2019 CVE Vulnerabilities
17,624 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-4704 | MEDIUM | 4.3 | 0.6% | Jul 1, 2020 | IBM Security Identity Manager Virtual Appliance 7.0.2 does not set the secure attribute on authorization tokens or sessi... |
| CVE-2019-4676 | HIGH | 7.8 | 0.5% | Jul 1, 2020 | IBM Security Identity Manager Virtual Appliance 7.0.2 stores user credentials in plain in clear text which can be read b... |
| CVE-2019-20408 | MEDIUM | 5.3 | 1.0% | Jul 1, 2020 | The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.7.0 allows remote attackers to access the con... |
| CVE-2019-19163 | HIGH | 8.8 | 0.6% | Jun 30, 2020 | A Vulnerability in the firmware of COMMAX WallPad(CDP-1020MB) allow an unauthenticated adjacent attacker to execute arbi... |
| CVE-2019-19161 | HIGH | 7.2 | 1.1% | Jun 30, 2020 | CyMiInstaller322 ActiveX which runs MIPLATFORM downloads files required to run applications. A vulnerability in download... |
| CVE-2019-20893 | CRITICAL | 9.8 | 2.2% | Jun 30, 2020 | An issue was discovered in Activision Infinity Ward Call of Duty Modern Warfare 2 through 2019-12-11. PartyHost_HandleJo... |
| CVE-2019-20416 | MEDIUM | 4.8 | 0.6% | Jun 30, 2020 | Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript... |
| CVE-2019-20415 | MEDIUM | 4.3 | 0.6% | Jun 30, 2020 | Atlassian Jira Server and Data Center in affected versions allows remote attackers to modify logging and profiling setti... |
| CVE-2019-19160 | HIGH | 8.8 | 0.6% | Jun 29, 2020 | Reportexpress ProPlus contains a vulnerability that could allow an arbitrary code execution by inserted VBscript into th... |
| CVE-2019-18256 | MEDIUM | 4.6 | 0.4% | Jun 29, 2020 | BIOTRONIK CardioMessenger II, The affected products use individual per-device credentials that are stored in a recoverab... |
| CVE-2019-18254 | MEDIUM | 4.6 | 0.2% | Jun 29, 2020 | BIOTRONIK CardioMessenger II, The affected products do not encrypt sensitive information while at rest. An attacker with... |
| CVE-2019-18252 | MEDIUM | 4.3 | 0.5% | Jun 29, 2020 | BIOTRONIK CardioMessenger II, The affected products allow credential reuse for multiple authentication purposes. An atta... |
| CVE-2019-18248 | MEDIUM | 4.3 | 0.4% | Jun 29, 2020 | BIOTRONIK CardioMessenger II, The affected products transmit credentials in clear-text prior to switching to an encrypte... |
| CVE-2019-18246 | MEDIUM | 4.3 | 0.5% | Jun 29, 2020 | BIOTRONIK CardioMessenger II, The affected products do not properly enforce mutual authentication with the BIOTRONIK Rem... |
| CVE-2019-3681 | CRITICAL | 9.8 | 1.4% | Jun 29, 2020 | A External Control of File Name or Path vulnerability in osc of SUSE Linux Enterprise Module for Development Tools 15, S... |
| CVE-2019-20414 | MEDIUM | 5.4 | 1.0% | Jun 29, 2020 | Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript... |
| CVE-2019-20413 | HIGH | 7.5 | 2.1% | Jun 29, 2020 | Affected versions of Atlassian Jira Server and Data Center allow remote attackers to impact the application's availabili... |
| CVE-2019-20412 | MEDIUM | 5.3 | 1.9% | Jun 29, 2020 | The Convert Sub-Task to Issue page in affected versions of Atlassian Jira Server and Data Center allow remote attackers ... |
| CVE-2019-20411 | MEDIUM | 4.3 | 0.7% | Jun 29, 2020 | Affected versions of Atlassian Jira Server and Data Center allow remote attackers to modify Wallboard settings via a Cro... |
| CVE-2019-20410 | MEDIUM | 6.5 | 1.9% | Jun 29, 2020 | Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view sensitive information via an I... |
| CVE-2019-4650 | MEDIUM | 6.3 | 1.0% | Jun 26, 2020 | IBM Maximo Asset Management 7.6.1.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL s... |
| CVE-2019-19506 | HIGH | 7.5 | 1.1% | Jun 25, 2020 | Tenda PA6 Wi-Fi Powerline extender 1.0.1.21 is vulnerable to a denial of service, caused by an error in the "homeplugd" ... |
| CVE-2019-19505 | HIGH | 8.8 | 3.5% | Jun 25, 2020 | Tenda PA6 Wi-Fi Powerline extender 1.0.1.21 is vulnerable to a stack-based buffer overflow, caused by improper bounds ch... |
| CVE-2019-16213 | HIGH | 8.8 | 2.9% | Jun 25, 2020 | Tenda PA6 Wi-Fi Powerline extender 1.0.1.21 could allow a remote authenticated attacker to execute arbitrary commands on... |
| CVE-2019-20892 | MEDIUM | 6.5 | 2.3% | Jun 25, 2020 | net-snmp before 5.8.1.pre1 has a double free in usm_free_usmStateReference in snmplib/snmpusm.c via an SNMPv3 GetBulk re... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now