2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-20874 | HIGH | 7.5 | 1.2% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows attackers to obtain sensi... |
| CVE-2019-20873 | MEDIUM | 6.5 | 0.9% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows attackers to obtain sensi... |
| CVE-2019-20872 | MEDIUM | 5.5 | 0.3% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. SSRF can attack local services. |
| CVE-2019-20871 | HIGH | 7.5 | 1.1% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. The Markdown library allows catastr... |
| CVE-2019-20870 | MEDIUM | 4.3 | 0.7% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.10.0. An attacker can bypass the intended appearance of the Edited... |
| CVE-2019-20869 | MEDIUM | 5.3 | 0.8% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.10.0, 5.9.1, 5.8.2, and 4.10.9. A non-member could change the Upda... |
| CVE-2019-20868 | HIGH | 7.5 | 0.9% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.11.0. Invite IDs were improperly generated. |
| CVE-2019-20867 | MEDIUM | 5.3 | 0.8% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.11.0. An attacker can interfere with a channel's post loading via ... |
| CVE-2019-20866 | MEDIUM | 5.3 | 0.9% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.12.0. Use of a Proxy HTTP header, rather than the source address i... |
| CVE-2019-20865 | HIGH | 8.8 | 0.5% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.12.0, 5.11.1, 5.10.2, 5.9.2, and 4.10.10. The login page allows CS... |
| CVE-2019-20864 | HIGH | 7.5 | 0.9% | Jun 19, 2020 | An issue was discovered in Mattermost Plugins before 5.13.0. The GitHub plugin allows an attacker to attach his Mattermo... |
| CVE-2019-20863 | HIGH | 7.5 | 0.9% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.13.0. Incoming webhook creation is not properly restricted. |
| CVE-2019-20862 | HIGH | 7.5 | 0.9% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.13.0. Non-members may fetch a team's slash commands. |
| CVE-2019-20861 | HIGH | 8.8 | 1.7% | Jun 19, 2020 | An issue was discovered in Mattermost Desktop App before 4.2.2. It allows attackers to execute arbitrary code via a craf... |
| CVE-2019-20860 | MEDIUM | 5.5 | 0.9% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.14.0, 5.13.3, 5.12.6, and 5.9.4. It allows remote attackers to cau... |
| CVE-2019-20859 | HIGH | 7.5 | 1.2% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.15.0. Login access control can be bypassed via crafted input. |
| CVE-2019-20858 | HIGH | 7.5 | 1.1% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.15.0. It allows attackers to cause a denial of service (CPU consum... |
| CVE-2019-20857 | HIGH | 7.5 | 1.1% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.16.0. It allows attackers to cause a denial of service (markdown r... |
| CVE-2019-20856 | CRITICAL | 9.8 | 1.4% | Jun 19, 2020 | An issue was discovered in Mattermost Desktop App before 4.3.0 on macOS. It allows dylib injection. |
| CVE-2019-20855 | HIGH | 7.5 | 1.2% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.16.1, 5.15.2, 5.14.5, and 5.9.6. It allows attackers to obtain sen... |
| CVE-2019-20854 | HIGH | 7.5 | 1.3% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.17.0. It allows remote attackers to cause a denial of service (cli... |
| CVE-2019-20853 | CRITICAL | 9.8 | 2.2% | Jun 19, 2020 | An issue was discovered in Mattermost Packages before 5.16.3. A Droplet could allow Internet access to a service that ha... |
| CVE-2019-20852 | HIGH | 7.5 | 1.1% | Jun 19, 2020 | An issue was discovered in Mattermost Mobile Apps before 1.26.0. Local logging is not blocked for sensitive information ... |
| CVE-2019-20851 | CRITICAL | 9.1 | 1.4% | Jun 19, 2020 | An issue was discovered in Mattermost Mobile Apps before 1.26.0. An attacker can use directory traversal with the Video ... |
| CVE-2019-20850 | MEDIUM | 5.3 | 0.9% | Jun 19, 2020 | An issue was discovered in Mattermost Mobile Apps before 1.26.0. A view cache can persist on a device after a logout. |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now