2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-19326MEDIUM5.9Silverstripe CMS sites through 4.4.4 which have opted into HTTP Cache Headers on responses served by the framework's HTT...
CVE-2019-17637HIGH7.1In all versions of Eclipse Web Tools Platform through release 3.18 (2020-06), XML and DTD files referring to external en...
CVE-2019-12784HIGH8.8An issue was discovered in Verint Impact 360 15.1. At wfo/control/signin, the login form can accept submissions from ext...
CVE-2019-12783MEDIUM6.1An issue was discovered in Verint Impact 360 15.1. At wfo/control/signin, the rd parameter can accept a URL, to which us...
CVE-2019-12773MEDIUM6.1An issue was discovered in Verint Impact 360 15.1. At wfo/help/help_popup.jsp, the helpURL parameter can be changed to e...
CVE-2019-15888Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2019-15887Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2019-15886Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2019-15885Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2019-15884Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2019-15883Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2019-15882Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2019-15881Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2019-19338MEDIUM5.5A flaw was found in the fix for CVE-2019-11135, in the Linux upstream kernel versions before 5.5 where, the way Intel CP...
CVE-2019-4591HIGH7.8IBM Maximo Asset Management 7.6.0 and 7.6.1 does not invalidate session after logout which could allow a local user to i...
CVE-2019-20907HIGH7.5In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when o...
CVE-2019-20901MEDIUM6.1The login.jsp resource in Jira before version 8.5.2, and from version 8.6.0 before version 8.6.1 allows remote attackers...
CVE-2019-20900MEDIUM4.8Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript...
CVE-2019-20899MEDIUM5.3The Gadget API in Atlassian Jira Server and Data Center in affected versions allows remote attackers to make Jira unresp...
CVE-2019-20898HIGH7.5Affected versions of Atlassian Jira Server and Data Center allow remote attackers to access sensitive information withou...
CVE-2019-20897MEDIUM6.5The avatar upload feature in affected versions of Atlassian Jira Server and Data Center allows remote attackers to achie...
CVE-2019-17638CRITICAL9.4In Eclipse Jetty, versions 9.4.27.v20200227 to 9.4.29.v20200521, in case of too large response headers, Jetty throws an ...
CVE-2019-10096Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2019-19417HIGH7.5The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attacker could exploit the...
CVE-2019-19416HIGH7.5The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attacker could exploit the...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now