2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-19415HIGH7.5The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attacker could exploit the...
CVE-2019-20896CRITICAL9.8WebChess 1.0 allows SQL injection via the messageFrom, gameID, opponent, messageID, or to parameter.
CVE-2019-19935MEDIUM6.1Froala Editor before 3.2.3 allows XSS.
CVE-2019-4324MEDIUM6.1"HCL AppScan Enterprise is susceptible to Cross-Site Scripting while importing a specially crafted test policy."
CVE-2019-4323MEDIUM4.3"HCL AppScan Enterprise advisory API documentation is susceptible to clickjacking, which could allow an attacker to embe...
CVE-2019-14900MEDIUM6.5A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementati...
CVE-2019-8252MEDIUM5.5Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20...
CVE-2019-8251MEDIUM5.5Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20...
CVE-2019-8250HIGH7.8Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20...
CVE-2019-8249HIGH7.8Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20...
CVE-2019-8066HIGH7.8Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20...
CVE-2019-20419HIGH7.8Affected versions of Atlassian Jira Server and Data Center allow remote attackers to execute arbitrary code via a DLL hi...
CVE-2019-20418MEDIUM6.5Affected versions of Atlassian Jira Server and Data Center allow remote attackers to prevent users from accessing the in...
CVE-2019-20894HIGH7.5Traefik 2.x, in certain configurations, allows HTTPS sessions to proceed without mutual TLS verification in a situation ...
CVE-2019-20417Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-15011. Reason: This candidate is a reservation d...
CVE-2019-15312HIGH8.8An issue was discovered on Zolo Halo devices via the Linkplay firmware. There is a Zolo Halo DNS rebinding attack. The d...
CVE-2019-15311CRITICAL9.8An issue was discovered on Zolo Halo devices via the Linkplay firmware. There is Zolo Halo LAN remote code execution. Th...
CVE-2019-15310CRITICAL9.8An issue was discovered on various devices via the Linkplay firmware. There is WAN remote code execution without user in...
CVE-2019-4706LOW2.7IBM Security Identity Manager Virtual Appliance 7.0.2 writes information to log files which can be of a sensitive nature...
CVE-2019-4705LOW2.7IBM Security Identity Manager Virtual Appliance 7.0.2 discloses sensitive information to unauthorized users. The informa...
CVE-2019-4704MEDIUM4.3IBM Security Identity Manager Virtual Appliance 7.0.2 does not set the secure attribute on authorization tokens or sessi...
CVE-2019-4676HIGH7.8IBM Security Identity Manager Virtual Appliance 7.0.2 stores user credentials in plain in clear text which can be read b...
CVE-2019-20408MEDIUM5.3The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.7.0 allows remote attackers to access the con...
CVE-2019-19163HIGH8.8A Vulnerability in the firmware of COMMAX WallPad(CDP-1020MB) allow an unauthenticated adjacent attacker to execute arbi...
CVE-2019-19161HIGH7.2CyMiInstaller322 ActiveX which runs MIPLATFORM downloads files required to run applications. A vulnerability in download...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now