2019 CVE Vulnerabilities

17,624 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-20897MEDIUM6.5The avatar upload feature in affected versions of Atlassian Jira Server and Data Center allows remote attackers to achie...
CVE-2019-17638CRITICAL9.4In Eclipse Jetty, versions 9.4.27.v20200227 to 9.4.29.v20200521, in case of too large response headers, Jetty throws an ...
CVE-2019-10096——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2019-19417HIGH7.5The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attacker could exploit the...
CVE-2019-19416HIGH7.5The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attacker could exploit the...
CVE-2019-19415HIGH7.5The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attacker could exploit the...
CVE-2019-20896CRITICAL9.8WebChess 1.0 allows SQL injection via the messageFrom, gameID, opponent, messageID, or to parameter.
CVE-2019-19935MEDIUM6.1Froala Editor before 3.2.3 allows XSS.
CVE-2019-4324MEDIUM6.1"HCL AppScan Enterprise is susceptible to Cross-Site Scripting while importing a specially crafted test policy."
CVE-2019-4323MEDIUM4.3"HCL AppScan Enterprise advisory API documentation is susceptible to clickjacking, which could allow an attacker to embe...
CVE-2019-14900MEDIUM6.5A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementati...
CVE-2019-8252MEDIUM5.5Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20...
CVE-2019-8251MEDIUM5.5Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20...
CVE-2019-8250HIGH7.8Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20...
CVE-2019-8249HIGH7.8Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20...
CVE-2019-8066HIGH7.8Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20...
CVE-2019-20419HIGH7.8Affected versions of Atlassian Jira Server and Data Center allow remote attackers to execute arbitrary code via a DLL hi...
CVE-2019-20418MEDIUM6.5Affected versions of Atlassian Jira Server and Data Center allow remote attackers to prevent users from accessing the in...
CVE-2019-20894HIGH7.5Traefik 2.x, in certain configurations, allows HTTPS sessions to proceed without mutual TLS verification in a situation ...
CVE-2019-20417——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-15011. Reason: This candidate is a reservation d...
CVE-2019-15312HIGH8.8An issue was discovered on Zolo Halo devices via the Linkplay firmware. There is a Zolo Halo DNS rebinding attack. The d...
CVE-2019-15311CRITICAL9.8An issue was discovered on Zolo Halo devices via the Linkplay firmware. There is Zolo Halo LAN remote code execution. Th...
CVE-2019-15310CRITICAL9.8An issue was discovered on various devices via the Linkplay firmware. There is WAN remote code execution without user in...
CVE-2019-4706LOW2.7IBM Security Identity Manager Virtual Appliance 7.0.2 writes information to log files which can be of a sensitive nature...
CVE-2019-4705LOW2.7IBM Security Identity Manager Virtual Appliance 7.0.2 discloses sensitive information to unauthorized users. The informa...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now