2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-16327 | CRITICAL | 9.8 | 1.8% | Dec 26, 2019 | D-Link DIR-601 B1 2.00NA devices are vulnerable to authentication bypass. They do not check for authentication at the se... |
| CVE-2019-16326 | HIGH | 8.8 | 0.6% | Dec 26, 2019 | D-Link DIR-601 B1 2.00NA devices have CSRF because no anti-CSRF token is implemented. A remote attacker could exploit th... |
| CVE-2019-16789 | HIGH | 8.2 | 2.6% | Dec 26, 2019 | In Waitress through version 1.4.0, if a proxy server is used in front of waitress, an invalid request may be sent by an ... |
| CVE-2019-16781 | MEDIUM | 5.4 | 1.4% | Dec 26, 2019 | In WordPress before 5.3.1, authenticated users with lower privileges (like contributors) can inject JavaScript code in t... |
| CVE-2019-16780 | MEDIUM | 5.4 | 1.7% | Dec 26, 2019 | WordPress users with lower privileges (like contributors) can inject JavaScript code in the block editor using a specifi... |
| CVE-2019-6035 | MEDIUM | 6.1 | 1.1% | Dec 26, 2019 | Open redirect vulnerability in Athenz v1.8.24 and earlier allows remote attackers to redirect users to arbitrary web sit... |
| CVE-2019-6034 | MEDIUM | 6.1 | 0.7% | Dec 26, 2019 | a-blog cms versions prior to Ver.2.10.23 (Ver.2.10.x), Ver.2.9.26 (Ver.2.9.x), and Ver.2.8.64 (Ver.2.8.x) allows arbitra... |
| CVE-2019-6033 | MEDIUM | 6.1 | 0.8% | Dec 26, 2019 | Cross-site scripting vulnerability in a-blog cms versions prior to Ver.2.10.23 (Ver.2.10.x), Ver.2.9.26 (Ver.2.9.x), and... |
| CVE-2019-6032 | HIGH | 7.4 | 0.5% | Dec 26, 2019 | The NTV News24 prior to Ver.3.0.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle at... |
| CVE-2019-6031 | MEDIUM | 6.1 | 0.8% | Dec 26, 2019 | Cross-site scripting vulnerability in KINZA for Windows version 5.9.2 and earlier and for Mac version 5.0.0 and earlier ... |
| CVE-2019-6030 | HIGH | 8.8 | 0.7% | Dec 26, 2019 | Cross-site request forgery (CSRF) vulnerability in Custom Body Class 0.6.0 and earlier allows remote attackers to hijack... |
| CVE-2019-6029 | MEDIUM | 6.1 | 0.9% | Dec 26, 2019 | Cross-site scripting vulnerability in Custom Body Class 0.6.0 and earlier allows remote attackers to inject arbitrary we... |
| CVE-2019-6027 | HIGH | 8.8 | 0.7% | Dec 26, 2019 | Cross-site request forgery (CSRF) vulnerability in WP Spell Check 7.1.9 and earlier allows remote attackers to hijack th... |
| CVE-2019-6026 | HIGH | 7.8 | 0.4% | Dec 26, 2019 | Privilege escalation vulnerability in Multiple MOTEX products (LanScope Cat client program (MR) and LanScope Cat client ... |
| CVE-2019-6025 | MEDIUM | 6.1 | 0.9% | Dec 26, 2019 | Open redirect vulnerability in Movable Type series Movable Type 7 r.4602 (7.1.3) and earlier (Movable Type 7), Movable T... |
| CVE-2019-6024 | MEDIUM | 6.5 | 2.0% | Dec 26, 2019 | Rakuma App for Android version 7.15.0 and earlier, and for iOS version 7.16.4 and earlier allows an attacker to bypass a... |
| CVE-2019-6023 | MEDIUM | 4.3 | 1.0% | Dec 26, 2019 | Cybozu Office 10.0.0 to 10.8.3 allows remote authenticated attackers to bypass access restriction which may result in ob... |
| CVE-2019-6022 | MEDIUM | 6.5 | 2.0% | Dec 26, 2019 | Directory traversal vulnerability in Cybozu Office 10.0.0 to 10.8.3 allows remote authenticated attackers to alter arbit... |
| CVE-2019-6021 | MEDIUM | 6.1 | 0.9% | Dec 26, 2019 | Open redirect vulnerability in Library Information Management System LIMEDIO all versions allows remote attackers to red... |
| CVE-2019-6020 | MEDIUM | 6.1 | 0.9% | Dec 26, 2019 | Open redirect vulnerability in PowerCMS 5.12 and earlier (PowerCMS 5.x), 4.42 and earlier (PowerCMS 4.x), and 3.293 and ... |
| CVE-2019-6019 | HIGH | 7.8 | 0.8% | Dec 26, 2019 | Untrusted search path vulnerability in STAMP Workbench installer all versions allows an attacker to gain privileges via ... |
| CVE-2019-6018 | MEDIUM | 6.1 | 0.8% | Dec 26, 2019 | Cross-site scripting vulnerability in NetCommons 3.2.2 and earlier (NetCommons3.x) allows remote attackers to inject arb... |
| CVE-2019-6017 | MEDIUM | 5.3 | 1.1% | Dec 26, 2019 | REMISE Payment Module (2.11, 2.12 and 2.13) version 3.0.12 and earlier allow remote attackers to [Disclosed_Information_... |
| CVE-2019-6016 | MEDIUM | 6.1 | 0.8% | Dec 26, 2019 | Cross-site scripting vulnerability in REMISE Payment Module (2.11, 2.12 and 2.13) version 3.0.12 and earlier allows remo... |
| CVE-2019-6014 | HIGH | 8.8 | 1.2% | Dec 26, 2019 | DBA-1510P firmware 1.70b009 and earlier allows an attacker to execute arbitrary OS commands via Web User Interface. |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now