2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-16540 | MEDIUM | 6.5 | 1.6% | Nov 21, 2019 | A path traversal vulnerability in Jenkins Support Core Plugin 2.63 and earlier allows attackers with Overall/Read permis... |
| CVE-2019-16539 | MEDIUM | 6.5 | 0.7% | Nov 21, 2019 | A missing permission check in Jenkins Support Core Plugin 2.63 and earlier allows attackers with Overall/Read permission... |
| CVE-2019-15704 | MEDIUM | 5.5 | 0.2% | Nov 21, 2019 | A clear text storage of sensitive information vulnerability in FortiClient for Mac may allow a local attacker to read se... |
| CVE-2019-10535 | MEDIUM | 5.5 | 0.2% | Nov 21, 2019 | Improper validation for loop variable received from firmware can lead to out of bound access in WLAN function while iter... |
| CVE-2019-10490 | MEDIUM | 5.5 | 0.2% | Nov 21, 2019 | Use after free issue in Xtra daemon shutdown due to static object instance getting freed from a multiple places in Snapd... |
| CVE-2019-19037 | MEDIUM | 5.5 | 1.9% | Nov 21, 2019 | ext4_empty_dir in fs/ext4/namei.c in the Linux kernel through 5.3.12 allows a NULL pointer dereference because ext4_read... |
| CVE-2019-19039 | MEDIUM | 5.5 | 0.7% | Nov 21, 2019 | __btrfs_free_extent in fs/btrfs/extent-tree.c in the Linux kernel through 5.3.12 calls btrfs_print_leaf in a certain ENO... |
| CVE-2019-19036 | MEDIUM | 5.5 | 1.8% | Nov 21, 2019 | btrfs_root_node in fs/btrfs/ctree.c in the Linux kernel through 5.3.12 allows a NULL pointer dereference because rcu_der... |
| CVE-2019-6853 | MEDIUM | 6.1 | 0.6% | Nov 20, 2019 | A CWE-79: Failure to Preserve Web Page Structure vulnerability exists in Andover Continuum (models 9680, 5740 and 5720, ... |
| CVE-2019-4530 | MEDIUM | 6.5 | 0.7% | Nov 20, 2019 | IBM Maximo Asset Management 7.6, 7.6.1, and 7.6.1.1 could allow an authenticated user to delete a record that they shoul... |
| CVE-2019-15073 | MEDIUM | 6.1 | 1.1% | Nov 20, 2019 | An Open Redirect vulnerability for all browsers in MAIL2000 through version 6.0 and 7.0, which will redirect to a malici... |
| CVE-2019-15072 | MEDIUM | 6.1 | 1.5% | Nov 20, 2019 | The login feature in "/cgi-bin/portal" in MAIL2000 through version 6.0 and 7.0 has a cross-site scripting (XSS) vulnerab... |
| CVE-2019-15071 | MEDIUM | 6.1 | 1.6% | Nov 20, 2019 | The "/cgi-bin/go" page in MAIL2000 through version 6.0 and 7.0 has a cross-site scripting (XSS) vulnerability, allowing ... |
| CVE-2019-6187 | MEDIUM | 6.5 | 0.9% | Nov 20, 2019 | A stored CSV Injection vulnerability was reported in Lenovo XClarity Controller (XCC) that could allow an administrative... |
| CVE-2019-10083 | MEDIUM | 5.3 | 2.8% | Nov 19, 2019 | When updating a Process Group via the API in NiFi versions 1.3.0 to 1.9.2, the response to the request includes all of i... |
| CVE-2019-10080 | MEDIUM | 6.5 | 2.3% | Nov 19, 2019 | The XMLFileLookupService in NiFi versions 1.3.0 to 1.9.2 allowed trusted users to inadvertently configure a potentially ... |
| CVE-2019-18373 | MEDIUM | 5.6 | 0.3% | Nov 18, 2019 | Norton App Lock, prior to 1.4.0.503, may be susceptible to a bypass exploit. In this type of circumstance, the exploit c... |
| CVE-2019-17085 | MEDIUM | 6.5 | 0.8% | Nov 18, 2019 | XXE attack vulnerability on Micro Focus Operations Agent, affected version 12.0, 12.01, 12.02, 12.03, 12.04, 12.05, 12.0... |
| CVE-2019-15054 | MEDIUM | 6.1 | 2.7% | Nov 18, 2019 | Multiple cross-site scripting (XSS) vulnerabilities in Mailbird before 2.7.5.0 r allow remote attackers to execute arbit... |
| CVE-2019-10070 | MEDIUM | 6.1 | 1.8% | Nov 18, 2019 | Apache Atlas versions 0.8.3 and 1.1.0 were found vulnerable to Stored Cross-Site Scripting in the search functionality |
| CVE-2019-10763 | MEDIUM | 6.5 | 0.9% | Nov 18, 2019 | pimcore/pimcore before 6.3.0 is vulnerable to SQL Injection. An attacker with limited privileges (classes permission) ca... |
| CVE-2019-3423 | MEDIUM | 5.3 | 1.3% | Nov 18, 2019 | permission and access control vulnerability, which exists in V2.1.14 and below versions of C520V21 smart camera devices.... |
| CVE-2019-12311 | MEDIUM | 6.1 | 1.1% | Nov 18, 2019 | Sandline Centraleyezer (On Premises) allows Unrestricted File Upload leading to Stored XSS. An HTML page running a scrip... |
| CVE-2019-12299 | MEDIUM | 6.1 | 0.9% | Nov 18, 2019 | Sandline Centraleyezer (On Premises) allows Stored XSS using HTML entities in the name field of the Category section. |
| CVE-2019-5688 | MEDIUM | 6.7 | 0.4% | Nov 18, 2019 | NVIDIA NVFlash, NVUFlash Tool prior to v5.588.0 and GPUModeSwitch Tool prior to 2019-11, NVIDIA kernel mode driver (nvfl... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now