2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-17324 | MEDIUM | 6.5 | 1.2% | Oct 30, 2019 | ClipSoft REXPERT 1.0.0.527 and earlier version allows directory traversal by issuing a special HTTP POST request with ..... |
| CVE-2019-17322 | MEDIUM | 6.5 | 1.2% | Oct 30, 2019 | ClipSoft REXPERT 1.0.0.527 and earlier version allows arbitrary file creation via a POST request with the parameter set ... |
| CVE-2019-17321 | MEDIUM | 5.3 | 0.9% | Oct 30, 2019 | ClipSoft REXPERT 1.0.0.527 and earlier version have an information disclosure issue. When requesting web page associated... |
| CVE-2019-18207 | MEDIUM | 5.4 | 0.5% | Oct 30, 2019 | In Zucchetti InfoBusiness before and including 4.4.1, an authenticated user can inject client-side code due to improper ... |
| CVE-2019-18205 | MEDIUM | 6.1 | 0.7% | Oct 30, 2019 | Multiple Reflected Cross-site Scripting (XSS) vulnerabilities exist in Zucchetti InfoBusiness before and including 4.4.1... |
| CVE-2019-7619 | MEDIUM | 5.3 | 2.4% | Oct 30, 2019 | Elasticsearch versions 7.0.0-7.3.2 and 6.7.0-6.8.3 contain a username disclosure flaw was found in the API Key service. ... |
| CVE-2019-8235 | MEDIUM | 6.5 | 1.9% | Oct 30, 2019 | An insecure direct object reference (IDOR) vulnerability exists in Magento 2.3 prior to 2.3.1, 2.2 prior to 2.2.8, and 2... |
| CVE-2019-9758 | MEDIUM | 5.4 | 1.0% | Oct 29, 2019 | An issue was discovered in LabKey Server 19.1.0. The display name of a user is vulnerable to stored XSS that can execute... |
| CVE-2019-6847 | MEDIUM | 4.9 | 1.0% | Oct 29, 2019 | A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon BMxCR... |
| CVE-2019-6846 | MEDIUM | 6.5 | 1.0% | Oct 29, 2019 | A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists in Modicon M580, Modicon M340, Modicon B... |
| CVE-2019-6844 | MEDIUM | 4.9 | 1.0% | Oct 29, 2019 | A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon BMxCR... |
| CVE-2019-6843 | MEDIUM | 4.9 | 1.0% | Oct 29, 2019 | A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580 with firmware (version prior... |
| CVE-2019-6842 | MEDIUM | 4.9 | 1.0% | Oct 29, 2019 | A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon BMxCR... |
| CVE-2019-6841 | MEDIUM | 4.9 | 24.4% | Oct 29, 2019 | A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580 with firmware (version prior... |
| CVE-2019-5533 | MEDIUM | 4.3 | 17.9% | Oct 29, 2019 | In VMware SD-WAN by VeloCloud versions 3.x prior to 3.3.0, the VeloCloud Orchestrator parameter authorization check mist... |
| CVE-2019-18612 | MEDIUM | 5.3 | 0.9% | Oct 29, 2019 | An issue was discovered in the AbuseFilter extension through 1.34 for MediaWiki. Previously hidden (restricted) AbuseFil... |
| CVE-2019-18611 | MEDIUM | 6.5 | 0.9% | Oct 29, 2019 | An issue was discovered in the CheckUser extension through 1.34 for MediaWiki. Certain sensitive information within over... |
| CVE-2019-18603 | MEDIUM | 5.9 | 1.2% | Oct 29, 2019 | OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to information leakage upon certain error conditions because unini... |
| CVE-2019-13066 | MEDIUM | 6.1 | 1.0% | Oct 29, 2019 | Sahi Pro 8.0.0 has a script manager arena located at _s_/dyn/pro/DBReports with many different areas that are vulnerable... |
| CVE-2019-10743 | MEDIUM | 5.5 | 6.5% | Oct 29, 2019 | All versions of archiver allow attacker to perform a Zip Slip attack via the "unarchive" functions. It is exploited usin... |
| CVE-2019-4600 | MEDIUM | 5.3 | 1.4% | Oct 29, 2019 | IBM API Connect version V5.0.0.0 through 5.0.8.7 could reveal sensitive information to an attacker using a specially cra... |
| CVE-2019-4330 | MEDIUM | 4.3 | 1.1% | Oct 29, 2019 | IBM Security Guardium Big Data Intelligence (SonarG) 4.0 does not set the secure attribute for cookies in HTTPS sessions... |
| CVE-2019-4329 | MEDIUM | 4.3 | 0.9% | Oct 29, 2019 | IBM Security Guardium Big Data Intelligence (SonarG) 4.0 uses incomplete blacklisting for input validation which allows ... |
| CVE-2019-4311 | MEDIUM | 5.3 | 1.2% | Oct 29, 2019 | IBM Security Guardium Big Data Intelligence (SonarG) 4.0 discloses sensitive information to unauthorized users. The info... |
| CVE-2019-4309 | MEDIUM | 5.5 | 0.3% | Oct 29, 2019 | IBM Security Guardium Big Data Intelligence (SonarG) 4.0 uses hard coded credentials which could allow a local user to o... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now