2019 CVE Vulnerabilities

17,618 CVEs published in 2019.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2019-25224CRITICAL9.8The WP Database Backup plugin for WordPress is vulnerable to OS Command Injection in versions before 5.2 via the mysqldu...
CVE-2019-17082CRITICAL9Insufficiently Protected Credentials vulnerability in OpenText™ AccuRev allows Authentication Bypass. When installed on ...
CVE-2019-20461CRITICAL9.8An issue was discovered on Alecto IVM-100 2019-11-12 devices. The device uses a custom UDP protocol to start and control...
CVE-2019-20457CRITICAL9.1An issue was discovered on Brother MFC-J491DW C1806180757 devices. The printer's web-interface password hash can be retr...
CVE-2019-25217CRITICAL9.8The SiteGround Optimizer plugin for WordPress is vulnerable to authorization bypass leading to Remote Code Execution and...
CVE-2019-25154CRITICAL9.6Inappropriate implementation in iframe in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially p...
CVE-2019-16639CRITICAL9.8An issue was found on the Ruijie EG-2000 series gateway. There is a newcli.php API interface without access control, whi...
CVE-2019-25211CRITICAL9.1parseWildcardRules in Gin-Gonic CORS middleware before 1.6.0 mishandles a wildcard at the end of an origin string, e.g.,...
CVE-2019-19755CRITICAL9.1ethOS through 1.3.3 ships with SSH host keys baked into the installation image, which allows man-in-the-middle attacks a...
CVE-2019-19753CRITICAL9.1SimpleMiningOS through v1259 ships with SSH host keys baked into the installation image, which allows man-in-the-middle ...
CVE-2019-19752CRITICAL9.8nvOC through 3.2 ships with SSH host keys baked into the installation image, which allows man-in-the-middle attacks and ...
CVE-2019-25159CRITICAL9.8A vulnerability was found in mpedraza2020 Intranet del Monterroso up to 4.50.0. It has been classified as critical. This...
CVE-2019-25158CRITICAL9.8A vulnerability has been found in pedroetb tts-api up to 2.1.4 and classified as critical. This vulnerability affects th...
CVE-2019-19450CRITICAL9.8paraparser in ReportLab before 3.5.31 allows remote code execution because start_unichar in paraparser.py evaluates untr...
CVE-2019-13690CRITICAL9.6Inappropriate implementation in OS in Google Chrome on ChromeOS prior to 75.0.3770.80 allowed a remote attacker to perfo...
CVE-2019-25136CRITICAL10A compromised child process could have injected XBL Bindings into privileged CSS rules, resulting in arbitrary code exec...
CVE-2019-25141CRITICAL9.8The Easy WP SMTP plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.3.9. Thi...
CVE-2019-25138CRITICAL9.8The User Submitted Posts plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validatio...
CVE-2019-19791CRITICAL9.8In LemonLDAP::NG (aka lemonldap-ng) before 2.0.7, the default Apache HTTP Server configuration does not properly restric...
CVE-2019-25101CRITICAL9.8A vulnerability classified as critical has been found in OnShift TurboGears 1.0.11.10. This affects an unknown part of t...
CVE-2019-25100CRITICAL9.8A vulnerability was found in happyman twmap. It has been declared as critical. Affected by this vulnerability is an unkn...
CVE-2019-25098CRITICAL9.8A vulnerability was found in soerennb eXtplorer up to 2.1.12. It has been classified as critical. This affects an unknow...
CVE-2019-25097CRITICAL9.8A vulnerability was found in soerennb eXtplorer up to 2.1.12 and classified as critical. Affected by this issue is some ...
CVE-2019-11851CRITICAL9.8The ACENet service in Sierra Wireless ALEOS before 4.4.9, 4.5.x through 4.9.x before 4.9.5, and 4.10.x through 4.13.x be...
CVE-2019-15167CRITICAL9.1The VRRP parser in tcpdump before 4.9.3 has a buffer over-read in print-vrrp.c:vrrp_print() for VRRP version 3, a differ...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now