2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-16863 | MEDIUM | 5.9 | 3.3% | Nov 14, 2019 | STMicroelectronics ST33TPHF2ESPI TPM devices before 2019-09-12 allow attackers to extract the ECDSA private key via a si... |
| CVE-2019-3662 | MEDIUM | 6.5 | 1.2% | Nov 14, 2019 | Path Traversal: '/absolute/pathname/here' vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows remo... |
| CVE-2019-3640 | MEDIUM | 6.5 | 0.5% | Nov 14, 2019 | Unprotected Transport of Credentials in ePO extension in McAfee Data Loss Prevention 11.x prior to 11.4.0 allows remote ... |
| CVE-2019-18954 | MEDIUM | 5.3 | 1.2% | Nov 14, 2019 | Pomelo v2.2.5 allows external control of critical state data. A malicious user input can corrupt arbitrary methods and a... |
| CVE-2019-3650 | MEDIUM | 6.5 | 0.9% | Nov 13, 2019 | Information Disclosure vulnerability in McAfee Advanced Threat Defense (ATD prior to 4.8 allows remote authenticated att... |
| CVE-2019-3649 | MEDIUM | 6.5 | 0.9% | Nov 13, 2019 | Information Disclosure vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows remote authenticated at... |
| CVE-2019-3420 | MEDIUM | 6.5 | 0.7% | Nov 13, 2019 | All versions up to V2.5.0_EG1T5_TED of ZTE ZXHN H108N product are impacted by an information leak vulnerability. An atta... |
| CVE-2019-13555 | MEDIUM | 5.9 | 1.5% | Nov 13, 2019 | In Mitsubishi Electric MELSEC-Q Series Q03/04/06/13/26UDVCPU: serial number 21081 and prior, Q04/06/13/26UDPVCPU: serial... |
| CVE-2019-0388 | MEDIUM | 5.3 | 0.7% | Nov 13, 2019 | SAP UI5 HTTP Handler (corrected in SAP_UI versions 7.5, 7.51, 7.52, 7.53, 7.54 and SAP UI_700 version 2.0) allows an att... |
| CVE-2019-0386 | MEDIUM | 6.3 | 0.7% | Nov 13, 2019 | Order processing in SAP ERP Sales (corrected in SAP_APPL 6.0, 6.02, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18) and S4HANA... |
| CVE-2019-18923 | MEDIUM | 6.1 | 0.9% | Nov 13, 2019 | Insufficient content type validation of proxied resources in go-camo before 2.1.1 allows a remote attacker to serve arbi... |
| CVE-2019-0393 | MEDIUM | 4.3 | 0.7% | Nov 13, 2019 | An SQL Injection vulnerability in SAP Quality Management (corrected in S4CORE versions 1.0, 1.01, 1.02, 1.03) allows an ... |
| CVE-2019-0391 | MEDIUM | 4.3 | 0.9% | Nov 13, 2019 | Under certain conditions SAP NetWeaver AS Java (corrected in 7.10, 7.20, 7.30, 7.31, 7.40, 7.50) allows an attacker to a... |
| CVE-2019-0390 | MEDIUM | 4.3 | 0.7% | Nov 13, 2019 | Under certain conditions SAP Data Hub (corrected in DH_Foundation version 2) allows an attacker to access information wh... |
| CVE-2019-0385 | MEDIUM | 6.5 | 0.5% | Nov 13, 2019 | SAP Enable Now, before version 1908, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Script... |
| CVE-2019-0382 | MEDIUM | 5.4 | 0.5% | Nov 13, 2019 | A Cross-Site Scripting vulnerability exists in SAP BusinessObjects Business Intelligence Platform (Web Intelligence-Publ... |
| CVE-2019-17550 | MEDIUM | 6.1 | 1.3% | Nov 13, 2019 | The Blog2Social plugin before 5.9.0 for WordPress is affected by: Cross Site Scripting (XSS). The impact is: Allows an a... |
| CVE-2019-17515 | MEDIUM | 6.1 | 1.3% | Nov 13, 2019 | The CleanTalk cleantalk-spam-protect plugin before 5.127.4 for WordPress is affected by: Cross Site Scripting (XSS). The... |
| CVE-2019-9467 | MEDIUM | 6.7 | 0.3% | Nov 13, 2019 | In the Bootloader, there is a possible kernel command injection due to missing command sanitization. This could lead to ... |
| CVE-2019-18883 | MEDIUM | 6.1 | 0.9% | Nov 13, 2019 | XSS exists in Lavalite CMS 5.7 via the admin/profile name or designation field. |
| CVE-2019-18793 | MEDIUM | 6.1 | 0.8% | Nov 13, 2019 | Parallels Plesk Panel 9.5 allows XSS in target/locales/tr-TR/help/index.htm? via the "fileName" parameter. |
| CVE-2019-16951 | MEDIUM | 5.3 | 1.0% | Nov 13, 2019 | A remote file include (RFI) issue was discovered in Enghouse Web Chat 6.2.284.34. One can replace the localhost attribut... |
| CVE-2019-16950 | MEDIUM | 6.1 | 0.7% | Nov 13, 2019 | An XSS issue was discovered in Enghouse Web Chat 6.1.300.31 and 6.2.284.34. The QueueName parameter of a GET request all... |
| CVE-2019-2233 | MEDIUM | 6.8 | 0.2% | Nov 13, 2019 | In getUserCount and getCount of UserSwitcherController.java, there is possible new user creation due to a logic error. T... |
| CVE-2019-2212 | MEDIUM | 5.5 | 0.2% | Nov 13, 2019 | In poisson_distribution of random, there is an out of bounds read. This could lead to local information disclosure with ... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now