2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-11255MEDIUM6.5Improper input validation in Kubernetes CSI sidecar containers for external-provisioner (<v0.4.3, <v1.0.2, v1.1, <v1.2.2...
CVE-2019-19602MEDIUM6.1fpregs_state_valid in arch/x86/include/asm/fpu/internal.h in the Linux kernel before 5.4.2, when GCC 9 is used, allows c...
CVE-2019-19596MEDIUM5.4GitBook through 2.6.9 allows XSS via a local .md file.
CVE-2019-19587MEDIUM6.1In WSO2 Enterprise Integrator 6.5.0, reflected XSS occurs when updating the message processor configuration from the sou...
CVE-2019-19579MEDIUM6.8An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where...
CVE-2019-16752MEDIUM4.3An issue was discovered in Decentralized Anonymous Payment System (DAPS) through 2019-08-26. It is possible to force wal...
CVE-2019-11216MEDIUM6.5BMC Smart Reporting 7.3 20180418 allows authenticated XXE within the import functionality. One can import a malicious XM...
CVE-2019-19229MEDIUM6.5admincgi-bin/service.fcgi on Fronius Solar Inverter devices before 3.14.1 (HM 1.12.1) allows action=download&filename= D...
CVE-2019-19133MEDIUM6.1The CSS Hero plugin through 4.0.3 for WordPress is prone to reflected XSS via the URI in a csshero_action=edit_page requ...
CVE-2019-18347MEDIUM5.4A stored XSS issue was discovered in DAViCal through 1.1.8. It does not adequately sanitize output of various fields tha...
CVE-2019-7197MEDIUM4.8A stored cross-site scripting (XSS) vulnerability has been reported to affect multiple versions of QTS. If exploited, th...
CVE-2019-19555MEDIUM5.5read_textobject in read.c in Xfig fig2dev 3.2.7b has a stack-based buffer overflow because of an incorrect sscanf.
CVE-2019-17554MEDIUM5.5The XML content type entity deserializer in Apache Olingo versions 4.0.0 to 4.6.0 is not configured to deny the resoluti...
CVE-2019-3750MEDIUM5.5Dell Command Update versions prior to 3.1 contain an Arbitrary File Deletion Vulnerability. A local authenticated malici...
CVE-2019-3749MEDIUM5.5Dell Command Update versions prior to 3.1 contain an Arbitrary File Deletion Vulnerability. A local authenticated malici...
CVE-2019-18574MEDIUM4.8RSA Authentication Manager software versions prior to 8.4 P8 contain a stored cross-site scripting vulnerability in the ...
CVE-2019-19457MEDIUM5.4SALTO ProAccess SPACE 5.4.3.0 allows XSS.
CVE-2019-18993MEDIUM5.4OpenWrt 18.06.4 allows XSS via the "New port forward" Name field to the cgi-bin/luci/admin/network/firewall/forwards URI...
CVE-2019-18992MEDIUM5.4OpenWrt 18.06.4 allows XSS via these Name fields to the cgi-bin/luci/admin/network/firewall/rules URI: "Open ports on ro...
CVE-2019-13456MEDIUM6.5In FreeRADIUS 3.0 through 3.0.19, on average 1 in every 2048 EAP-pwd handshakes fails because the password element canno...
CVE-2019-19460MEDIUM5.5An issue was discovered in SALTO ProAccess SPACE 5.4.3.0. The product's webserver runs as a Windows service with local S...
CVE-2019-3990MEDIUM4.3A User Enumeration flaw exists in Harbor. The issue is present in the "/users" API endpoint. This endpoint is supposed t...
CVE-2019-19537MEDIUM4.2In the Linux kernel before 5.2.10, there is a race condition bug that can be caused by a malicious USB device in the USB...
CVE-2019-19536MEDIUM4.6In the Linux kernel before 5.2.9, there is an info-leak bug that can be caused by a malicious USB device in the drivers/...
CVE-2019-19535MEDIUM4.6In the Linux kernel before 5.2.9, there is an info-leak bug that can be caused by a malicious USB device in the drivers/...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now