2019 CVE Vulnerabilities

17,624 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-4704MEDIUM4.3IBM Security Identity Manager Virtual Appliance 7.0.2 does not set the secure attribute on authorization tokens or sessi...
CVE-2019-4676HIGH7.8IBM Security Identity Manager Virtual Appliance 7.0.2 stores user credentials in plain in clear text which can be read b...
CVE-2019-20408MEDIUM5.3The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.7.0 allows remote attackers to access the con...
CVE-2019-19163HIGH8.8A Vulnerability in the firmware of COMMAX WallPad(CDP-1020MB) allow an unauthenticated adjacent attacker to execute arbi...
CVE-2019-19161HIGH7.2CyMiInstaller322 ActiveX which runs MIPLATFORM downloads files required to run applications. A vulnerability in download...
CVE-2019-20893CRITICAL9.8An issue was discovered in Activision Infinity Ward Call of Duty Modern Warfare 2 through 2019-12-11. PartyHost_HandleJo...
CVE-2019-20416MEDIUM4.8Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript...
CVE-2019-20415MEDIUM4.3Atlassian Jira Server and Data Center in affected versions allows remote attackers to modify logging and profiling setti...
CVE-2019-19160HIGH8.8Reportexpress ProPlus contains a vulnerability that could allow an arbitrary code execution by inserted VBscript into th...
CVE-2019-18256MEDIUM4.6BIOTRONIK CardioMessenger II, The affected products use individual per-device credentials that are stored in a recoverab...
CVE-2019-18254MEDIUM4.6BIOTRONIK CardioMessenger II, The affected products do not encrypt sensitive information while at rest. An attacker with...
CVE-2019-18252MEDIUM4.3BIOTRONIK CardioMessenger II, The affected products allow credential reuse for multiple authentication purposes. An atta...
CVE-2019-18248MEDIUM4.3BIOTRONIK CardioMessenger II, The affected products transmit credentials in clear-text prior to switching to an encrypte...
CVE-2019-18246MEDIUM4.3BIOTRONIK CardioMessenger II, The affected products do not properly enforce mutual authentication with the BIOTRONIK Rem...
CVE-2019-3681CRITICAL9.8A External Control of File Name or Path vulnerability in osc of SUSE Linux Enterprise Module for Development Tools 15, S...
CVE-2019-20414MEDIUM5.4Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript...
CVE-2019-20413HIGH7.5Affected versions of Atlassian Jira Server and Data Center allow remote attackers to impact the application's availabili...
CVE-2019-20412MEDIUM5.3The Convert Sub-Task to Issue page in affected versions of Atlassian Jira Server and Data Center allow remote attackers ...
CVE-2019-20411MEDIUM4.3Affected versions of Atlassian Jira Server and Data Center allow remote attackers to modify Wallboard settings via a Cro...
CVE-2019-20410MEDIUM6.5Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view sensitive information via an I...
CVE-2019-4650MEDIUM6.3IBM Maximo Asset Management 7.6.1.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL s...
CVE-2019-19506HIGH7.5Tenda PA6 Wi-Fi Powerline extender 1.0.1.21 is vulnerable to a denial of service, caused by an error in the "homeplugd" ...
CVE-2019-19505HIGH8.8Tenda PA6 Wi-Fi Powerline extender 1.0.1.21 is vulnerable to a stack-based buffer overflow, caused by improper bounds ch...
CVE-2019-16213HIGH8.8Tenda PA6 Wi-Fi Powerline extender 1.0.1.21 could allow a remote authenticated attacker to execute arbitrary commands on...
CVE-2019-20892MEDIUM6.5net-snmp before 5.8.1.pre1 has a double free in usm_free_usmStateReference in snmplib/snmpusm.c via an SNMPv3 GetBulk re...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now