2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-17235MEDIUM5.3includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows information disclosure.
CVE-2019-18882MEDIUM6.1WSO2 IS as Key Manager 5.7.0 allows stored XSS in download-userinfo.jag because Content-Type is mishandled.
CVE-2019-18881MEDIUM6.1WSO2 IS as Key Manager 5.7.0 allows unauthenticated reflected XSS in the dashboard user profile.
CVE-2019-18853MEDIUM6.5ImageMagick before 7.0.9-0 allows remote attackers to cause a denial of service because XML_PARSE_HUGE is not properly r...
CVE-2019-18849MEDIUM5.5In tnef before 1.4.18, an attacker may be able to write to the victim's .ssh/authorized_keys file via an e-mail message ...
CVE-2019-5698MEDIUM4.4NVIDIA Virtual GPU Manager, all versions, contains a vulnerability in the vGPU plugin, in which an input index value is ...
CVE-2019-5696MEDIUM5.5NVIDIA Virtual GPU Manager, all versions, contains a vulnerability in which the provision of an incorrectly sized buffer...
CVE-2019-5694MEDIUM6.5NVIDIA Windows GPU Display Driver, R390 driver version, contains a vulnerability in NVIDIA Control Panel in which it inc...
CVE-2019-5693MEDIUM5.5NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) in whi...
CVE-2019-4645MEDIUM6.1IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbit...
CVE-2019-4581MEDIUM6.1IBM QRadar 7.3.0 to 7.3.2 Patch 4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitr...
CVE-2019-4556MEDIUM6.5IBM QRadar Advisor 1.0.0 through 2.4.0 uses incomplete blacklisting for input validation which allows attackers to bypas...
CVE-2019-4509MEDIUM4.3IBM QRadar 7.3.0 to 7.3.2 Patch 4 is vulnerable to incorrect authorization in some components which could allow an authe...
CVE-2019-4470MEDIUM5.4IBM QRadar 7.3.0 to 7.3.2 Patch 4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitr...
CVE-2019-4454MEDIUM5.4IBM QRadar 7.3.0 to 7.3.2 Patch 4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitr...
CVE-2019-4450MEDIUM6.1IBM i 7.2, 7.3, and 7.4 for i is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary ...
CVE-2019-4412MEDIUM5.3IBM Cognos Controller stores sensitive information in URL parameters. This may lead to information disclosure if unautho...
CVE-2019-4411MEDIUM4.3IBM Cognos Controller 10.3.0, 10.3.1, 10.4.0, and 10.4.1 could allow an authenticated user to obtain sensitive informati...
CVE-2019-4334MEDIUM4.3IBM Cognos Analytics 11.0 and 11.1 could reveal sensitive information to an authenticated user that could be used in fut...
CVE-2019-13535MEDIUM4.6In Medtronic Valleylab FT10 Energy Platform (VLFT10GEN) version 2.1.0 and lower and version 2.0.3 and lower, and Valleyl...
CVE-2019-13531MEDIUM4.6In Medtronic Valleylab FT10 Energy Platform (VLFT10GEN) version 2.1.0 and lower and version 2.0.3 and lower, and Valleyl...
CVE-2019-16210MEDIUM5.5Brocade SANnav versions before v2.0, logs plain text database connection password while triggering support save.
CVE-2019-16206MEDIUM5.5The authentication mechanism, in Brocade SANnav versions before v2.0, logs plaintext account credentials at the ‘trace’ ...
CVE-2019-13557MEDIUM5.3In Tasy EMR, Tasy WebPortal Versions 3.02.1757 and prior, there is an information exposure vulnerability which may allow...
CVE-2019-3866MEDIUM5.5An information-exposure vulnerability was discovered where openstack-mistral's undercloud log files containing clear-tex...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now