2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-0395 | MEDIUM | 5.4 | 0.7% | Dec 11, 2019 | SAP BusinessObjects Business Intelligence Platform (Fiori BI Launchpad), before version 4.2, allows execution of JavaScr... |
| CVE-2019-19582 | MEDIUM | 6.5 | 0.4% | Dec 11, 2019 | An issue was discovered in Xen through 4.12.x allowing x86 guest OS users to cause a denial of service (infinite loop) b... |
| CVE-2019-19581 | MEDIUM | 6.5 | 0.4% | Dec 11, 2019 | An issue was discovered in Xen through 4.12.x allowing 32-bit Arm guest OS users to cause a denial of service (out-of-bo... |
| CVE-2019-19580 | MEDIUM | 6.6 | 1.2% | Dec 11, 2019 | An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to gain host OS privileges by leveraging ra... |
| CVE-2019-14317 | MEDIUM | 5.3 | 1.8% | Dec 11, 2019 | wolfSSL and wolfCrypt 4.1.0 and earlier (formerly known as CyaSSL) generate biased DSA nonces. This allows a remote atta... |
| CVE-2019-18378 | MEDIUM | 4.8 | 0.7% | Dec 11, 2019 | Symantec Messaging Gateway, prior to 10.7.3, may be susceptible to a cross-site scripting (XSS) exploit, which is a type... |
| CVE-2019-10772 | MEDIUM | 6.1 | 0.7% | Dec 11, 2019 | It is possible to bypass enshrined/svg-sanitize before 0.13.1 using the "xlink:href" attribute due to mishandling of the... |
| CVE-2019-4665 | MEDIUM | 5.4 | 0.6% | Dec 11, 2019 | IBM Spectrum Scale 4.2 and 5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary... |
| CVE-2019-15009 | MEDIUM | 4.3 | 0.7% | Dec 11, 2019 | The /json/profile/removeStarAjax.do resource in Atlassian Fisheye and Crucible before version 4.8.0 allows remote attack... |
| CVE-2019-15008 | MEDIUM | 6.1 | 0.7% | Dec 11, 2019 | The /plugins/servlet/branchreview resource in Atlassian Fisheye and Crucible before version 4.7.3 allows remote attacker... |
| CVE-2019-15007 | MEDIUM | 4.8 | 0.6% | Dec 11, 2019 | The review resource in Atlassian Fisheye and Crucible before version 4.7.3 allows remote attackers to inject arbitrary H... |
| CVE-2019-19719 | MEDIUM | 6.1 | 22.0% | Dec 11, 2019 | Tableau Server 10.3 through 2019.4 on Windows and Linux allows XSS via the embeddedAuthRedirect page. |
| CVE-2019-19709 | MEDIUM | 6.1 | 1.6% | Dec 11, 2019 | MediaWiki through 1.33.1 allows attackers to bypass the Title_blacklist protection mechanism by starting with an arbitra... |
| CVE-2019-19708 | MEDIUM | 6.1 | 0.7% | Dec 11, 2019 | The VisualEditor extension through 1.34 for MediaWiki allows XSS via pasted content containing an element with a data-ve... |
| CVE-2019-14870 | MEDIUM | 5.4 | 2.8% | Dec 10, 2019 | All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the S4U (MS-... |
| CVE-2019-14861 | MEDIUM | 5.3 | 2.3% | Dec 10, 2019 | All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the (poorly ... |
| CVE-2019-1490 | MEDIUM | 5.4 | 1.4% | Dec 10, 2019 | A spoofing vulnerability exists when a Skype for Business Server does not properly sanitize a specially crafted request,... |
| CVE-2019-1487 | MEDIUM | 6.5 | 4.0% | Dec 10, 2019 | An information disclosure vulnerability in Android Apps using Microsoft Authentication Library (MSAL) 0.3.1-Alpha or lat... |
| CVE-2019-1486 | MEDIUM | 6.1 | 1.5% | Dec 10, 2019 | A spoofing vulnerability exists in Visual Studio Live Share when a guest connected to a Live Share session is redirected... |
| CVE-2019-1481 | MEDIUM | 4.3 | 12.3% | Dec 10, 2019 | An information disclosure vulnerability exists in Windows Media Player when it fails to properly handle objects in memor... |
| CVE-2019-1480 | MEDIUM | 4.3 | 5.4% | Dec 10, 2019 | An information disclosure vulnerability exists in Windows Media Player when it fails to properly handle objects in memor... |
| CVE-2019-1474 | MEDIUM | 5.5 | 1.5% | Dec 10, 2019 | An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Window... |
| CVE-2019-1472 | MEDIUM | 5.5 | 1.5% | Dec 10, 2019 | An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Window... |
| CVE-2019-1470 | MEDIUM | 6 | 6.4% | Dec 10, 2019 | An information disclosure vulnerability exists when Windows Hyper-V on a host operating system fails to properly validat... |
| CVE-2019-1469 | MEDIUM | 5.5 | 1.6% | Dec 10, 2019 | An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Wi... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now