2019 CVE Vulnerabilities

17,624 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-20854HIGH7.5An issue was discovered in Mattermost Server before 5.17.0. It allows remote attackers to cause a denial of service (cli...
CVE-2019-20853CRITICAL9.8An issue was discovered in Mattermost Packages before 5.16.3. A Droplet could allow Internet access to a service that ha...
CVE-2019-20852HIGH7.5An issue was discovered in Mattermost Mobile Apps before 1.26.0. Local logging is not blocked for sensitive information ...
CVE-2019-20851CRITICAL9.1An issue was discovered in Mattermost Mobile Apps before 1.26.0. An attacker can use directory traversal with the Video ...
CVE-2019-20850MEDIUM5.3An issue was discovered in Mattermost Mobile Apps before 1.26.0. A view cache can persist on a device after a logout.
CVE-2019-20849MEDIUM5.3An issue was discovered in Mattermost Mobile Apps before 1.26.0. Cookie data can persist on a device after a logout.
CVE-2019-20848HIGH7.5An issue was discovered in Mattermost Mobile Apps before 1.26.0. The Quick Reply feature mishandles crafted replies.
CVE-2019-20847MEDIUM5.3An issue was discovered in Mattermost Server before 5.18.0. An attacker can send a user_typing WebSocket event to any ch...
CVE-2019-20846HIGH7.5An issue was discovered in Mattermost Server before 5.18.0. It has weak permissions for server-local file storage.
CVE-2019-20845HIGH7.5An issue was discovered in Mattermost Server before 5.18.0. It allows attackers to cause a denial of service (memory con...
CVE-2019-20844MEDIUM6.5An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. An attacker can spoof a d...
CVE-2019-20843HIGH7.5An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. There are weak permission...
CVE-2019-20842HIGH7.2An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. There is SQL injection by...
CVE-2019-20841HIGH8.8An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. CSRF can sometimes occur ...
CVE-2019-13033LOW3.3In CISOfy Lynis 2.x through 2.7.5, the license key can be obtained by looking at the process list when a data upload is ...
CVE-2019-9944HIGH7.5In Open Microscopy Environment OMERO.server 5.0.0 through 5.6.0, the reading of files from imported image filesets may c...
CVE-2019-9943HIGH7.5In ome.services.graphs.GraphTraversal.findObjectDetails in Open Microscopy Environment OMERO.server 5.1.0 through 5.6.0,...
CVE-2019-16245MEDIUM5.3OMERO before 5.6.1 makes the details of each user available to all users.
CVE-2019-20840HIGH7.5An issue was discovered in LibVNCServer before 0.9.13. libvncserver/ws_decode.c can lead to a crash because of unaligned...
CVE-2019-20839HIGH7.5libvncclient/sockets.c in LibVNCServer before 0.9.13 has a buffer overflow via a long socket filename.
CVE-2019-17655HIGH7.5A cleartext storage in a file or on disk (CWE-313) vulnerability in FortiOS SSL VPN 6.2.0 through 6.2.2, 6.0.9 and earli...
CVE-2019-18614HIGH7.8On the Cypress CYW20735 evaluation board, any data that exceeds 384 bytes is copied and causes an overflow. This is beca...
CVE-2019-20838HIGH7.5libpcre in PCRE before 8.43 allows a subject buffer over-read in JIT when UTF is disabled, and \X or \R has more than on...
CVE-2019-19112MEDIUM6.1The wpForo plugin 1.6.5 for WordPress allows XSS involving the wpf-dw-td-value class of dashboard.php.
CVE-2019-19111MEDIUM6.1The wpForo plugin 1.6.5 for WordPress allows XSS via the wp-admin/admin.php?page=wpforo-phrases langid parameter.

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now