2019 CVE Vulnerabilities

17,624 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-25222MEDIUM4.9The Thumbnail carousel slider plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions...
CVE-2019-1815MEDIUM5.3A security vulnerability was discovered in the local status page functionality of Cisco Meraki’s MX67 and MX68 security ...
CVE-2019-8900MEDIUM6.8A vulnerability in the SecureROM of some Apple devices can be exploited by an unauthenticated local attacker to execute ...
CVE-2019-15002MEDIUM4.3An exploitable CSRF vulnerability exists in Atlassian Jira, from versions 7.6.4 to 8.1.0. The login form doesn’t require...
CVE-2019-15690HIGH8.8LibVNCServer 0.9.12 release and earlier contains heap buffer overflow vulnerability within the HandleCursorShape() funct...
CVE-2019-3309——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is mistakenly publ...
CVE-2019-2483HIGH8.2Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions th...
CVE-2019-25221MEDIUM4.9The Responsive Filterable Portfolio plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all ve...
CVE-2019-17082CRITICAL9Insufficiently Protected Credentials vulnerability in OpenText™ AccuRev allows Authentication Bypass. When installed on ...
CVE-2019-25220HIGH7.5Bitcoin Core before 24.0.1 allows remote attackers to cause a denial of service (daemon crash) via a flood of low-diffic...
CVE-2019-20472MEDIUM6.2An issue was discovered on One2Track 2019-12-08 devices. Any SIM card used with the device cannot have a PIN configured....
CVE-2019-20469MEDIUM4.6An issue was discovered on One2Track 2019-12-08 devices. Confidential information is needlessly stored on the smartwatch...
CVE-2019-20462MEDIUM5.3An issue was discovered on Alecto IVM-100 2019-11-12 devices. The device comes with a serial interface at the board leve...
CVE-2019-20461CRITICAL9.8An issue was discovered on Alecto IVM-100 2019-11-12 devices. The device uses a custom UDP protocol to start and control...
CVE-2019-20460HIGH8.8An issue was discovered on Epson Expression Home XP255 20.08.FM10I8 devices. POST requests don't require (anti-)CSRF tok...
CVE-2019-20459HIGH8.4An issue was discovered on Epson Expression Home XP255 20.08.FM10I8 devices. With the SNMPv1 public community, all value...
CVE-2019-20458HIGH8.8An issue was discovered on Epson Expression Home XP255 20.08.FM10I8 devices. By default, the device comes (and functions...
CVE-2019-20457CRITICAL9.1An issue was discovered on Brother MFC-J491DW C1806180757 devices. The printer's web-interface password hash can be retr...
CVE-2019-25219HIGH7.5Asio C++ Library before 1.13.0 lacks a fallback error code in the case of SSL_ERROR_SYSCALL with no associated error inf...
CVE-2019-25218MEDIUM4.9The Photo Gallery Slideshow & Masonry Tiled Gallery plugin for WordPress is vulnerable to SQL Injection via the 'id' par...
CVE-2019-25217CRITICAL9.8The SiteGround Optimizer plugin for WordPress is vulnerable to authorization bypass leading to Remote Code Execution and...
CVE-2019-25216MEDIUM6.1The Rich Review plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the POST body 'update' parameter i...
CVE-2019-25215HIGH7.3The ARI-Adminer plugin for WordPress is vulnerable to authorization bypass due to a lack of file access controls in near...
CVE-2019-25214MEDIUM6.1The ShopWP plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several REST ...
CVE-2019-25213HIGH7.5The Advanced Access Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read in versions up to,...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now