2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-6207 | MEDIUM | 5.5 | 0.7% | Dec 18, 2019 | An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input ... |
| CVE-2019-6204 | MEDIUM | 6.1 | 0.7% | Dec 18, 2019 | A logic issue was addressed with improved validation. This issue is fixed in iOS 12.2, Safari 12.1. Enabling the Safari ... |
| CVE-2019-19833 | MEDIUM | 6.5 | 14.7% | Dec 18, 2019 | In Tautulli 2.1.9, CSRF in the /shutdown URI allows an attacker to shut down the remote media server. (Also, anonymous a... |
| CVE-2019-19829 | MEDIUM | 5.4 | 2.3% | Dec 18, 2019 | A cross-site scripting (XSS) vulnerability exists in SolarWinds Serv-U FTP Server 15.1.7 in the email parameter, a diffe... |
| CVE-2019-11992 | MEDIUM | 6.1 | 1.0% | Dec 18, 2019 | A security vulnerability in HPE OneView for VMware vCenter 9.5 could be exploited remotely to allow Cross-Site Scripting... |
| CVE-2019-4388 | MEDIUM | 4.8 | 0.5% | Dec 18, 2019 | HCL AppScan Source 9.0.3.13 and earlier is susceptible to cross-site scripting (XSS) attacks by allowing users to embed ... |
| CVE-2019-19742 | MEDIUM | 4.8 | 19.8% | Dec 18, 2019 | On D-Link DIR-615 devices, the User Account Configuration page is vulnerable to blind XSS via the name field. |
| CVE-2019-10513 | MEDIUM | 5.5 | 0.2% | Dec 18, 2019 | Possibility of Null pointer access if the SPDM commands are executed in the non-standard way in Trustzone in Snapdragon ... |
| CVE-2019-10482 | MEDIUM | 5.9 | 0.6% | Dec 18, 2019 | Due to the use of non-time-constant comparison functions there is issue in timing side channels which can be used as a p... |
| CVE-2019-19845 | MEDIUM | 5.3 | 1.1% | Dec 18, 2019 | In Joomla! before 3.9.14, a missing access check in framework files could lead to a path disclosure. |
| CVE-2019-19775 | MEDIUM | 6.1 | 0.9% | Dec 18, 2019 | The image thumbnailing handler in Zulip Server versions 1.9.0 to before 2.0.8 allowed an open redirect that was visible ... |
| CVE-2019-15013 | MEDIUM | 4.3 | 1.2% | Dec 18, 2019 | The WorkflowResource class removeStatus method in Jira before version 7.13.12, from version 8.0.0 before version 8.4.3, ... |
| CVE-2019-3996 | MEDIUM | 6.5 | 5.9% | Dec 17, 2019 | ELOG 3.1.4-57bea22 and below can be used as an HTTP GET request proxy when unauthenticated remote attackers send crafted... |
| CVE-2019-17337 | MEDIUM | 5.4 | 0.7% | Dec 17, 2019 | The Spotfire library component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace and TIBCO ... |
| CVE-2019-17336 | MEDIUM | 6.5 | 0.9% | Dec 17, 2019 | The Data access layer component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace and TIBCO... |
| CVE-2019-17335 | MEDIUM | 6.5 | 0.8% | Dec 17, 2019 | The Data access layer component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace and TIBCO... |
| CVE-2019-19497 | MEDIUM | 5.4 | 0.6% | Dec 17, 2019 | MDaemon Email Server 17.5.1 allows XSS via the filename of an attachment to an email message. |
| CVE-2019-15235 | MEDIUM | 6.5 | 1.4% | Dec 17, 2019 | CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.864 allows an attacker to get a victim's session file name from /ho... |
| CVE-2019-14782 | MEDIUM | 6.5 | 1.4% | Dec 17, 2019 | CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.856 through 0.9.8.864 allows an attacker to get a victim's session ... |
| CVE-2019-19714 | MEDIUM | 5.3 | 0.8% | Dec 17, 2019 | Contao 4.8.4 and 4.8.5 has Improper Encoding or Escaping of Output. It is possible to inject insert tags into the login ... |
| CVE-2019-16576 | MEDIUM | 6.5 | 0.9% | Dec 17, 2019 | A missing permission check in Jenkins Alauda Kubernetes Suport Plugin 2.3.0 and earlier allows attackers with Overall/Re... |
| CVE-2019-16574 | MEDIUM | 6.5 | 0.9% | Dec 17, 2019 | A missing permission check in Jenkins Alauda DevOps Pipeline Plugin 2.3.2 and earlier allows attackers with Overall/Read... |
| CVE-2019-16572 | MEDIUM | 5.5 | 0.3% | Dec 17, 2019 | Jenkins Weibo Plugin 1.0.1 and earlier stores credentials unencrypted in its global configuration file on the Jenkins ma... |
| CVE-2019-16571 | MEDIUM | 4.3 | 0.7% | Dec 17, 2019 | A missing permission check in Jenkins RapidDeploy Plugin 4.1 and earlier allows attackers with Overall/Read permission t... |
| CVE-2019-16569 | MEDIUM | 4.3 | 0.7% | Dec 17, 2019 | A cross-site request forgery vulnerability in Jenkins Mantis Plugin 0.26 and earlier allows attackers to connect to an a... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now