2019 CVE Vulnerabilities

17,624 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-25212MEDIUM4.9The video carousel slider with lightbox plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in al...
CVE-2019-6198HIGH7.8A vulnerability was reported in Lenovo PC Manager prior to version 2.8.90.11211 that could allow a local attacker to esc...
CVE-2019-6197HIGH7.8A vulnerability was reported in Lenovo PC Manager prior to version 2.8.90.11211 that could allow a local attacker to esc...
CVE-2019-6185——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2019-6174——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2019-6164——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2019-6162——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2019-19761——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2019-19760——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2019-19759——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2019-25154CRITICAL9.6Inappropriate implementation in iframe in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially p...
CVE-2019-16641HIGH8.4An issue was found on the Ruijie EG-2000 series gateway. There is a buffer overflow in client.so. Consequently, an attac...
CVE-2019-16640HIGH7.5An issue was found in upload.php on the Ruijie EG-2000 series gateway. A parameter passed to the class UploadFile is mis...
CVE-2019-16639CRITICAL9.8An issue was found on the Ruijie EG-2000 series gateway. There is a newcli.php API interface without access control, whi...
CVE-2019-16638HIGH7.5An issue was found on the Ruijie EG-2000 series gateway. An attacker can easily dump cleartext stored passwords in /data...
CVE-2019-25211CRITICAL9.1parseWildcardRules in Gin-Gonic CORS middleware before 1.6.0 mishandles a wildcard at the end of an origin string, e.g.,...
CVE-2019-15798——Rejected reason: CVE ID was once reserved, but never used.
CVE-2019-15797——Rejected reason: CVE ID was once reserved, but never used.
CVE-2019-19755CRITICAL9.1ethOS through 1.3.3 ships with SSH host keys baked into the installation image, which allows man-in-the-middle attacks a...
CVE-2019-19754MEDIUM5.7HiveOS through 0.6-102@191212 ships with SSH host keys baked into the installation image, which allows man-in-the-middle...
CVE-2019-19753CRITICAL9.1SimpleMiningOS through v1259 ships with SSH host keys baked into the installation image, which allows man-in-the-middle ...
CVE-2019-19752CRITICAL9.8nvOC through 3.2 ships with SSH host keys baked into the installation image, which allows man-in-the-middle attacks and ...
CVE-2019-19751MEDIUM5.6easyMINE before 2019-12-05 ships with SSH host keys baked into the installation image, which allows man-in-the-middle at...
CVE-2019-6268HIGH7.5RAD SecFlow-2 devices with Hardware 0202, Firmware 4.1.01.63, and U-Boot 2010.12 allow URIs beginning with /.. for Direc...
CVE-2019-25210MEDIUM6.5An issue was discovered in Cloud Native Computing Foundation (CNCF) Helm through 3.13.3. It displays values of secrets w...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now