2019-11503 | — | — | 2.4% | Apr 24, 2019 | snap-confine as included in snapd before 2.39 did not guard against symlink races when performing the chdir() to the cur... |
| CVE-2019-11502 | — | — | 2.5% | Apr 24, 2019 | snap-confine in snapd before 2.38 incorrectly set the ownership of a snap application to the uid and gid of the first ca... |
| CVE-2019-11203 | MEDIUM | 6.1 | 0.7% | Apr 24, 2019 | The workspace client, openspace client, app development client, and REST API of TIBCO Software Inc.'s TIBCO ActiveMatrix... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now