2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-18454MEDIUM6.1An issue was discovered in GitLab Community and Enterprise Edition 10.5 through 12.4 in link validation for RDoc wiki pa...
CVE-2019-18453MEDIUM4.3An issue was discovered in GitLab Community and Enterprise Edition 11.6 through 12.4 in the add comments via email featu...
CVE-2019-18452MEDIUM5.3An issue was discovered in GitLab Community and Enterprise Edition 11.3 through 12.4 when moving an issue to a public pr...
CVE-2019-18451MEDIUM6.1An issue was discovered in GitLab Community and Enterprise Edition 10.7.4 through 12.4 in the InternalRedirect filtering...
CVE-2019-18450MEDIUM4.3An issue was discovered in GitLab Community and Enterprise Edition before 12.4 in the Project labels feature. It has Ins...
CVE-2019-18449MEDIUM4.3An issue was discovered in GitLab Community and Enterprise Edition before 12.4 in the autocomplete feature. It has Insec...
CVE-2019-18448MEDIUM6.5An issue was discovered in GitLab Community and Enterprise Edition before 12.4. It has Incorrect Access Control.
CVE-2019-18447MEDIUM4.3An issue was discovered in GitLab Community and Enterprise Edition before 12.4. It has Insecure Permissions.
CVE-2019-18446MEDIUM4.3An issue was discovered in GitLab Community and Enterprise Edition 8.15 through 12.4. It has Insecure Permissions (issue...
CVE-2019-15845MEDIUM6.5Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 mishandles path checking within File.fnmatch functions.
CVE-2019-14449MEDIUM5.4An issue was discovered in Cloudera Manager 5.x before 5.16.2, 6.0.x before 6.0.2, and 6.1.x before 6.1.1. Malicious imp...
CVE-2019-19129MEDIUM6.1Afterlogic WebMail Pro 8.3.11, and WebMail in Afterlogic Aurora 8.3.11, allows Remote Stored XSS via an attachment name.
CVE-2019-18459MEDIUM5.3An issue was discovered in GitLab Community and Enterprise Edition 11.3 to 12.3 in the protected environments feature. I...
CVE-2019-16243MEDIUM6.1On TCL Alcatel Cingular Flip 2 B9HUAH1 devices, there is an undocumented web API that allows unprivileged JavaScript, in...
CVE-2019-16242MEDIUM6.8On TCL Alcatel Cingular Flip 2 B9HUAH1 devices, there is an engineering application named omamock that is vulnerable to ...
CVE-2019-16241MEDIUM6.8On TCL Alcatel Cingular Flip 2 B9HUAH1 devices, PIN authentication can be bypassed by creating a special file within the...
CVE-2019-15688MEDIUM6.1Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small ...
CVE-2019-15687MEDIUM6.5Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small ...
CVE-2019-15686MEDIUM4.3Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small ...
CVE-2019-15685MEDIUM4.3Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small ...
CVE-2019-19306MEDIUM5.4The Zoho CRM Lead Magnet plugin 1.6.9.1 for WordPress allows XSS via module, EditShortcode, or LayoutName.
CVE-2019-19206MEDIUM5.4Dolibarr CRM/ERP 10.0.3 allows viewimage.php?file= Stored XSS due to JavaScript execution in an SVG image for a profile ...
CVE-2019-18463MEDIUM4.3An issue was discovered in GitLab Community and Enterprise Edition through 12.4. It has Insecure Permissions (issue 4 of...
CVE-2019-18462MEDIUM4.3An issue was discovered in GitLab Community and Enterprise Edition 11.3 through 12.4. It has Insecure Permissions.
CVE-2019-18461MEDIUM4.3An issue was discovered in GitLab Community and Enterprise Edition 11.3 through 12.3 when a sub group epic is added to a...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now