2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-16333MEDIUM5.4GetSimple CMS v3.3.15 has Persistent Cross-Site Scripting (XSS) in admin/theme-edit.php.
CVE-2019-16332MEDIUM6.1In the api-bearer-auth plugin before 20190907 for WordPress, the server parameter is not correctly filtered in the swagg...
CVE-2019-16321MEDIUM6.1ScadaBR 1.0CE, and 1.1.x through 1.1.0-RC, has XSS via a request for a nonexistent resource, as demonstrated by the dwr/...
CVE-2019-16320MEDIUM5.3Cobham Sea Tel v170 224521 through v194 225444 devices allow attackers to obtain potentially sensitive information, such...
CVE-2019-16307MEDIUM6.1A Reflected Cross-Site Scripting (XSS) vulnerability in the webEx module in webExMeetingLogin.jsp and deleteWebExMeeting...
CVE-2019-16312MEDIUM6.1s-cms V3.0 has XSS in index.php?type=text via the S_id parameter.
CVE-2019-16310MEDIUM5.4NIUSHOP V1.11 has XSS via the index.php?s=/admin URI.
CVE-2019-5314MEDIUM6.1Some web components in the ArubaOS software are vulnerable to HTTP Response splitting (CRLF injection) and Reflected XSS...
CVE-2019-13920MEDIUM4.3A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). Some parts of the web app...
CVE-2019-13919MEDIUM4.3A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). Some pages that should on...
CVE-2019-16289MEDIUM5.4The insert-php (aka Woody ad snippets) plugin before 2.2.8 for WordPress allows authenticated XSS via the winp_item para...
CVE-2019-3646MEDIUM6.5DLL Search Order Hijacking vulnerability in Microsoft Windows client in McAfee Total Protection (MTP) Free Antivirus Tri...
CVE-2019-15031MEDIUM4.4In the Linux kernel through 5.2.14 on the powerpc platform, a local user can read vector registers of other users' proce...
CVE-2019-15030MEDIUM4.4In the Linux kernel through 5.2.14 on the powerpc platform, a local user can read vector registers of other users' proce...
CVE-2019-12922MEDIUM6.5A CSRF issue in phpMyAdmin 4.9.0.1 allows deletion of any server in the Setup page.
CVE-2019-12517MEDIUM6.1An XSS issue was discovered in the slickquiz plugin through 1.3.7.1 for WordPress. The save_quiz_score functionality ava...
CVE-2019-16275MEDIUM6.5hostapd before 2.10 and wpa_supplicant before 2.10 allow an incorrect indication of disconnection in certain situations ...
CVE-2019-6009MEDIUM6.1Open redirect vulnerability in SHIRASAGI v1.7.0 and earlier allows remote attackers to redirect users to arbitrary web s...
CVE-2019-6004MEDIUM6.1Open redirect vulnerability in ApeosWare Management Suite Ver.1.4.0.18 and earlier, and ApeosWare Management Suite 2 Ver...
CVE-2019-6003MEDIUM6.1Cross-site scripting vulnerability in EC-CUBE plugin 'Amazon Pay Plugin 2.12,2.13' version 2.4.2 and earlier allows remo...
CVE-2019-5985MEDIUM6.1Cross-site scripting vulnerability in Hikari Denwa router/Home GateWay (Hikari Denwa router/Home GateWay provided by NIP...
CVE-2019-5978MEDIUM6.1Open redirect vulnerability in Cybozu Garoon 4.0.0 to 4.10.2 allows remote attackers to redirect users to arbitrary web ...
CVE-2019-5977MEDIUM4.3Mail header injection vulnerability in Cybozu Garoon 4.0.0 to 4.10.2 may allow a remote authenticated attackers to alter...
CVE-2019-5976MEDIUM4.9Cybozu Garoon 4.0.0 to 4.10.2 allows an attacker with administrative rights to cause a denial of service condition via u...
CVE-2019-5975MEDIUM5.4DOM-based cross-site scripting vulnerability in Cybozu Garoon 4.6.0 to 4.10.2 allows remote authenticated attackers to i...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now