2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-25079Rejected reason: This candidate is unused by its CNA.
CVE-2019-7819MEDIUM5.5Adobe Acrobat Reader versions 2019.010.20098 and earlier are affected by an out-of-bounds read vulnerability that could ...
CVE-2019-16471HIGH7.8Adobe Acrobat Reader versions 2019.021.20056 and earlier are affected by a Use After Free vulnerability that could resul...
CVE-2019-16470HIGH7.8Adobe Acrobat Reader versions 2019.021.20056 and earlier are affected by a Stack-based Buffer Overflow vulnerability tha...
CVE-2019-13690CRITICAL9.6Inappropriate implementation in OS in Google Chrome on ChromeOS prior to 75.0.3770.80 allowed a remote attacker to perfo...
CVE-2019-13689HIGH7.8Inappropriate implementation in OS in Google Chrome on ChromeOS prior to 75.0.3770.80 allowed a remote attacker to perfo...
CVE-2019-25152MEDIUM6.1The Abandoned Cart Lite for WooCommerce and Abandoned Cart Pro for WooCommerce plugins for WordPress are vulnerable to S...
CVE-2019-25136CRITICAL10A compromised child process could have injected XBL Bindings into privileged CSS rules, resulting in arbitrary code exec...
CVE-2019-16283HIGH7.8A potential security vulnerability has been identified with a version of the HP Softpaq installer that can lead to arbit...
CVE-2019-25151MEDIUM4.3The Funnel Builder plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the a...
CVE-2019-25150HIGH8.8The Email Templates plugin for WordPress is vulnerable to HTML Injection in versions up to, and including, 1.3. This mak...
CVE-2019-25149MEDIUM4.3The Gallery Images Ape plugin for WordPress is vulnerable to Arbitrary Plugin Deactivation in versions up to, and includ...
CVE-2019-25148MEDIUM6.1The WP HTML Mail plugin for WordPress is vulnerable to HTML injection in versions up to, and including, 2.9.0.3 due to i...
CVE-2019-25147MEDIUM6.1The Pretty Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting via various IP headers as well as the...
CVE-2019-25146MEDIUM6.1The DELUCKS SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the saveSettings() function that h...
CVE-2019-25145MEDIUM6.1The Contact Form & SMTP Plugin by PirateForms plugin for WordPress is vulnerable to HTML injection in the ‘public/class-...
CVE-2019-25144MEDIUM6.1The WP HTML Mail plugin for WordPress is vulnerable to HTML injection in versions up to, and including, 2.2.10 due to in...
CVE-2019-25143MEDIUM4.3The GDPR Cookie Compliance plugin for WordPress is vulnerable to authorization bypass due to a missing capability check ...
CVE-2019-25142HIGH8.8The Mesmerize & Materialis themes for WordPress are vulnerable to authenticated options change in versions up to, and in...
CVE-2019-25141CRITICAL9.8The Easy WP SMTP plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.3.9. Thi...
CVE-2019-25140MEDIUM6.1The WordPress Coming Soon Page & Maintenance Mode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ...
CVE-2019-25139MEDIUM5.3The Coming Soon Page & Maintenance Mode plugin for WordPress is vulnerable to unauthenticated settings reset in versions...
CVE-2019-25138CRITICAL9.8The User Submitted Posts plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validatio...
CVE-2019-19791CRITICAL9.8In LemonLDAP::NG (aka lemonldap-ng) before 2.0.7, the default Apache HTTP Server configuration does not properly restric...
CVE-2019-25137HIGH7.2Umbraco CMS 4.11.8 through 7.15.10, and 7.12.4, allows Remote Code Execution by authenticated administrators via msxsl:s...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now