2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-16863MEDIUM5.9STMicroelectronics ST33TPHF2ESPI TPM devices before 2019-09-12 allow attackers to extract the ECDSA private key via a si...
CVE-2019-3662MEDIUM6.5Path Traversal: '/absolute/pathname/here' vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows remo...
CVE-2019-3640MEDIUM6.5Unprotected Transport of Credentials in ePO extension in McAfee Data Loss Prevention 11.x prior to 11.4.0 allows remote ...
CVE-2019-18954MEDIUM5.3Pomelo v2.2.5 allows external control of critical state data. A malicious user input can corrupt arbitrary methods and a...
CVE-2019-3650MEDIUM6.5Information Disclosure vulnerability in McAfee Advanced Threat Defense (ATD prior to 4.8 allows remote authenticated att...
CVE-2019-3649MEDIUM6.5Information Disclosure vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows remote authenticated at...
CVE-2019-3420MEDIUM6.5All versions up to V2.5.0_EG1T5_TED of ZTE ZXHN H108N product are impacted by an information leak vulnerability. An atta...
CVE-2019-13555MEDIUM5.9In Mitsubishi Electric MELSEC-Q Series Q03/04/06/13/26UDVCPU: serial number 21081 and prior, Q04/06/13/26UDPVCPU: serial...
CVE-2019-0388MEDIUM5.3SAP UI5 HTTP Handler (corrected in SAP_UI versions 7.5, 7.51, 7.52, 7.53, 7.54 and SAP UI_700 version 2.0) allows an att...
CVE-2019-0386MEDIUM6.3Order processing in SAP ERP Sales (corrected in SAP_APPL 6.0, 6.02, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18) and S4HANA...
CVE-2019-18923MEDIUM6.1Insufficient content type validation of proxied resources in go-camo before 2.1.1 allows a remote attacker to serve arbi...
CVE-2019-0393MEDIUM4.3An SQL Injection vulnerability in SAP Quality Management (corrected in S4CORE versions 1.0, 1.01, 1.02, 1.03) allows an ...
CVE-2019-0391MEDIUM4.3Under certain conditions SAP NetWeaver AS Java (corrected in 7.10, 7.20, 7.30, 7.31, 7.40, 7.50) allows an attacker to a...
CVE-2019-0390MEDIUM4.3Under certain conditions SAP Data Hub (corrected in DH_Foundation version 2) allows an attacker to access information wh...
CVE-2019-0385MEDIUM6.5SAP Enable Now, before version 1908, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Script...
CVE-2019-0382MEDIUM5.4A Cross-Site Scripting vulnerability exists in SAP BusinessObjects Business Intelligence Platform (Web Intelligence-Publ...
CVE-2019-17550MEDIUM6.1The Blog2Social plugin before 5.9.0 for WordPress is affected by: Cross Site Scripting (XSS). The impact is: Allows an a...
CVE-2019-17515MEDIUM6.1The CleanTalk cleantalk-spam-protect plugin before 5.127.4 for WordPress is affected by: Cross Site Scripting (XSS). The...
CVE-2019-9467MEDIUM6.7In the Bootloader, there is a possible kernel command injection due to missing command sanitization. This could lead to ...
CVE-2019-18883MEDIUM6.1XSS exists in Lavalite CMS 5.7 via the admin/profile name or designation field.
CVE-2019-18793MEDIUM6.1Parallels Plesk Panel 9.5 allows XSS in target/locales/tr-TR/help/index.htm? via the "fileName" parameter.
CVE-2019-16951MEDIUM5.3A remote file include (RFI) issue was discovered in Enghouse Web Chat 6.2.284.34. One can replace the localhost attribut...
CVE-2019-16950MEDIUM6.1An XSS issue was discovered in Enghouse Web Chat 6.1.300.31 and 6.2.284.34. The QueueName parameter of a GET request all...
CVE-2019-2233MEDIUM6.8In getUserCount and getCount of UserSwitcherController.java, there is possible new user creation due to a logic error. T...
CVE-2019-2212MEDIUM5.5In poisson_distribution of random, there is an out of bounds read. This could lead to local information disclosure with ...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now