2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-16327CRITICAL9.8D-Link DIR-601 B1 2.00NA devices are vulnerable to authentication bypass. They do not check for authentication at the se...
CVE-2019-16326HIGH8.8D-Link DIR-601 B1 2.00NA devices have CSRF because no anti-CSRF token is implemented. A remote attacker could exploit th...
CVE-2019-16789HIGH8.2In Waitress through version 1.4.0, if a proxy server is used in front of waitress, an invalid request may be sent by an ...
CVE-2019-16781MEDIUM5.4In WordPress before 5.3.1, authenticated users with lower privileges (like contributors) can inject JavaScript code in t...
CVE-2019-16780MEDIUM5.4WordPress users with lower privileges (like contributors) can inject JavaScript code in the block editor using a specifi...
CVE-2019-6035MEDIUM6.1Open redirect vulnerability in Athenz v1.8.24 and earlier allows remote attackers to redirect users to arbitrary web sit...
CVE-2019-6034MEDIUM6.1a-blog cms versions prior to Ver.2.10.23 (Ver.2.10.x), Ver.2.9.26 (Ver.2.9.x), and Ver.2.8.64 (Ver.2.8.x) allows arbitra...
CVE-2019-6033MEDIUM6.1Cross-site scripting vulnerability in a-blog cms versions prior to Ver.2.10.23 (Ver.2.10.x), Ver.2.9.26 (Ver.2.9.x), and...
CVE-2019-6032HIGH7.4The NTV News24 prior to Ver.3.0.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle at...
CVE-2019-6031MEDIUM6.1Cross-site scripting vulnerability in KINZA for Windows version 5.9.2 and earlier and for Mac version 5.0.0 and earlier ...
CVE-2019-6030HIGH8.8Cross-site request forgery (CSRF) vulnerability in Custom Body Class 0.6.0 and earlier allows remote attackers to hijack...
CVE-2019-6029MEDIUM6.1Cross-site scripting vulnerability in Custom Body Class 0.6.0 and earlier allows remote attackers to inject arbitrary we...
CVE-2019-6027HIGH8.8Cross-site request forgery (CSRF) vulnerability in WP Spell Check 7.1.9 and earlier allows remote attackers to hijack th...
CVE-2019-6026HIGH7.8Privilege escalation vulnerability in Multiple MOTEX products (LanScope Cat client program (MR) and LanScope Cat client ...
CVE-2019-6025MEDIUM6.1Open redirect vulnerability in Movable Type series Movable Type 7 r.4602 (7.1.3) and earlier (Movable Type 7), Movable T...
CVE-2019-6024MEDIUM6.5Rakuma App for Android version 7.15.0 and earlier, and for iOS version 7.16.4 and earlier allows an attacker to bypass a...
CVE-2019-6023MEDIUM4.3Cybozu Office 10.0.0 to 10.8.3 allows remote authenticated attackers to bypass access restriction which may result in ob...
CVE-2019-6022MEDIUM6.5Directory traversal vulnerability in Cybozu Office 10.0.0 to 10.8.3 allows remote authenticated attackers to alter arbit...
CVE-2019-6021MEDIUM6.1Open redirect vulnerability in Library Information Management System LIMEDIO all versions allows remote attackers to red...
CVE-2019-6020MEDIUM6.1Open redirect vulnerability in PowerCMS 5.12 and earlier (PowerCMS 5.x), 4.42 and earlier (PowerCMS 4.x), and 3.293 and ...
CVE-2019-6019HIGH7.8Untrusted search path vulnerability in STAMP Workbench installer all versions allows an attacker to gain privileges via ...
CVE-2019-6018MEDIUM6.1Cross-site scripting vulnerability in NetCommons 3.2.2 and earlier (NetCommons3.x) allows remote attackers to inject arb...
CVE-2019-6017MEDIUM5.3REMISE Payment Module (2.11, 2.12 and 2.13) version 3.0.12 and earlier allow remote attackers to [Disclosed_Information_...
CVE-2019-6016MEDIUM6.1Cross-site scripting vulnerability in REMISE Payment Module (2.11, 2.12 and 2.13) version 3.0.12 and earlier allows remo...
CVE-2019-6014HIGH8.8DBA-1510P firmware 1.70b009 and earlier allows an attacker to execute arbitrary OS commands via Web User Interface.

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now