2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-0218A vulnerability was discovered wherein a specially crafted URL could enable reflected XSS via JavaScript in the pony mai...
CVE-2019-5428Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-11358. Reason: This candidate is a duplicate of ...
CVE-2019-5427HIGH7.5c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protect...
CVE-2019-11461An issue was discovered in GNOME Nautilus 3.30 prior to 3.30.6 and 3.32 prior to 3.32.1. A compromised thumbnailer may e...
CVE-2019-11384The Zalora application 6.15.1 for Android stores confidential information insecurely on the system (i.e. plain text), wh...
CVE-2019-10248Eclipse Vorto versions prior to 0.11 resolved Maven build artifacts for the Xtext project over HTTP instead of HTTPS. An...
CVE-2019-9955On Zyxel ATP200, ATP500, ATP800, USG20-VPN, USG20W-VPN, USG40, USG40W, USG60, USG60W, USG110, USG210, USG310, USG1100, U...
CVE-2019-10247MEDIUM5.3In Eclipse Jetty version 7.x, 8.x, 9.2.27 and older, 9.3.26 and older, and 9.4.16 and older, the server running on any O...
CVE-2019-10246MEDIUM5.3In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the full...
CVE-2019-10241MEDIUM6.1In Eclipse Jetty version 9.2.26 and older, 9.3.25 and older, and 9.4.15 and older, the server is vulnerable to XSS condi...
CVE-2019-6157MEDIUM6.5In various firmware versions of Lenovo System x, the integrated management module II (IMM2)'s first failure data capture...
CVE-2019-6155MEDIUM4.1A potential vulnerability was found in an SMI handler in various BIOS versions of certain legacy IBM System x and IBM Bl...
CVE-2019-3902MEDIUM5.1A flaw was found in Mercurial before 4.9. It was possible to use symlinks and subrepositories to defeat Mercurial's path...
CVE-2019-3901MEDIUM4.7A race condition in perf_event_open() allows local attackers to leak sensitive data from setuid programs. As no relevant...
CVE-2019-3899CRITICAL9.8It was found that default configuration of Heketi does not require any authentication potentially exposing the managemen...
CVE-2019-11456Gila CMS 1.10.1 allows fm/save CSRF for executing arbitrary PHP code.
CVE-2019-11455HIGH8.1A buffer over-read in Util_urlDecode in util.c in Tildeslash Monit before 5.25.3 allows a remote authenticated attacker ...
CVE-2019-11454MEDIUM6.1Persistent cross-site scripting (XSS) in http/cervlet.c in Tildeslash Monit before 5.25.3 allows a remote unauthenticate...
CVE-2019-11452whatsns 4.0 allows index.php?admin_category/remove.html cid[] SQL injection.
CVE-2019-11451whatsns 4.0 allows index.php?inform/add.html qid SQL injection.
CVE-2019-11450whatsns 4.0 allows index.php?question/ajaxadd.html title SQL injection.
CVE-2019-11244MEDIUM5In Kubernetes v1.8.x-v1.14.x, schema info is cached by kubectl in the location specified by --cache-dir (defaulting to $...
CVE-2019-11243HIGH8.1In Kubernetes v1.12.0-v1.12.4 and v1.13.0, the rest.AnonymousClientConfig() method returns a copy of the provided config...
CVE-2019-11449I, Librarian 4.10 has XSS via the notes.php notes parameter.
CVE-2019-11448An issue was discovered in Zoho ManageEngine Applications Manager 11.0 through 14.0. An unauthenticated user can gain th...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now