2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-20849 | MEDIUM | 5.3 | 0.9% | Jun 19, 2020 | An issue was discovered in Mattermost Mobile Apps before 1.26.0. Cookie data can persist on a device after a logout. |
| CVE-2019-20848 | HIGH | 7.5 | 0.9% | Jun 19, 2020 | An issue was discovered in Mattermost Mobile Apps before 1.26.0. The Quick Reply feature mishandles crafted replies. |
| CVE-2019-20847 | MEDIUM | 5.3 | 0.8% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.18.0. An attacker can send a user_typing WebSocket event to any ch... |
| CVE-2019-20846 | HIGH | 7.5 | 1.1% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.18.0. It has weak permissions for server-local file storage. |
| CVE-2019-20845 | HIGH | 7.5 | 1.1% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.18.0. It allows attackers to cause a denial of service (memory con... |
| CVE-2019-20844 | MEDIUM | 6.5 | 0.4% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. An attacker can spoof a d... |
| CVE-2019-20843 | HIGH | 7.5 | 1.1% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. There are weak permission... |
| CVE-2019-20842 | HIGH | 7.2 | 1.0% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. There is SQL injection by... |
| CVE-2019-20841 | HIGH | 8.8 | 0.4% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. CSRF can sometimes occur ... |
| CVE-2019-13033 | LOW | 3.3 | 0.4% | Jun 18, 2020 | In CISOfy Lynis 2.x through 2.7.5, the license key can be obtained by looking at the process list when a data upload is ... |
| CVE-2019-9944 | HIGH | 7.5 | 1.1% | Jun 17, 2020 | In Open Microscopy Environment OMERO.server 5.0.0 through 5.6.0, the reading of files from imported image filesets may c... |
| CVE-2019-9943 | HIGH | 7.5 | 0.8% | Jun 17, 2020 | In ome.services.graphs.GraphTraversal.findObjectDetails in Open Microscopy Environment OMERO.server 5.1.0 through 5.6.0,... |
| CVE-2019-16245 | MEDIUM | 5.3 | 0.9% | Jun 17, 2020 | OMERO before 5.6.1 makes the details of each user available to all users. |
| CVE-2019-20840 | HIGH | 7.5 | 2.6% | Jun 17, 2020 | An issue was discovered in LibVNCServer before 0.9.13. libvncserver/ws_decode.c can lead to a crash because of unaligned... |
| CVE-2019-20839 | HIGH | 7.5 | 3.6% | Jun 17, 2020 | libvncclient/sockets.c in LibVNCServer before 0.9.13 has a buffer overflow via a long socket filename. |
| CVE-2019-17655 | HIGH | 7.5 | 1.0% | Jun 16, 2020 | A cleartext storage in a file or on disk (CWE-313) vulnerability in FortiOS SSL VPN 6.2.0 through 6.2.2, 6.0.9 and earli... |
| CVE-2019-18614 | HIGH | 7.8 | 0.3% | Jun 16, 2020 | On the Cypress CYW20735 evaluation board, any data that exceeds 384 bytes is copied and causes an overflow. This is beca... |
| CVE-2019-20838 | HIGH | 7.5 | 2.8% | Jun 15, 2020 | libpcre in PCRE before 8.43 allows a subject buffer over-read in JIT when UTF is disabled, and \X or \R has more than on... |
| CVE-2019-19112 | MEDIUM | 6.1 | 0.9% | Jun 15, 2020 | The wpForo plugin 1.6.5 for WordPress allows XSS involving the wpf-dw-td-value class of dashboard.php. |
| CVE-2019-19111 | MEDIUM | 6.1 | 0.9% | Jun 15, 2020 | The wpForo plugin 1.6.5 for WordPress allows XSS via the wp-admin/admin.php?page=wpforo-phrases langid parameter. |
| CVE-2019-19110 | MEDIUM | 4.8 | 0.7% | Jun 15, 2020 | The wpForo plugin 1.6.5 for WordPress allows XSS via the wp-admin/admin.php?page=wpforo-phrases s parameter. |
| CVE-2019-19109 | HIGH | 8.8 | 0.7% | Jun 15, 2020 | The wpForo plugin 1.6.5 for WordPress allows wp-admin/admin.php?page=wpforo-usergroups CSRF. |
| CVE-2019-16252 | MEDIUM | 5.9 | 0.5% | Jun 12, 2020 | Missing SSL Certificate Validation in the Nutfind.com application through 3.9.12 for Android allows a man-in-the-middle ... |
| CVE-2019-15123 | HIGH | 7.2 | 2.4% | Jun 12, 2020 | The Branding Module in Viki Vera 4.9.1.26180 allows an authenticated user to change the logo on the website. An attacker... |
| CVE-2019-5735 | — | — | — | Jun 10, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now