2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-14364 | MEDIUM | 6.1 | 1.3% | Jul 28, 2019 | An XSS vulnerability in the "Email Subscribers & Newsletters" plugin 4.1.6 for WordPress allows an attacker to inject ma... |
| CVE-2019-14315 | MEDIUM | 6.1 | 1.2% | Jul 28, 2019 | A cross-site scripting (XSS) vulnerability in upload.php in SunHater KCFinder 3.20-test1, 3.20-test2, 3.12, and earlier ... |
| CVE-2019-6002 | MEDIUM | 6.1 | 1.1% | Jul 26, 2019 | Cross-site scripting vulnerability in Central Dogma 0.17.0 to 0.40.1 allows remote attackers to inject arbitrary web scr... |
| CVE-2019-13387 | MEDIUM | 6.1 | 2.2% | Jul 26, 2019 | In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.846, Reflected XSS in filemanager2.php (parameter fm_current_dir... |
| CVE-2019-13385 | MEDIUM | 4.3 | 2.0% | Jul 26, 2019 | In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.840, File and Directory Information Exposure in filemanager allo... |
| CVE-2019-13057 | MEDIUM | 4.9 | 3.2% | Jul 26, 2019 | An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (databas... |
| CVE-2019-14275 | MEDIUM | 5.5 | 1.2% | Jul 26, 2019 | Xfig fig2dev 3.2.7a has a stack-based buffer overflow in the calc_arrow function in bound.c. |
| CVE-2019-14274 | MEDIUM | 5.5 | 1.6% | Jul 26, 2019 | MCPP 2.7.2 has a heap-based buffer overflow in the do_msg() function in support.c. |
| CVE-2019-5605 | MEDIUM | 6.5 | 2.3% | Jul 26, 2019 | In FreeBSD 11.3-STABLE before r350217, 11.3-RELEASE before 11.3-RELEASE-p1, and 11.2-RELEASE before 11.2-RELEASE-p12, du... |
| CVE-2019-10974 | MEDIUM | 5.5 | 0.3% | Jul 26, 2019 | NREL EnergyPlus, Versions 8.6.0 and possibly prior versions, The application fails to prevent an exception handler from ... |
| CVE-2019-10972 | MEDIUM | 5.5 | 0.9% | Jul 26, 2019 | Mitsubishi Electric FR Configurator2, Version 1.16S and prior. This vulnerability can be triggered when an attacker prov... |
| CVE-2019-3621 | MEDIUM | 6.8 | 0.3% | Jul 25, 2019 | Authentication protection bypass vulnerability in McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3.0 al... |
| CVE-2019-4439 | MEDIUM | 5.3 | 0.3% | Jul 25, 2019 | IBM Cloud Private 3.1.0, 3.1.1, and 3.1.2 does not invalidate session after logout which could allow a local user to imp... |
| CVE-2019-4116 | MEDIUM | 5.5 | 0.4% | Jul 25, 2019 | IBM Cloud Private 2.1.0, 3.1.0, and 3.1.1 could disclose highly sensitive information in installer logs that could be us... |
| CVE-2019-3486 | MEDIUM | 4.6 | 1.0% | Jul 25, 2019 | Mitigates a stored cross site scripting issue in ArcSight Security Management Center versions prior to 2.9.1 |
| CVE-2019-3485 | MEDIUM | 4.6 | 1.1% | Jul 24, 2019 | Mitigates a stored cross site scripting issue in ArcSight Logger versions prior to 6.7.1 |
| CVE-2019-3595 | MEDIUM | 6.5 | 0.7% | Jul 24, 2019 | Improper Neutralization of Special Elements used in a Command ('Command Injection') in ePO extension in McAfee Data Loss... |
| CVE-2019-10968 | MEDIUM | 4.4 | 0.3% | Jul 24, 2019 | Philips Holter 2010 Plus, all versions. A vulnerability has been identified that may allow system options that were not ... |
| CVE-2019-14250 | MEDIUM | 5.5 | 2.3% | Jul 24, 2019 | An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32. simple_object_elf_match in simple-object-... |
| CVE-2019-2879 | MEDIUM | 4.9 | 1.9% | Jul 23, 2019 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected... |
| CVE-2019-2877 | MEDIUM | 5.5 | 0.5% | Jul 23, 2019 | Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions th... |
| CVE-2019-2863 | MEDIUM | 6.5 | 0.5% | Jul 23, 2019 | Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions th... |
| CVE-2019-2853 | MEDIUM | 6.3 | 1.2% | Jul 23, 2019 | Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filter... |
| CVE-2019-2848 | MEDIUM | 6.5 | 0.4% | Jul 23, 2019 | Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions th... |
| CVE-2019-2834 | MEDIUM | 6.5 | 2.3% | Jul 23, 2019 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that a... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now