2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-16907 | MEDIUM | 5.3 | 1.6% | Oct 31, 2019 | An issue was discovered in the Infosysta "In-App & Desktop Notifications" app 1.6.13_J8 for Jira. It is possible to obta... |
| CVE-2019-5023 | MEDIUM | 5.9 | 0.7% | Oct 31, 2019 | An exploitable vulnerability exists in the grsecurity PaX patch for the function read_kmem, in PaX from version pax-linu... |
| CVE-2019-16295 | MEDIUM | 4.6 | 0.5% | Oct 31, 2019 | Stored XSS in filemanager2.php in CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.885 exists via the cmd_arg parame... |
| CVE-2019-5095 | MEDIUM | 4.3 | 1.1% | Oct 31, 2019 | An issue summary information disclosure vulnerability exists in Atlassian Jira Tempo plugin, version 4.10.0. Authenticat... |
| CVE-2019-18657 | MEDIUM | 5.3 | 1.5% | Oct 31, 2019 | ClickHouse before 19.13.5.44 allows HTTP header injection via the url table function. |
| CVE-2019-14356 | MEDIUM | 5.3 | 1.2% | Oct 31, 2019 | On Coldcard MK1 and MK2 devices, a side channel for the row-based OLED display was found. The power consumption of each ... |
| CVE-2019-18656 | MEDIUM | 6.1 | 0.7% | Oct 31, 2019 | Pimcore 6.2.3 has XSS in the translations grid because bundles/AdminBundle/Resources/public/js/pimcore/settings/translat... |
| CVE-2019-16251 | MEDIUM | 4.3 | 0.9% | Oct 31, 2019 | plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated optio... |
| CVE-2019-3419 | MEDIUM | 5.7 | 0.5% | Oct 31, 2019 | A security vulnerability exists in a management port in the version of ZTE's ZXMP M721V3.10P01B10_M2NCP. An attacker cou... |
| CVE-2019-18369 | MEDIUM | 5.3 | 1.1% | Oct 31, 2019 | In JetBrains YouTrack before 2019.2.55152, removing tags from the issues list without the corresponding permission was p... |
| CVE-2019-18367 | MEDIUM | 5.3 | 0.7% | Oct 31, 2019 | In JetBrains TeamCity before 2019.1.2, a non-destructive operation could be performed by a user without the correspondin... |
| CVE-2019-18366 | MEDIUM | 5.3 | 1.1% | Oct 31, 2019 | In JetBrains TeamCity before 2019.1.2, secure values could be exposed to users with the "View build runtime parameters a... |
| CVE-2019-18365 | MEDIUM | 4.3 | 0.8% | Oct 31, 2019 | In JetBrains TeamCity before 2019.1.4, reverse tabnabbing was possible on several pages. |
| CVE-2019-18363 | MEDIUM | 5.3 | 0.9% | Oct 31, 2019 | In JetBrains TeamCity before 2019.1.2, access could be gained to the history of builds of a deleted build configuration ... |
| CVE-2019-18362 | MEDIUM | 5.3 | 0.9% | Oct 31, 2019 | JetBrains MPS before 2019.2.2 exposed listening ports to the network. |
| CVE-2019-18361 | MEDIUM | 5.3 | 0.4% | Oct 31, 2019 | JetBrains IntelliJ IDEA before 2019.2 allows local user privilege escalation, potentially leading to arbitrary code exec... |
| CVE-2019-18360 | MEDIUM | 5.3 | 0.9% | Oct 31, 2019 | In JetBrains Hub versions earlier than 2019.1.11738, username enumeration was possible through password recovery. |
| CVE-2019-18424 | MEDIUM | 6.8 | 0.5% | Oct 31, 2019 | An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where... |
| CVE-2019-18420 | MEDIUM | 6.5 | 2.5% | Oct 31, 2019 | An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to cause a denial of service via a VCPUOP_i... |
| CVE-2019-17551 | MEDIUM | 6.1 | 0.7% | Oct 31, 2019 | In Apak Wholesale Floorplanning Finance 6.31.8.3 and 6.31.8.5, an attacker can send an authenticated POST request with a... |
| CVE-2019-18645 | MEDIUM | 5.5 | 0.4% | Oct 31, 2019 | The quarantine restoration function in Total Defense Anti-virus 11.5.2.28 is vulnerable to symbolic link attacks, allowi... |
| CVE-2019-18644 | MEDIUM | 5.9 | 0.6% | Oct 31, 2019 | The malware scan function in Total Defense Anti-virus 11.5.2.28 is vulnerable to a TOCTOU bug; consequently, symbolic li... |
| CVE-2019-12417 | MEDIUM | 4.8 | 1.3% | Oct 30, 2019 | A malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript ... |
| CVE-2019-17326 | MEDIUM | 6.5 | 1.3% | Oct 30, 2019 | ClipSoft REXPERT 1.0.0.527 and earlier version allows remote attacker to arbitrary file deletion by issuing a HTTP GET r... |
| CVE-2019-17325 | MEDIUM | 6.5 | 1.2% | Oct 30, 2019 | ClipSoft REXPERT 1.0.0.527 and earlier version allows remote attacker to upload arbitrary local file via the ActiveX met... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now