2019 CVE Vulnerabilities

17,624 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-25744MEDIUM5.4WordPress Popup Builder 3.49 contains a persistent cross-site scripting vulnerability that allows authenticated attacker...
CVE-2019-25743MEDIUM5.4WordPress Soliloquy Lite 2.5.6 contains a persistent cross-site scripting vulnerability that allows authenticated attack...
CVE-2019-25742MEDIUM5.4WordPress Theme Zoner Real Estate 4.1.1 contains a persistent cross-site scripting vulnerability that allows authenticat...
CVE-2019-25741CRITICAL9.8Mobatek MobaXterm 12.1 contains a structured exception handling (SEH) based buffer overflow vulnerability in the usernam...
CVE-2019-25740HIGH7.1Joomla com_jsjobs 1.2.6 contains an arbitrary file deletion vulnerability that allows authenticated attackers to delete ...
CVE-2019-25739MEDIUM5.4GigToDo 1.3 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malic...
CVE-2019-25738CRITICAL9.8WordPress Hybrid Composer 1.4.6 contains an unauthenticated settings change vulnerability that allows unauthenticated at...
CVE-2019-25737MEDIUM6.1Live Chat Unlimited 2.8.3 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to ...
CVE-2019-25736HIGH8.6LabF nfsAxe 3.7 Ping Client contains a buffer overflow vulnerability that allows local attackers to execute arbitrary co...
CVE-2019-25735HIGH8.6AllPlayer 7.4 contains a local buffer overflow vulnerability in URL handling that allows attackers to overwrite structur...
CVE-2019-25734MEDIUM5.1Contact Form by WD 1.13.1 contains a cross-site request forgery vulnerability combined with local file inclusion that al...
CVE-2019-25733HIGH8.6NetShareWatcher 1.5.8.0 contains a structured exception handler buffer overflow vulnerability that allows local attacker...
CVE-2019-25732HIGH8.8PHP EI-Tube Script 3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary ...
CVE-2019-25731MEDIUM6.1Zuz Music 2.1 contains a persistent cross-site scripting vulnerability that allows unauthenticated attackers to inject m...
CVE-2019-25730HIGH8.8Listing Hub CMS 1.0 contains a SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQ...
CVE-2019-25729CRITICAL9.8PDF Signer 3.0 contains a server-side template injection vulnerability that allows unauthenticated attackers to execute ...
CVE-2019-25728HIGH8.8Care2x 2.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL...
CVE-2019-25727CRITICAL9.8WordPress Plugin ad manager wd 1.0.11 contains an arbitrary file download vulnerability that allows unauthenticated atta...
CVE-2019-25726HIGH8.8All in One Video Downloader 1.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute...
CVE-2019-25720HIGH7.1Dräger SC Monitoring devices (SC 6002XL, SC 6802XL, SC 7000, SC 8000, SC 9000 XL) contain a denial-of-service vulnerabil...
CVE-2019-25724HIGH7.1Dräger Infinity M300 patient worn monitors with software version VG2.x and earlier contain a network-based denial of ser...
CVE-2019-25723MEDIUM6.3Dräger Perseus A500 software versions 2.00 through 2.02 contains an improper input handling vulnerability that allows ex...
CVE-2019-25722HIGH7.6Dräger SC Monitoring devices (SC 6002XL, SC 6802XL, SC 7000, SC 8000, SC 9000 XL) contain hard-coded plaintext credentia...
CVE-2019-25721HIGH7.1Dräger Infinity M300 patient worn monitors with software version VG2.3.1 and earlier contain a network-based denial of s...
CVE-2019-25719HIGH8.8Dräger Infinity Acute Care System and Standalone Infinity M540 patient monitors running software versions VG4.1.1, VG4.0...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now