2019 CVE Vulnerabilities

17,624 CVEs published in 2019.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2019-25776HIGH7.5Weaver E-cology contains an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrar...
CVE-2019-25766HIGH7.5Renovate versions >= 13.87.0 and <= 19.38.6 leak temporary repository tokens into pull request comments during certain G...
CVE-2019-25765HIGH7.5ASP-CMS contains a SQL injection vulnerability in the commentList.asp endpoint that allows unauthenticated remote attack...
CVE-2019-25764HIGH7.3**UNSUPPORTED WHEN ASSIGNED**  Exposed IOCTL with Insufficient Access Control in the ASUS AURA SYNC driver allows a loca...
CVE-2019-25762HIGH7.5Joomla! Component JoomProject 1.1.3.2 contains an information disclosure vulnerability that allows unauthenticated attac...
CVE-2019-25761HIGH7.1Joomla! Component JoomCRM 1.1.1 contains an SQL injection vulnerability that allows authenticated attackers to execute a...
CVE-2019-25759HIGH7.1Joomla! Component vBizz 1.0.7 contains an SQL injection vulnerability that allows authenticated attackers to execute arb...
CVE-2019-25758HIGH8.8Joomla! Component vBizz 1.0.7 contains an unrestricted file upload vulnerability that allows authenticated attackers to ...
CVE-2019-25757HIGH7.1Joomla vWishlist 1.0.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary ...
CVE-2019-25756HIGH8.2Joomla! Component vAccount 2.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execut...
CVE-2019-25755HIGH8.2Joomla Component vReview 1.9.11 contains an SQL injection vulnerability that allows unauthenticated attackers to execute...
CVE-2019-25754HIGH8.2Joomla Component vRestaurant 1.9.4 contains an SQL injection vulnerability that allows unauthenticated attackers to exec...
CVE-2019-25753HIGH8.2Joomla! Component VMap 1.9.6 contains an SQL injection vulnerability that allows unauthenticated attackers to execute ar...
CVE-2019-25752HIGH8.2Joomla! Component J-BusinessDirectory 4.9.7 contains an SQL injection vulnerability that allows unauthenticated attacker...
CVE-2019-25751HIGH8.2Joomla Component J-ClassifiedsManager 3.0.5 contains an SQL injection vulnerability that allows unauthenticated attacker...
CVE-2019-25750HIGH8.2Joomla Component J-MultipleHotelReservation 6.0.7 contains an SQL injection vulnerability that allows unauthenticated at...
CVE-2019-25749HIGH7.1Joomla J-CruisePortal 6.0.4 contains an SQL injection vulnerability that allows authenticated attackers to execute arbit...
CVE-2019-25748HIGH8.2Joomla JHotelReservation 6.0.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute ...
CVE-2019-25747HIGH8.5Network Inventory Advisor 5.0.26.0 installs the niaservice service with an unquoted binary path that allows local attack...
CVE-2019-25746HIGH7.1WordPress Sliced Invoices 3.8.2 contains an authenticated SQL injection vulnerability that allows authenticated attacker...
CVE-2019-25745HIGH8.8WordPress Plugin Google Review Slider 6.1 contains a time-based blind SQL injection vulnerability that allows unauthenti...
CVE-2019-25740HIGH7.1Joomla com_jsjobs 1.2.6 contains an arbitrary file deletion vulnerability that allows authenticated attackers to delete ...
CVE-2019-25736HIGH8.6LabF nfsAxe 3.7 Ping Client contains a buffer overflow vulnerability that allows local attackers to execute arbitrary co...
CVE-2019-25735HIGH8.6AllPlayer 7.4 contains a local buffer overflow vulnerability in URL handling that allows attackers to overwrite structur...
CVE-2019-25733HIGH8.6NetShareWatcher 1.5.8.0 contains a structured exception handler buffer overflow vulnerability that allows local attacker...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now