2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-16333 | MEDIUM | 5.4 | 0.7% | Sep 15, 2019 | GetSimple CMS v3.3.15 has Persistent Cross-Site Scripting (XSS) in admin/theme-edit.php. |
| CVE-2019-16332 | MEDIUM | 6.1 | 5.7% | Sep 15, 2019 | In the api-bearer-auth plugin before 20190907 for WordPress, the server parameter is not correctly filtered in the swagg... |
| CVE-2019-16321 | MEDIUM | 6.1 | 0.8% | Sep 15, 2019 | ScadaBR 1.0CE, and 1.1.x through 1.1.0-RC, has XSS via a request for a nonexistent resource, as demonstrated by the dwr/... |
| CVE-2019-16320 | MEDIUM | 5.3 | 1.1% | Sep 15, 2019 | Cobham Sea Tel v170 224521 through v194 225444 devices allow attackers to obtain potentially sensitive information, such... |
| CVE-2019-16307 | MEDIUM | 6.1 | 1.1% | Sep 14, 2019 | A Reflected Cross-Site Scripting (XSS) vulnerability in the webEx module in webExMeetingLogin.jsp and deleteWebExMeeting... |
| CVE-2019-16312 | MEDIUM | 6.1 | 0.8% | Sep 14, 2019 | s-cms V3.0 has XSS in index.php?type=text via the S_id parameter. |
| CVE-2019-16310 | MEDIUM | 5.4 | 0.6% | Sep 14, 2019 | NIUSHOP V1.11 has XSS via the index.php?s=/admin URI. |
| CVE-2019-5314 | MEDIUM | 6.1 | 0.6% | Sep 13, 2019 | Some web components in the ArubaOS software are vulnerable to HTTP Response splitting (CRLF injection) and Reflected XSS... |
| CVE-2019-13920 | MEDIUM | 4.3 | 0.4% | Sep 13, 2019 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). Some parts of the web app... |
| CVE-2019-13919 | MEDIUM | 4.3 | 0.8% | Sep 13, 2019 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). Some pages that should on... |
| CVE-2019-16289 | MEDIUM | 5.4 | 1.0% | Sep 13, 2019 | The insert-php (aka Woody ad snippets) plugin before 2.2.8 for WordPress allows authenticated XSS via the winp_item para... |
| CVE-2019-3646 | MEDIUM | 6.5 | 1.5% | Sep 13, 2019 | DLL Search Order Hijacking vulnerability in Microsoft Windows client in McAfee Total Protection (MTP) Free Antivirus Tri... |
| CVE-2019-15031 | MEDIUM | 4.4 | 0.6% | Sep 13, 2019 | In the Linux kernel through 5.2.14 on the powerpc platform, a local user can read vector registers of other users' proce... |
| CVE-2019-15030 | MEDIUM | 4.4 | 0.5% | Sep 13, 2019 | In the Linux kernel through 5.2.14 on the powerpc platform, a local user can read vector registers of other users' proce... |
| CVE-2019-12922 | MEDIUM | 6.5 | 10.2% | Sep 13, 2019 | A CSRF issue in phpMyAdmin 4.9.0.1 allows deletion of any server in the Setup page. |
| CVE-2019-12517 | MEDIUM | 6.1 | 1.2% | Sep 13, 2019 | An XSS issue was discovered in the slickquiz plugin through 1.3.7.1 for WordPress. The save_quiz_score functionality ava... |
| CVE-2019-16275 | MEDIUM | 6.5 | 1.2% | Sep 12, 2019 | hostapd before 2.10 and wpa_supplicant before 2.10 allow an incorrect indication of disconnection in certain situations ... |
| CVE-2019-6009 | MEDIUM | 6.1 | 1.8% | Sep 12, 2019 | Open redirect vulnerability in SHIRASAGI v1.7.0 and earlier allows remote attackers to redirect users to arbitrary web s... |
| CVE-2019-6004 | MEDIUM | 6.1 | 1.1% | Sep 12, 2019 | Open redirect vulnerability in ApeosWare Management Suite Ver.1.4.0.18 and earlier, and ApeosWare Management Suite 2 Ver... |
| CVE-2019-6003 | MEDIUM | 6.1 | 1.0% | Sep 12, 2019 | Cross-site scripting vulnerability in EC-CUBE plugin 'Amazon Pay Plugin 2.12,2.13' version 2.4.2 and earlier allows remo... |
| CVE-2019-5985 | MEDIUM | 6.1 | 0.9% | Sep 12, 2019 | Cross-site scripting vulnerability in Hikari Denwa router/Home GateWay (Hikari Denwa router/Home GateWay provided by NIP... |
| CVE-2019-5978 | MEDIUM | 6.1 | 1.1% | Sep 12, 2019 | Open redirect vulnerability in Cybozu Garoon 4.0.0 to 4.10.2 allows remote attackers to redirect users to arbitrary web ... |
| CVE-2019-5977 | MEDIUM | 4.3 | 1.1% | Sep 12, 2019 | Mail header injection vulnerability in Cybozu Garoon 4.0.0 to 4.10.2 may allow a remote authenticated attackers to alter... |
| CVE-2019-5976 | MEDIUM | 4.9 | 1.2% | Sep 12, 2019 | Cybozu Garoon 4.0.0 to 4.10.2 allows an attacker with administrative rights to cause a denial of service condition via u... |
| CVE-2019-5975 | MEDIUM | 5.4 | 0.8% | Sep 12, 2019 | DOM-based cross-site scripting vulnerability in Cybozu Garoon 4.6.0 to 4.10.2 allows remote authenticated attackers to i... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now