2019 CVE Vulnerabilities

17,624 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-25287HIGH8.5Adaware Web Companion version 4.8.2078.3950 contains an unquoted service path vulnerability in the WCAssistantService th...
CVE-2019-25286HIGH8.5GCafé 3.0 contains an unquoted service path vulnerability in the gbClientService that allows local attackers to potentia...
CVE-2019-25285HIGH8.5Alps Pointing-device Controller 8.1202.1711.04 contains an unquoted service path vulnerability in the ApHidMonitorServic...
CVE-2019-25283HIGH8.5Shrew Soft VPN Client 2.2.2 contains an unquoted service path vulnerability that allows local users to execute arbitrary...
CVE-2019-25281HIGH8.5NCP Secure Entry Client 9.2 contains an unquoted service path vulnerability in multiple Windows services that allows loc...
CVE-2019-25276HIGH8.5Studio 5000 Logix Designer 30.01.00 contains an unquoted service path vulnerability in the FactoryTalk Activation Servic...
CVE-2019-25275HIGH8.5BartVPN 1.2.2 contains an unquoted service path vulnerability in the BartVPNService that allows local attackers to poten...
CVE-2019-25274HIGH8.5ProShow Producer 9.0.3797 contains an unquoted service path vulnerability in the ScsiAccess service that allows local at...
CVE-2019-25273HIGH8.5Easy-Hide-IP 5.0.0.3 contains an unquoted service path vulnerability in the EasyRedirect service that allows local attac...
CVE-2019-25272HIGH8.5TexasSoft CyberPlanet 6.4.131 contains an unquoted service path vulnerability in the CCSrvProxy service that allows loca...
CVE-2019-25271HIGH8.5NETGATE Data Backup 3.0.620 contains an unquoted service path vulnerability in its NGDatBckpSrv Windows service configur...
CVE-2019-25269HIGH8.5Amiti Antivirus 25.0.640 contains an unquoted service path vulnerability in its Windows service configurations. Attacker...
CVE-2019-25267HIGH8.5Wing FTP Server 6.0.7 contains an unquoted service path vulnerability that allows local attackers to potentially execute...
CVE-2019-25260HIGH8.8OXID eShop versions 6.x prior to 6.3.4 contains a SQL injection vulnerability in the 'sorting' parameter that allows att...
CVE-2019-25265MEDIUM6.4Online Inventory Manager 3.2 contains a stored cross-site scripting vulnerability in the group description field of the ...
CVE-2019-25264MEDIUM6.4Snipe-IT 4.7.5 contains a persistent cross-site scripting vulnerability that allows authorized users to upload malicious...
CVE-2019-25263MEDIUM6.4Zendesk SweetHawk Survey 1.6 contains a persistent cross-site scripting vulnerability that allows attackers to inject ma...
CVE-2019-25261HIGH8.5AnyDesk 5.4.0 contains an unquoted service path vulnerability in its Windows service configuration that allows local att...
CVE-2019-25232CRITICAL9.8NetPCLinker 1.0.0.0 contains a buffer overflow vulnerability in the Clients Control Panel DNS/IP field that allows attac...
CVE-2019-25297MEDIUM5.1Poll, Survey & Quiz Maker Plugin by Opinion Stage Wordpress plugin versions prior to 19.6.25 contain a stored cross-site...
CVE-2019-25296CRITICAL9.8The WP Cost Estimation plugin for WordPress is vulnerable to arbitrary file uploads and deletion due to missing file typ...
CVE-2019-25295MEDIUM6.5The WP Cost Estimation plugin for WordPress is vulnerable to Upload Directory Traversal in versions before 9.660 via the...
CVE-2019-25291CRITICAL9.3INIM Electronics Smartliving SmartLAN/G/SI <=6.x contains hard-coded credentials in its Linux distribution image that ca...
CVE-2019-25290MEDIUM6.9Smartliving SmartLAN/G/SI <=6.x contains an unauthenticated server-side request forgery vulnerability in the GetImage fu...
CVE-2019-25289HIGH8.8SmartLiving SmartLAN <=6.x contains an authenticated remote command injection vulnerability in the web.cgi binary throug...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now