2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-0395MEDIUM5.4SAP BusinessObjects Business Intelligence Platform (Fiori BI Launchpad), before version 4.2, allows execution of JavaScr...
CVE-2019-19582MEDIUM6.5An issue was discovered in Xen through 4.12.x allowing x86 guest OS users to cause a denial of service (infinite loop) b...
CVE-2019-19581MEDIUM6.5An issue was discovered in Xen through 4.12.x allowing 32-bit Arm guest OS users to cause a denial of service (out-of-bo...
CVE-2019-19580MEDIUM6.6An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to gain host OS privileges by leveraging ra...
CVE-2019-14317MEDIUM5.3wolfSSL and wolfCrypt 4.1.0 and earlier (formerly known as CyaSSL) generate biased DSA nonces. This allows a remote atta...
CVE-2019-18378MEDIUM4.8Symantec Messaging Gateway, prior to 10.7.3, may be susceptible to a cross-site scripting (XSS) exploit, which is a type...
CVE-2019-10772MEDIUM6.1It is possible to bypass enshrined/svg-sanitize before 0.13.1 using the "xlink:href" attribute due to mishandling of the...
CVE-2019-4665MEDIUM5.4IBM Spectrum Scale 4.2 and 5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary...
CVE-2019-15009MEDIUM4.3The /json/profile/removeStarAjax.do resource in Atlassian Fisheye and Crucible before version 4.8.0 allows remote attack...
CVE-2019-15008MEDIUM6.1The /plugins/servlet/branchreview resource in Atlassian Fisheye and Crucible before version 4.7.3 allows remote attacker...
CVE-2019-15007MEDIUM4.8The review resource in Atlassian Fisheye and Crucible before version 4.7.3 allows remote attackers to inject arbitrary H...
CVE-2019-19719MEDIUM6.1Tableau Server 10.3 through 2019.4 on Windows and Linux allows XSS via the embeddedAuthRedirect page.
CVE-2019-19709MEDIUM6.1MediaWiki through 1.33.1 allows attackers to bypass the Title_blacklist protection mechanism by starting with an arbitra...
CVE-2019-19708MEDIUM6.1The VisualEditor extension through 1.34 for MediaWiki allows XSS via pasted content containing an element with a data-ve...
CVE-2019-14870MEDIUM5.4All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the S4U (MS-...
CVE-2019-14861MEDIUM5.3All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the (poorly ...
CVE-2019-1490MEDIUM5.4A spoofing vulnerability exists when a Skype for Business Server does not properly sanitize a specially crafted request,...
CVE-2019-1487MEDIUM6.5An information disclosure vulnerability in Android Apps using Microsoft Authentication Library (MSAL) 0.3.1-Alpha or lat...
CVE-2019-1486MEDIUM6.1A spoofing vulnerability exists in Visual Studio Live Share when a guest connected to a Live Share session is redirected...
CVE-2019-1481MEDIUM4.3An information disclosure vulnerability exists in Windows Media Player when it fails to properly handle objects in memor...
CVE-2019-1480MEDIUM4.3An information disclosure vulnerability exists in Windows Media Player when it fails to properly handle objects in memor...
CVE-2019-1474MEDIUM5.5An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Window...
CVE-2019-1472MEDIUM5.5An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Window...
CVE-2019-1470MEDIUM6An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validat...
CVE-2019-1469MEDIUM5.5An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Wi...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now