2019 CVE Vulnerabilities

17,624 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-20909HIGH7.5An issue was discovered in GNU LibreDWG through 0.9.3. There is a NULL pointer dereference in the function dwg_encode_LW...
CVE-2019-4748MEDIUM5.4IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability allows users to embed...
CVE-2019-4747MEDIUM5.4IBM Team Concert (RTC) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScr...
CVE-2019-20908MEDIUM6.7An issue was discovered in drivers/firmware/efi/efi.c in the Linux kernel before 5.4. Incorrect access permissions for t...
CVE-2019-17639MEDIUM5.3In Eclipse OpenJ9 prior to version 0.21 on Power platforms, calling the System.arraycopy method with a length longer tha...
CVE-2019-19326MEDIUM5.9Silverstripe CMS sites through 4.4.4 which have opted into HTTP Cache Headers on responses served by the framework's HTT...
CVE-2019-17637HIGH7.1In all versions of Eclipse Web Tools Platform through release 3.18 (2020-06), XML and DTD files referring to external en...
CVE-2019-12784HIGH8.8An issue was discovered in Verint Impact 360 15.1. At wfo/control/signin, the login form can accept submissions from ext...
CVE-2019-12783MEDIUM6.1An issue was discovered in Verint Impact 360 15.1. At wfo/control/signin, the rd parameter can accept a URL, to which us...
CVE-2019-12773MEDIUM6.1An issue was discovered in Verint Impact 360 15.1. At wfo/help/help_popup.jsp, the helpURL parameter can be changed to e...
CVE-2019-15888——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2019-15887——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2019-15886——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2019-15885——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2019-15884——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2019-15883——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2019-15882——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2019-15881——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2019-19338MEDIUM5.5A flaw was found in the fix for CVE-2019-11135, in the Linux upstream kernel versions before 5.5 where, the way Intel CP...
CVE-2019-4591HIGH7.8IBM Maximo Asset Management 7.6.0 and 7.6.1 does not invalidate session after logout which could allow a local user to i...
CVE-2019-20907HIGH7.5In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when o...
CVE-2019-20901MEDIUM6.1The login.jsp resource in Jira before version 8.5.2, and from version 8.6.0 before version 8.6.1 allows remote attackers...
CVE-2019-20900MEDIUM4.8Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript...
CVE-2019-20899MEDIUM5.3The Gadget API in Atlassian Jira Server and Data Center in affected versions allows remote attackers to make Jira unresp...
CVE-2019-20898HIGH7.5Affected versions of Atlassian Jira Server and Data Center allow remote attackers to access sensitive information withou...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now