2019 CVE Vulnerabilities
17,624 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-20909 | HIGH | 7.5 | 1.6% | Jul 16, 2020 | An issue was discovered in GNU LibreDWG through 0.9.3. There is a NULL pointer dereference in the function dwg_encode_LW... |
| CVE-2019-4748 | MEDIUM | 5.4 | 0.6% | Jul 16, 2020 | IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability allows users to embed... |
| CVE-2019-4747 | MEDIUM | 5.4 | 0.6% | Jul 16, 2020 | IBM Team Concert (RTC) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScr... |
| CVE-2019-20908 | MEDIUM | 6.7 | 0.5% | Jul 15, 2020 | An issue was discovered in drivers/firmware/efi/efi.c in the Linux kernel before 5.4. Incorrect access permissions for t... |
| CVE-2019-17639 | MEDIUM | 5.3 | 1.5% | Jul 15, 2020 | In Eclipse OpenJ9 prior to version 0.21 on Power platforms, calling the System.arraycopy method with a length longer tha... |
| CVE-2019-19326 | MEDIUM | 5.9 | 0.8% | Jul 15, 2020 | Silverstripe CMS sites through 4.4.4 which have opted into HTTP Cache Headers on responses served by the framework's HTT... |
| CVE-2019-17637 | HIGH | 7.1 | 0.9% | Jul 15, 2020 | In all versions of Eclipse Web Tools Platform through release 3.18 (2020-06), XML and DTD files referring to external en... |
| CVE-2019-12784 | HIGH | 8.8 | 0.7% | Jul 14, 2020 | An issue was discovered in Verint Impact 360 15.1. At wfo/control/signin, the login form can accept submissions from ext... |
| CVE-2019-12783 | MEDIUM | 6.1 | 0.9% | Jul 14, 2020 | An issue was discovered in Verint Impact 360 15.1. At wfo/control/signin, the rd parameter can accept a URL, to which us... |
| CVE-2019-12773 | MEDIUM | 6.1 | 0.8% | Jul 14, 2020 | An issue was discovered in Verint Impact 360 15.1. At wfo/help/help_popup.jsp, the helpURL parameter can be changed to e... |
| CVE-2019-15888 | — | — | — | Jul 14, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2019-15887 | — | — | — | Jul 14, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2019-15886 | — | — | — | Jul 14, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2019-15885 | — | — | — | Jul 14, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2019-15884 | — | — | — | Jul 14, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2019-15883 | — | — | — | Jul 14, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2019-15882 | — | — | — | Jul 14, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2019-15881 | — | — | — | Jul 14, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2019-19338 | MEDIUM | 5.5 | 0.5% | Jul 13, 2020 | A flaw was found in the fix for CVE-2019-11135, in the Linux upstream kernel versions before 5.5 where, the way Intel CP... |
| CVE-2019-4591 | HIGH | 7.8 | 0.3% | Jul 13, 2020 | IBM Maximo Asset Management 7.6.0 and 7.6.1 does not invalidate session after logout which could allow a local user to i... |
| CVE-2019-20907 | HIGH | 7.5 | 6.3% | Jul 13, 2020 | In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when o... |
| CVE-2019-20901 | MEDIUM | 6.1 | 1.2% | Jul 13, 2020 | The login.jsp resource in Jira before version 8.5.2, and from version 8.6.0 before version 8.6.1 allows remote attackers... |
| CVE-2019-20900 | MEDIUM | 4.8 | 0.9% | Jul 13, 2020 | Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript... |
| CVE-2019-20899 | MEDIUM | 5.3 | 2.1% | Jul 13, 2020 | The Gadget API in Atlassian Jira Server and Data Center in affected versions allows remote attackers to make Jira unresp... |
| CVE-2019-20898 | HIGH | 7.5 | 1.3% | Jul 13, 2020 | Affected versions of Atlassian Jira Server and Data Center allow remote attackers to access sensitive information withou... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now