2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-25276HIGH8.5Studio 5000 Logix Designer 30.01.00 contains an unquoted service path vulnerability in the FactoryTalk Activation Servic...
CVE-2019-25275HIGH8.5BartVPN 1.2.2 contains an unquoted service path vulnerability in the BartVPNService that allows local attackers to poten...
CVE-2019-25274HIGH8.5ProShow Producer 9.0.3797 contains an unquoted service path vulnerability in the ScsiAccess service that allows local at...
CVE-2019-25273HIGH8.5Easy-Hide-IP 5.0.0.3 contains an unquoted service path vulnerability in the EasyRedirect service that allows local attac...
CVE-2019-25272HIGH8.5TexasSoft CyberPlanet 6.4.131 contains an unquoted service path vulnerability in the CCSrvProxy service that allows loca...
CVE-2019-25271HIGH8.5NETGATE Data Backup 3.0.620 contains an unquoted service path vulnerability in its NGDatBckpSrv Windows service configur...
CVE-2019-25269HIGH8.5Amiti Antivirus 25.0.640 contains an unquoted service path vulnerability in its Windows service configurations. Attacker...
CVE-2019-25267HIGH8.5Wing FTP Server 6.0.7 contains an unquoted service path vulnerability that allows local attackers to potentially execute...
CVE-2019-25260HIGH8.8OXID eShop versions 6.x prior to 6.3.4 contains a SQL injection vulnerability in the 'sorting' parameter that allows att...
CVE-2019-25265MEDIUM6.4Online Inventory Manager 3.2 contains a stored cross-site scripting vulnerability in the group description field of the ...
CVE-2019-25264MEDIUM6.4Snipe-IT 4.7.5 contains a persistent cross-site scripting vulnerability that allows authorized users to upload malicious...
CVE-2019-25263MEDIUM6.4Zendesk SweetHawk Survey 1.6 contains a persistent cross-site scripting vulnerability that allows attackers to inject ma...
CVE-2019-25261HIGH8.5AnyDesk 5.4.0 contains an unquoted service path vulnerability in its Windows service configuration that allows local att...
CVE-2019-25232CRITICAL9.8NetPCLinker 1.0.0.0 contains a buffer overflow vulnerability in the Clients Control Panel DNS/IP field that allows attac...
CVE-2019-25297MEDIUM5.1Poll, Survey & Quiz Maker Plugin by Opinion Stage Wordpress plugin versions prior to 19.6.25 contain a stored cross-site...
CVE-2019-25296CRITICAL9.8The WP Cost Estimation plugin for WordPress is vulnerable to arbitrary file uploads and deletion due to missing file typ...
CVE-2019-25295MEDIUM6.5The WP Cost Estimation plugin for WordPress is vulnerable to Upload Directory Traversal in versions before 9.660 via the...
CVE-2019-25291CRITICAL9.3INIM Electronics Smartliving SmartLAN/G/SI <=6.x contains hard-coded credentials in its Linux distribution image that ca...
CVE-2019-25290MEDIUM6.9Smartliving SmartLAN/G/SI <=6.x contains an unauthenticated server-side request forgery vulnerability in the GetImage fu...
CVE-2019-25289HIGH8.8SmartLiving SmartLAN <=6.x contains an authenticated remote command injection vulnerability in the web.cgi binary throug...
CVE-2019-25284MEDIUM6.1V-SOL GPON/EPON OLT Platform v2.03 contains multiple reflected cross-site scripting vulnerabilities due to improper inpu...
CVE-2019-25282CRITICAL9.8V-SOL GPON/EPON OLT Platform v2.03 contains an open redirect vulnerability in the script that allows attackers to manipu...
CVE-2019-25280MEDIUM6.1Yahei-PHP Prober 0.4.7 contains a remote HTML injection vulnerability that allows attackers to execute arbitrary HTML co...
CVE-2019-25279HIGH7.5FaceSentry Access Control System 6.4.8 contains a cleartext password storage vulnerability that allows attackers to acce...
CVE-2019-25278CRITICAL9.1FaceSentry Access Control System 6.4.8 contains a cleartext transmission vulnerability that allows remote attackers to i...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now