2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-25332HIGH8.4FTP Commander Pro 8.03 contains a local stack overflow vulnerability that allows attackers to execute arbitrary code by ...
CVE-2019-25331HIGH8.4AVS Audio Converter 9.1 contains a local buffer overflow vulnerability that allows local attackers to overwrite CPU regi...
CVE-2019-25330HIGH7.5SurfOffline Professional 2.2.0.103 contains a structured exception handler (SEH) overflow vulnerability that allows atta...
CVE-2019-25329HIGH7.5FTP Navigator 8.03 contains a denial of service vulnerability that allows attackers to crash the application by overwrit...
CVE-2019-25328HIGH7.5XnConvert 1.82 contains a denial of service vulnerability in its registration code input field that allows attackers to ...
CVE-2019-25327CRITICAL9.8Prime95 version 29.8 build 6 contains a buffer overflow vulnerability in the user ID input field that allows remote atta...
CVE-2019-25325HIGH8.8Thrive Smart Home 1.1 contains an SQL injection vulnerability in the checklogin.php endpoint that allows unauthenticated...
CVE-2019-25324MEDIUM6.1RICOH Web Image Monitor 1.09 contains an HTML injection vulnerability in the address configuration CGI script that allow...
CVE-2019-25323MEDIUM6.1Heatmiser Netmonitor v3.03 contains an HTML injection vulnerability in the outputSetup.htm page that allows attackers to...
CVE-2019-25322CRITICAL9.3Heatmiser Netmonitor 3.03 contains a hardcoded credentials vulnerability in the networkSetup.htm page with predictable a...
CVE-2019-25321CRITICAL9.8FTP Navigator 8.03 contains a stack overflow vulnerability that allows attackers to execute arbitrary code by overwritin...
CVE-2019-25320HIGH8.8E Learning Script 1.0 contains an authentication bypass vulnerability that allows attackers to access the dashboard with...
CVE-2019-25319CRITICAL9.8Domain Quester Pro 6.02 contains a stack overflow vulnerability that allows remote attackers to execute arbitrary code b...
CVE-2019-25318HIGH8.8AVS Audio Converter 9.1.2.600 contains a stack overflow vulnerability that allows attackers to execute arbitrary code by...
CVE-2019-25348Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2019-25347HIGH7.5thesystem App 1.0 contains a SQL injection vulnerability that allows attackers to bypass authentication by manipulating ...
CVE-2019-25346HIGH7.5TheSystem 1.0 contains a SQL injection vulnerability that allows attackers to bypass authentication by manipulating the ...
CVE-2019-25345HIGH8.5Realtek IIS Codec Service 6.4.10041.133 contains an unquoted service path vulnerability that allows local attackers to p...
CVE-2019-25344HIGH8.5Wondershare MobileGo 8.5.0 contains an insecure file permissions vulnerability that allows local users to modify executa...
CVE-2019-25343HIGH8.5NextVPN 4.10 contains an insecure file permissions vulnerability that allows local users to modify executable files with...
CVE-2019-25313MEDIUM5.1FlexNet Publisher 11.12.1 contains a cross-site request forgery vulnerability that allows attackers to create administra...
CVE-2019-25317MEDIUM5.4Kimai 2 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts into ...
CVE-2019-25316MEDIUM6.4GOautodial 4.0 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject ma...
CVE-2019-25315MEDIUM6.4WordPress Server Log Viewer 1.0 contains a persistent cross-site scripting vulnerability that allows attackers to inject...
CVE-2019-25314MEDIUM5.5Yoast Duplicate-Post WordPress Plugin 3.2.3 contains a persistent cross-site scripting vulnerability in plugin settings ...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now