2019 CVE Vulnerabilities
17,624 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-20897 | MEDIUM | 6.5 | 1.9% | Jul 13, 2020 | The avatar upload feature in affected versions of Atlassian Jira Server and Data Center allows remote attackers to achie... |
| CVE-2019-17638 | CRITICAL | 9.4 | 11.1% | Jul 9, 2020 | In Eclipse Jetty, versions 9.4.27.v20200227 to 9.4.29.v20200521, in case of too large response headers, Jetty throws an ... |
| CVE-2019-10096 | — | — | — | Jul 9, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2019-19417 | HIGH | 7.5 | 0.9% | Jul 8, 2020 | The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attacker could exploit the... |
| CVE-2019-19416 | HIGH | 7.5 | 0.9% | Jul 8, 2020 | The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attacker could exploit the... |
| CVE-2019-19415 | HIGH | 7.5 | 0.9% | Jul 8, 2020 | The SIP module of some Huawei products have a denial of service (DoS) vulnerability. A remote attacker could exploit the... |
| CVE-2019-20896 | CRITICAL | 9.8 | 1.0% | Jul 7, 2020 | WebChess 1.0 allows SQL injection via the messageFrom, gameID, opponent, messageID, or to parameter. |
| CVE-2019-19935 | MEDIUM | 6.1 | 1.8% | Jul 7, 2020 | Froala Editor before 3.2.3 allows XSS. |
| CVE-2019-4324 | MEDIUM | 6.1 | 0.6% | Jul 7, 2020 | "HCL AppScan Enterprise is susceptible to Cross-Site Scripting while importing a specially crafted test policy." |
| CVE-2019-4323 | MEDIUM | 4.3 | 0.8% | Jul 7, 2020 | "HCL AppScan Enterprise advisory API documentation is susceptible to clickjacking, which could allow an attacker to embe... |
| CVE-2019-14900 | MEDIUM | 6.5 | 2.1% | Jul 6, 2020 | A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementati... |
| CVE-2019-8252 | MEDIUM | 5.5 | 2.4% | Jul 6, 2020 | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20... |
| CVE-2019-8251 | MEDIUM | 5.5 | 2.4% | Jul 6, 2020 | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20... |
| CVE-2019-8250 | HIGH | 7.8 | 3.6% | Jul 6, 2020 | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20... |
| CVE-2019-8249 | HIGH | 7.8 | 3.6% | Jul 6, 2020 | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20... |
| CVE-2019-8066 | HIGH | 7.8 | 5.3% | Jul 6, 2020 | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20... |
| CVE-2019-20419 | HIGH | 7.8 | 0.8% | Jul 3, 2020 | Affected versions of Atlassian Jira Server and Data Center allow remote attackers to execute arbitrary code via a DLL hi... |
| CVE-2019-20418 | MEDIUM | 6.5 | 1.0% | Jul 3, 2020 | Affected versions of Atlassian Jira Server and Data Center allow remote attackers to prevent users from accessing the in... |
| CVE-2019-20894 | HIGH | 7.5 | 1.6% | Jul 2, 2020 | Traefik 2.x, in certain configurations, allows HTTPS sessions to proceed without mutual TLS verification in a situation ... |
| CVE-2019-20417 | — | — | — | Jul 2, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-15011. Reason: This candidate is a reservation d... |
| CVE-2019-15312 | HIGH | 8.8 | 2.9% | Jul 1, 2020 | An issue was discovered on Zolo Halo devices via the Linkplay firmware. There is a Zolo Halo DNS rebinding attack. The d... |
| CVE-2019-15311 | CRITICAL | 9.8 | 7.6% | Jul 1, 2020 | An issue was discovered on Zolo Halo devices via the Linkplay firmware. There is Zolo Halo LAN remote code execution. Th... |
| CVE-2019-15310 | CRITICAL | 9.8 | 8.3% | Jul 1, 2020 | An issue was discovered on various devices via the Linkplay firmware. There is WAN remote code execution without user in... |
| CVE-2019-4706 | LOW | 2.7 | 0.8% | Jul 1, 2020 | IBM Security Identity Manager Virtual Appliance 7.0.2 writes information to log files which can be of a sensitive nature... |
| CVE-2019-4705 | LOW | 2.7 | 0.8% | Jul 1, 2020 | IBM Security Identity Manager Virtual Appliance 7.0.2 discloses sensitive information to unauthorized users. The informa... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now