2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-20893 | CRITICAL | 9.8 | 2.2% | Jun 30, 2020 | An issue was discovered in Activision Infinity Ward Call of Duty Modern Warfare 2 through 2019-12-11. PartyHost_HandleJo... |
| CVE-2019-20416 | MEDIUM | 4.8 | 0.6% | Jun 30, 2020 | Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript... |
| CVE-2019-20415 | MEDIUM | 4.3 | 0.6% | Jun 30, 2020 | Atlassian Jira Server and Data Center in affected versions allows remote attackers to modify logging and profiling setti... |
| CVE-2019-19160 | HIGH | 8.8 | 0.6% | Jun 29, 2020 | Reportexpress ProPlus contains a vulnerability that could allow an arbitrary code execution by inserted VBscript into th... |
| CVE-2019-18256 | MEDIUM | 4.6 | 0.4% | Jun 29, 2020 | BIOTRONIK CardioMessenger II, The affected products use individual per-device credentials that are stored in a recoverab... |
| CVE-2019-18254 | MEDIUM | 4.6 | 0.2% | Jun 29, 2020 | BIOTRONIK CardioMessenger II, The affected products do not encrypt sensitive information while at rest. An attacker with... |
| CVE-2019-18252 | MEDIUM | 4.3 | 0.5% | Jun 29, 2020 | BIOTRONIK CardioMessenger II, The affected products allow credential reuse for multiple authentication purposes. An atta... |
| CVE-2019-18248 | MEDIUM | 4.3 | 0.4% | Jun 29, 2020 | BIOTRONIK CardioMessenger II, The affected products transmit credentials in clear-text prior to switching to an encrypte... |
| CVE-2019-18246 | MEDIUM | 4.3 | 0.5% | Jun 29, 2020 | BIOTRONIK CardioMessenger II, The affected products do not properly enforce mutual authentication with the BIOTRONIK Rem... |
| CVE-2019-3681 | CRITICAL | 9.8 | 1.4% | Jun 29, 2020 | A External Control of File Name or Path vulnerability in osc of SUSE Linux Enterprise Module for Development Tools 15, S... |
| CVE-2019-20414 | MEDIUM | 5.4 | 1.0% | Jun 29, 2020 | Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript... |
| CVE-2019-20413 | HIGH | 7.5 | 2.1% | Jun 29, 2020 | Affected versions of Atlassian Jira Server and Data Center allow remote attackers to impact the application's availabili... |
| CVE-2019-20412 | MEDIUM | 5.3 | 1.9% | Jun 29, 2020 | The Convert Sub-Task to Issue page in affected versions of Atlassian Jira Server and Data Center allow remote attackers ... |
| CVE-2019-20411 | MEDIUM | 4.3 | 0.7% | Jun 29, 2020 | Affected versions of Atlassian Jira Server and Data Center allow remote attackers to modify Wallboard settings via a Cro... |
| CVE-2019-20410 | MEDIUM | 6.5 | 1.9% | Jun 29, 2020 | Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view sensitive information via an I... |
| CVE-2019-4650 | MEDIUM | 6.3 | 1.0% | Jun 26, 2020 | IBM Maximo Asset Management 7.6.1.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL s... |
| CVE-2019-19506 | HIGH | 7.5 | 1.1% | Jun 25, 2020 | Tenda PA6 Wi-Fi Powerline extender 1.0.1.21 is vulnerable to a denial of service, caused by an error in the "homeplugd" ... |
| CVE-2019-19505 | HIGH | 8.8 | 3.5% | Jun 25, 2020 | Tenda PA6 Wi-Fi Powerline extender 1.0.1.21 is vulnerable to a stack-based buffer overflow, caused by improper bounds ch... |
| CVE-2019-16213 | HIGH | 8.8 | 2.9% | Jun 25, 2020 | Tenda PA6 Wi-Fi Powerline extender 1.0.1.21 could allow a remote authenticated attacker to execute arbitrary commands on... |
| CVE-2019-20892 | MEDIUM | 6.5 | 2.3% | Jun 25, 2020 | net-snmp before 5.8.1.pre1 has a double free in usm_free_usmStateReference in snmplib/snmpusm.c via an SNMPv3 GetBulk re... |
| CVE-2019-20409 | CRITICAL | 9.8 | 2.5% | Jun 23, 2020 | The way in which velocity templates were used in Atlassian Jira Server and Data Center prior to version 8.8.0 allowed re... |
| CVE-2019-3865 | MEDIUM | 6.1 | 0.7% | Jun 22, 2020 | A vulnerability was found in quay-2, where a stored XSS vulnerability has been found in the super user function of quay.... |
| CVE-2019-14894 | HIGH | 7.2 | 4.1% | Jun 22, 2020 | A flaw was found in the CloudForms management engine version 5.10 and CloudForms management version 5.11, which triggere... |
| CVE-2019-14094 | HIGH | 7.8 | 0.2% | Jun 22, 2020 | Integer overflow in diag command handler when user inputs a large value for number of tasks field in the request packet ... |
| CVE-2019-14092 | MEDIUM | 5.5 | 0.2% | Jun 22, 2020 | System Services exports services without permission protect and can lead to information exposure in Snapdragon Industria... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now