2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-6013 | MEDIUM | 6.6 | 0.6% | Dec 26, 2019 | DBA-1510P firmware 1.70b009 and earlier allows authenticated attackers to execute arbitrary OS commands via Command Line... |
| CVE-2019-6012 | HIGH | 7.2 | 1.4% | Dec 26, 2019 | SQL injection vulnerability in the wpDataTables Lite Version 2.0.11 and earlier allows remote authenticated attackers to... |
| CVE-2019-6011 | MEDIUM | 6.1 | 0.9% | Dec 26, 2019 | Cross-site scripting vulnerability in wpDataTables Lite Version 2.0.11 and earlier allows remote attackers to inject arb... |
| CVE-2019-6008 | HIGH | 7.8 | 1.3% | Dec 26, 2019 | An unquoted search path vulnerability in Multiple Yokogawa products for Windows (Exaopc (R1.01.00 ? R3.77.00), Exaplog (... |
| CVE-2019-19681 | HIGH | 8.8 | 4.6% | Dec 26, 2019 | Pandora FMS 7.x suffers from remote code execution vulnerability. With an authenticated user who can modify the alert sy... |
| CVE-2019-15695 | HIGH | 7.2 | 4.5% | Dec 26, 2019 | TigerVNC version prior to 1.10.1 is vulnerable to stack buffer overflow, which could be triggered from CMsgReader::readS... |
| CVE-2019-19542 | MEDIUM | 5.4 | 0.7% | Dec 26, 2019 | The ListingPro theme before v2.0.14.2 for WordPress has Persistent XSS via the Good For field on the new listing submit ... |
| CVE-2019-19541 | MEDIUM | 5.4 | 0.7% | Dec 26, 2019 | The ListingPro theme before v2.0.14.2 for WordPress has Persistent XSS via the Best Day/Night field on the new listing s... |
| CVE-2019-19540 | MEDIUM | 6.1 | 0.9% | Dec 26, 2019 | The ListingPro theme before v2.0.14.2 for WordPress has Reflected XSS via the What field on the homepage. |
| CVE-2019-15694 | HIGH | 7.2 | 4.5% | Dec 26, 2019 | TigerVNC version prior to 1.10.1 is vulnerable to heap buffer overflow, which could be triggered from DecodeManager::dec... |
| CVE-2019-15693 | HIGH | 7.2 | 4.3% | Dec 26, 2019 | TigerVNC version prior to 1.10.1 is vulnerable to heap buffer overflow, which occurs in TightDecoder::FilterGradient. Ex... |
| CVE-2019-15692 | HIGH | 7.2 | 4.8% | Dec 26, 2019 | TigerVNC version prior to 1.10.1 is vulnerable to heap buffer overflow. Vulnerability could be triggered from CopyRectDe... |
| CVE-2019-15691 | HIGH | 7.2 | 4.7% | Dec 26, 2019 | TigerVNC version prior to 1.10.1 is vulnerable to stack use-after-return, which occurs due to incorrect usage of stack m... |
| CVE-2019-20000 | MEDIUM | 5.9 | 0.6% | Dec 26, 2019 | The malware scan function in BullGuard Premium Protection 20.0.371.8 has a TOCTOU issue that enables a symbolic link att... |
| CVE-2019-19999 | HIGH | 7.2 | 1.5% | Dec 26, 2019 | Halo before 1.2.0-beta.1 allows Server Side Template Injection (SSTI) because TemplateClassResolver.SAFER_RESOLVER is no... |
| CVE-2019-19998 | HIGH | 7.5 | 1.1% | Dec 26, 2019 | Xiuno BBS 4.0 allows XXE via plugin/xn_wechat_public/route/token.php. |
| CVE-2019-19985 | MEDIUM | 5.3 | 71.4% | Dec 26, 2019 | The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed unauthenticated file downloa... |
| CVE-2019-19984 | MEDIUM | 6.3 | 1.0% | Dec 26, 2019 | The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed users with edit_post capabil... |
| CVE-2019-19983 | MEDIUM | 4.3 | 1.2% | Dec 26, 2019 | In the WordPress plugin, Fast Velocity Minify before 2.7.7, the full web root path to the running WordPress application ... |
| CVE-2019-19982 | MEDIUM | 5.3 | 1.2% | Dec 26, 2019 | The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for unauthenticated option c... |
| CVE-2019-19981 | MEDIUM | 5.4 | 0.6% | Dec 26, 2019 | The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for CSRF to be exploited on ... |
| CVE-2019-19980 | MEDIUM | 4.3 | 1.0% | Dec 26, 2019 | The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a privilege bypass flaw that allowed authenticat... |
| CVE-2019-19979 | HIGH | 8.8 | 0.6% | Dec 26, 2019 | A flaw in the WordPress plugin, WP Maintenance before 5.0.6, allowed attackers to enable a vulnerable site's maintenance... |
| CVE-2019-19977 | CRITICAL | 9.8 | 3.1% | Dec 26, 2019 | libESMTP through 1.0.6 mishandles domain copying into a fixed-size buffer in ntlm_build_type_2 in ntlm/ntlmstruct.c, as ... |
| CVE-2019-19967 | HIGH | 7.5 | 1.0% | Dec 25, 2019 | The Administration page on Connect Box EuroDOCSIS 3.0 Voice Gateway CH7465LG-NCIP-6.12.18.25-2p6-NOSH devices accepts a ... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now