2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-17324MEDIUM6.5ClipSoft REXPERT 1.0.0.527 and earlier version allows directory traversal by issuing a special HTTP POST request with .....
CVE-2019-17322MEDIUM6.5ClipSoft REXPERT 1.0.0.527 and earlier version allows arbitrary file creation via a POST request with the parameter set ...
CVE-2019-17321MEDIUM5.3ClipSoft REXPERT 1.0.0.527 and earlier version have an information disclosure issue. When requesting web page associated...
CVE-2019-18207MEDIUM5.4In Zucchetti InfoBusiness before and including 4.4.1, an authenticated user can inject client-side code due to improper ...
CVE-2019-18205MEDIUM6.1Multiple Reflected Cross-site Scripting (XSS) vulnerabilities exist in Zucchetti InfoBusiness before and including 4.4.1...
CVE-2019-7619MEDIUM5.3Elasticsearch versions 7.0.0-7.3.2 and 6.7.0-6.8.3 contain a username disclosure flaw was found in the API Key service. ...
CVE-2019-8235MEDIUM6.5An insecure direct object reference (IDOR) vulnerability exists in Magento 2.3 prior to 2.3.1, 2.2 prior to 2.2.8, and 2...
CVE-2019-9758MEDIUM5.4An issue was discovered in LabKey Server 19.1.0. The display name of a user is vulnerable to stored XSS that can execute...
CVE-2019-6847MEDIUM4.9A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon BMxCR...
CVE-2019-6846MEDIUM6.5A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists in Modicon M580, Modicon M340, Modicon B...
CVE-2019-6844MEDIUM4.9A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon BMxCR...
CVE-2019-6843MEDIUM4.9A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580 with firmware (version prior...
CVE-2019-6842MEDIUM4.9A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon BMxCR...
CVE-2019-6841MEDIUM4.9A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580 with firmware (version prior...
CVE-2019-5533MEDIUM4.3In VMware SD-WAN by VeloCloud versions 3.x prior to 3.3.0, the VeloCloud Orchestrator parameter authorization check mist...
CVE-2019-18612MEDIUM5.3An issue was discovered in the AbuseFilter extension through 1.34 for MediaWiki. Previously hidden (restricted) AbuseFil...
CVE-2019-18611MEDIUM6.5An issue was discovered in the CheckUser extension through 1.34 for MediaWiki. Certain sensitive information within over...
CVE-2019-18603MEDIUM5.9OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to information leakage upon certain error conditions because unini...
CVE-2019-13066MEDIUM6.1Sahi Pro 8.0.0 has a script manager arena located at _s_/dyn/pro/DBReports with many different areas that are vulnerable...
CVE-2019-10743MEDIUM5.5All versions of archiver allow attacker to perform a Zip Slip attack via the "unarchive" functions. It is exploited usin...
CVE-2019-4600MEDIUM5.3IBM API Connect version V5.0.0.0 through 5.0.8.7 could reveal sensitive information to an attacker using a specially cra...
CVE-2019-4330MEDIUM4.3IBM Security Guardium Big Data Intelligence (SonarG) 4.0 does not set the secure attribute for cookies in HTTPS sessions...
CVE-2019-4329MEDIUM4.3IBM Security Guardium Big Data Intelligence (SonarG) 4.0 uses incomplete blacklisting for input validation which allows ...
CVE-2019-4311MEDIUM5.3IBM Security Guardium Big Data Intelligence (SonarG) 4.0 discloses sensitive information to unauthorized users. The info...
CVE-2019-4309MEDIUM5.5IBM Security Guardium Big Data Intelligence (SonarG) 4.0 uses hard coded credentials which could allow a local user to o...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now