2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-0271MEDIUM6.5ABAP Server (used in NetWeaver and Suite/ERP) and ABAP Platform does not sufficiently validate an XML document accepted ...
CVE-2019-0270ABAP Server of SAP NetWeaver and ABAP Platform fail to perform necessary authorization checks for an authenticated user,...
CVE-2019-0269SAP BusinessObjects Business Intelligence Platform (BI Workspace), versions 4.10 and 4.20, does not sufficiently encode ...
CVE-2019-0268SAP BusinessObjects Business Intelligence Platform (CMC Module), versions 4.10, 4.20 and 4.30, does not sufficiently val...
CVE-2019-3615MEDIUM5.3Data Leakage Attacks vulnerability in the web interface in McAfee Database Security prior to the 4.6.6 March 2019 update...
CVE-2019-9725The Web manager (aka Commander) on Korenix JetPort 5601 and 5601f devices has Persistent XSS via the Port Alias field un...
CVE-2019-9558Mailtraq WebMail version 2.17.7.3550 has Persistent Cross Site Scripting (XSS) via the body of an e-mail message. To exp...
CVE-2019-9557Ability Mail Server 4.2.6 has Persistent Cross Site Scripting (XSS) via the body e-mail body. To exploit the vulnerabili...
CVE-2019-9714An issue was discovered in Joomla! before 3.9.4. The media form field lacks escaping, leading to XSS.
CVE-2019-9713An issue was discovered in Joomla! before 3.9.4. The sample data plugins lack ACL checks, allowing unauthorized access.
CVE-2019-9712An issue was discovered in Joomla! before 3.9.4. The JSON handler in com_config lacks input validation, leading to XSS.
CVE-2019-9711An issue was discovered in Joomla! before 3.9.4. The item_title layout in edit views lacks escaping, leading to XSS.
CVE-2019-9721MEDIUM6.5A denial of service in the subtitle decoder in FFmpeg 3.2 and 4.1 allows attackers to hog the CPU via a crafted video fi...
CVE-2019-9718MEDIUM6.5In FFmpeg 3.2 and 4.1, a denial of service in the subtitle decoder allows attackers to hog the CPU via a crafted video f...
CVE-2019-9644An XSSI (cross-site inclusion) vulnerability in Jupyter Notebook before 5.7.6 allows inclusion of resources on malicious...
CVE-2019-9710An issue was discovered in webargs before 5.1.3, as used with marshmallow and other products. JSON parsing uses a short-...
CVE-2019-9706MEDIUM5.5Vixie Cron before the 3.0pl1-133 Debian package allows local users to cause a denial of service (use-after-free and daem...
CVE-2019-9705MEDIUM5.5Vixie Cron before the 3.0pl1-133 Debian package allows local users to cause a denial of service (memory consumption) via...
CVE-2019-9704MEDIUM5.5Vixie Cron before the 3.0pl1-133 Debian package allows local users to cause a denial of service (daemon crash) via a lar...
CVE-2019-4016HIGH7.8IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer ov...
CVE-2019-4015HIGH7.8IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer ov...
CVE-2019-1707MEDIUM5.4A vulnerability in the web-based management interface of Cisco DNA Center could allow an authenticated, remote attacker ...
CVE-2019-1702MEDIUM6.1Multiple vulnerabilities in the web-based management interface of Cisco Enterprise Chat and Email could allow an unauthe...
CVE-2019-1690MEDIUM6.5A vulnerability in the management interface of Cisco Application Policy Infrastructure Controller (APIC) software could ...
CVE-2019-1618HIGH7.8A vulnerability in the Tetration Analytics agent for Cisco Nexus 9000 Series Switches in standalone NX-OS mode could all...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now