2019 CVE Vulnerabilities

17,624 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-20879MEDIUM4.3An issue was discovered in Mattermost Server before 5.8.0, 5.7.2, 5.6.5, and 4.10.7. Changes to e-mail addresses do not ...
CVE-2019-20878MEDIUM4.3An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. Changes, within the application, to...
CVE-2019-20877MEDIUM5.3An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows attackers to obtain sensi...
CVE-2019-20876MEDIUM5.4An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. Users can deactivate themselves, by...
CVE-2019-20875MEDIUM5.3An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows a password reset to proce...
CVE-2019-20874HIGH7.5An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows attackers to obtain sensi...
CVE-2019-20873MEDIUM6.5An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows attackers to obtain sensi...
CVE-2019-20872MEDIUM5.5An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. SSRF can attack local services.
CVE-2019-20871HIGH7.5An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. The Markdown library allows catastr...
CVE-2019-20870MEDIUM4.3An issue was discovered in Mattermost Server before 5.10.0. An attacker can bypass the intended appearance of the Edited...
CVE-2019-20869MEDIUM5.3An issue was discovered in Mattermost Server before 5.10.0, 5.9.1, 5.8.2, and 4.10.9. A non-member could change the Upda...
CVE-2019-20868HIGH7.5An issue was discovered in Mattermost Server before 5.11.0. Invite IDs were improperly generated.
CVE-2019-20867MEDIUM5.3An issue was discovered in Mattermost Server before 5.11.0. An attacker can interfere with a channel's post loading via ...
CVE-2019-20866MEDIUM5.3An issue was discovered in Mattermost Server before 5.12.0. Use of a Proxy HTTP header, rather than the source address i...
CVE-2019-20865HIGH8.8An issue was discovered in Mattermost Server before 5.12.0, 5.11.1, 5.10.2, 5.9.2, and 4.10.10. The login page allows CS...
CVE-2019-20864HIGH7.5An issue was discovered in Mattermost Plugins before 5.13.0. The GitHub plugin allows an attacker to attach his Mattermo...
CVE-2019-20863HIGH7.5An issue was discovered in Mattermost Server before 5.13.0. Incoming webhook creation is not properly restricted.
CVE-2019-20862HIGH7.5An issue was discovered in Mattermost Server before 5.13.0. Non-members may fetch a team's slash commands.
CVE-2019-20861HIGH8.8An issue was discovered in Mattermost Desktop App before 4.2.2. It allows attackers to execute arbitrary code via a craf...
CVE-2019-20860MEDIUM5.5An issue was discovered in Mattermost Server before 5.14.0, 5.13.3, 5.12.6, and 5.9.4. It allows remote attackers to cau...
CVE-2019-20859HIGH7.5An issue was discovered in Mattermost Server before 5.15.0. Login access control can be bypassed via crafted input.
CVE-2019-20858HIGH7.5An issue was discovered in Mattermost Server before 5.15.0. It allows attackers to cause a denial of service (CPU consum...
CVE-2019-20857HIGH7.5An issue was discovered in Mattermost Server before 5.16.0. It allows attackers to cause a denial of service (markdown r...
CVE-2019-20856CRITICAL9.8An issue was discovered in Mattermost Desktop App before 4.3.0 on macOS. It allows dylib injection.
CVE-2019-20855HIGH7.5An issue was discovered in Mattermost Server before 5.16.1, 5.15.2, 5.14.5, and 5.9.6. It allows attackers to obtain sen...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now