2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-6013MEDIUM6.6DBA-1510P firmware 1.70b009 and earlier allows authenticated attackers to execute arbitrary OS commands via Command Line...
CVE-2019-6012HIGH7.2SQL injection vulnerability in the wpDataTables Lite Version 2.0.11 and earlier allows remote authenticated attackers to...
CVE-2019-6011MEDIUM6.1Cross-site scripting vulnerability in wpDataTables Lite Version 2.0.11 and earlier allows remote attackers to inject arb...
CVE-2019-6008HIGH7.8An unquoted search path vulnerability in Multiple Yokogawa products for Windows (Exaopc (R1.01.00 ? R3.77.00), Exaplog (...
CVE-2019-19681HIGH8.8Pandora FMS 7.x suffers from remote code execution vulnerability. With an authenticated user who can modify the alert sy...
CVE-2019-15695HIGH7.2TigerVNC version prior to 1.10.1 is vulnerable to stack buffer overflow, which could be triggered from CMsgReader::readS...
CVE-2019-19542MEDIUM5.4The ListingPro theme before v2.0.14.2 for WordPress has Persistent XSS via the Good For field on the new listing submit ...
CVE-2019-19541MEDIUM5.4The ListingPro theme before v2.0.14.2 for WordPress has Persistent XSS via the Best Day/Night field on the new listing s...
CVE-2019-19540MEDIUM6.1The ListingPro theme before v2.0.14.2 for WordPress has Reflected XSS via the What field on the homepage.
CVE-2019-15694HIGH7.2TigerVNC version prior to 1.10.1 is vulnerable to heap buffer overflow, which could be triggered from DecodeManager::dec...
CVE-2019-15693HIGH7.2TigerVNC version prior to 1.10.1 is vulnerable to heap buffer overflow, which occurs in TightDecoder::FilterGradient. Ex...
CVE-2019-15692HIGH7.2TigerVNC version prior to 1.10.1 is vulnerable to heap buffer overflow. Vulnerability could be triggered from CopyRectDe...
CVE-2019-15691HIGH7.2TigerVNC version prior to 1.10.1 is vulnerable to stack use-after-return, which occurs due to incorrect usage of stack m...
CVE-2019-20000MEDIUM5.9The malware scan function in BullGuard Premium Protection 20.0.371.8 has a TOCTOU issue that enables a symbolic link att...
CVE-2019-19999HIGH7.2Halo before 1.2.0-beta.1 allows Server Side Template Injection (SSTI) because TemplateClassResolver.SAFER_RESOLVER is no...
CVE-2019-19998HIGH7.5Xiuno BBS 4.0 allows XXE via plugin/xn_wechat_public/route/token.php.
CVE-2019-19985MEDIUM5.3The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed unauthenticated file downloa...
CVE-2019-19984MEDIUM6.3The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed users with edit_post capabil...
CVE-2019-19983MEDIUM4.3In the WordPress plugin, Fast Velocity Minify before 2.7.7, the full web root path to the running WordPress application ...
CVE-2019-19982MEDIUM5.3The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for unauthenticated option c...
CVE-2019-19981MEDIUM5.4The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for CSRF to be exploited on ...
CVE-2019-19980MEDIUM4.3The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a privilege bypass flaw that allowed authenticat...
CVE-2019-19979HIGH8.8A flaw in the WordPress plugin, WP Maintenance before 5.0.6, allowed attackers to enable a vulnerable site's maintenance...
CVE-2019-19977CRITICAL9.8libESMTP through 1.0.6 mishandles domain copying into a fixed-size buffer in ntlm_build_type_2 in ntlm/ntlmstruct.c, as ...
CVE-2019-19967HIGH7.5The Administration page on Connect Box EuroDOCSIS 3.0 Voice Gateway CH7465LG-NCIP-6.12.18.25-2p6-NOSH devices accepts a ...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now