2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-17235 | MEDIUM | 5.3 | 1.4% | Nov 12, 2019 | includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows information disclosure. |
| CVE-2019-18882 | MEDIUM | 6.1 | 0.6% | Nov 12, 2019 | WSO2 IS as Key Manager 5.7.0 allows stored XSS in download-userinfo.jag because Content-Type is mishandled. |
| CVE-2019-18881 | MEDIUM | 6.1 | 0.7% | Nov 12, 2019 | WSO2 IS as Key Manager 5.7.0 allows unauthenticated reflected XSS in the dashboard user profile. |
| CVE-2019-18853 | MEDIUM | 6.5 | 1.5% | Nov 11, 2019 | ImageMagick before 7.0.9-0 allows remote attackers to cause a denial of service because XML_PARSE_HUGE is not properly r... |
| CVE-2019-18849 | MEDIUM | 5.5 | 1.2% | Nov 11, 2019 | In tnef before 1.4.18, an attacker may be able to write to the victim's .ssh/authorized_keys file via an e-mail message ... |
| CVE-2019-5698 | MEDIUM | 4.4 | 0.3% | Nov 9, 2019 | NVIDIA Virtual GPU Manager, all versions, contains a vulnerability in the vGPU plugin, in which an input index value is ... |
| CVE-2019-5696 | MEDIUM | 5.5 | 0.3% | Nov 9, 2019 | NVIDIA Virtual GPU Manager, all versions, contains a vulnerability in which the provision of an incorrectly sized buffer... |
| CVE-2019-5694 | MEDIUM | 6.5 | 0.6% | Nov 9, 2019 | NVIDIA Windows GPU Display Driver, R390 driver version, contains a vulnerability in NVIDIA Control Panel in which it inc... |
| CVE-2019-5693 | MEDIUM | 5.5 | 0.3% | Nov 9, 2019 | NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) in whi... |
| CVE-2019-4645 | MEDIUM | 6.1 | 0.7% | Nov 9, 2019 | IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbit... |
| CVE-2019-4581 | MEDIUM | 6.1 | 0.9% | Nov 9, 2019 | IBM QRadar 7.3.0 to 7.3.2 Patch 4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitr... |
| CVE-2019-4556 | MEDIUM | 6.5 | 0.8% | Nov 9, 2019 | IBM QRadar Advisor 1.0.0 through 2.4.0 uses incomplete blacklisting for input validation which allows attackers to bypas... |
| CVE-2019-4509 | MEDIUM | 4.3 | 0.7% | Nov 9, 2019 | IBM QRadar 7.3.0 to 7.3.2 Patch 4 is vulnerable to incorrect authorization in some components which could allow an authe... |
| CVE-2019-4470 | MEDIUM | 5.4 | 0.6% | Nov 9, 2019 | IBM QRadar 7.3.0 to 7.3.2 Patch 4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitr... |
| CVE-2019-4454 | MEDIUM | 5.4 | 0.6% | Nov 9, 2019 | IBM QRadar 7.3.0 to 7.3.2 Patch 4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitr... |
| CVE-2019-4450 | MEDIUM | 6.1 | 0.7% | Nov 9, 2019 | IBM i 7.2, 7.3, and 7.4 for i is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary ... |
| CVE-2019-4412 | MEDIUM | 5.3 | 1.0% | Nov 9, 2019 | IBM Cognos Controller stores sensitive information in URL parameters. This may lead to information disclosure if unautho... |
| CVE-2019-4411 | MEDIUM | 4.3 | 0.8% | Nov 9, 2019 | IBM Cognos Controller 10.3.0, 10.3.1, 10.4.0, and 10.4.1 could allow an authenticated user to obtain sensitive informati... |
| CVE-2019-4334 | MEDIUM | 4.3 | 0.9% | Nov 9, 2019 | IBM Cognos Analytics 11.0 and 11.1 could reveal sensitive information to an authenticated user that could be used in fut... |
| CVE-2019-13535 | MEDIUM | 4.6 | 0.4% | Nov 8, 2019 | In Medtronic Valleylab FT10 Energy Platform (VLFT10GEN) version 2.1.0 and lower and version 2.0.3 and lower, and Valleyl... |
| CVE-2019-13531 | MEDIUM | 4.6 | 0.4% | Nov 8, 2019 | In Medtronic Valleylab FT10 Energy Platform (VLFT10GEN) version 2.1.0 and lower and version 2.0.3 and lower, and Valleyl... |
| CVE-2019-16210 | MEDIUM | 5.5 | 0.2% | Nov 8, 2019 | Brocade SANnav versions before v2.0, logs plain text database connection password while triggering support save. |
| CVE-2019-16206 | MEDIUM | 5.5 | 0.2% | Nov 8, 2019 | The authentication mechanism, in Brocade SANnav versions before v2.0, logs plaintext account credentials at the ‘trace’ ... |
| CVE-2019-13557 | MEDIUM | 5.3 | 1.2% | Nov 8, 2019 | In Tasy EMR, Tasy WebPortal Versions 3.02.1757 and prior, there is an information exposure vulnerability which may allow... |
| CVE-2019-3866 | MEDIUM | 5.5 | 0.3% | Nov 8, 2019 | An information-exposure vulnerability was discovered where openstack-mistral's undercloud log files containing clear-tex... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now