2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-25365 | CRITICAL | 9.8 | 0.5% | Feb 18, 2026 | ChaosPro 2.0 contains a buffer overflow vulnerability in the configuration file path handling that allows attackers to e... |
| CVE-2019-25364 | CRITICAL | 9.8 | 0.8% | Feb 18, 2026 | MailCarrier 2.51 contains a buffer overflow vulnerability in the POP3 USER command that allows remote attackers to execu... |
| CVE-2019-25362 | CRITICAL | 9.8 | 0.7% | Feb 18, 2026 | WMV to AVI MPEG DVD WMV Convertor 4.6.1217 contains a buffer overflow vulnerability that allows attackers to execute arb... |
| CVE-2019-25361 | CRITICAL | 9.8 | 0.6% | Feb 18, 2026 | Ayukov NFTP client 1.71 contains a buffer overflow vulnerability in the SYST command handling that allows remote attacke... |
| CVE-2019-25360 | CRITICAL | 9.8 | 0.7% | Feb 18, 2026 | Aida64 Engineer 6.10.5200 contains a buffer overflow vulnerability in the CSV logging configuration that allows attacker... |
| CVE-2019-25337 | CRITICAL | 9.8 | 0.4% | Feb 12, 2026 | OwnCloud 8.1.8 contains a username enumeration vulnerability that allows remote attackers to discover user accounts by m... |
| CVE-2019-25327 | CRITICAL | 9.8 | 0.5% | Feb 12, 2026 | Prime95 version 29.8 build 6 contains a buffer overflow vulnerability in the user ID input field that allows remote atta... |
| CVE-2019-25322 | CRITICAL | 9.3 | 0.3% | Feb 12, 2026 | Heatmiser Netmonitor 3.03 contains a hardcoded credentials vulnerability in the networkSetup.htm page with predictable a... |
| CVE-2019-25321 | CRITICAL | 9.8 | 0.7% | Feb 12, 2026 | FTP Navigator 8.03 contains a stack overflow vulnerability that allows attackers to execute arbitrary code by overwritin... |
| CVE-2019-25319 | CRITICAL | 9.8 | 0.5% | Feb 12, 2026 | Domain Quester Pro 6.02 contains a stack overflow vulnerability that allows remote attackers to execute arbitrary code b... |
| CVE-2019-25298 | CRITICAL | 9.1 | 0.4% | Feb 6, 2026 | html5_snmp 1.11 contains multiple SQL injection vulnerabilities that allow attackers to manipulate database queries thro... |
| CVE-2019-25232 | CRITICAL | 9.8 | 0.4% | Jan 30, 2026 | NetPCLinker 1.0.0.0 contains a buffer overflow vulnerability in the Clients Control Panel DNS/IP field that allows attac... |
| CVE-2019-25296 | CRITICAL | 9.8 | 0.6% | Jan 8, 2026 | The WP Cost Estimation plugin for WordPress is vulnerable to arbitrary file uploads and deletion due to missing file typ... |
| CVE-2019-25291 | CRITICAL | 9.3 | 0.4% | Jan 8, 2026 | INIM Electronics Smartliving SmartLAN/G/SI <=6.x contains hard-coded credentials in its Linux distribution image that ca... |
| CVE-2019-25282 | CRITICAL | 9.8 | 0.4% | Jan 8, 2026 | V-SOL GPON/EPON OLT Platform v2.03 contains an open redirect vulnerability in the script that allows attackers to manipu... |
| CVE-2019-25278 | CRITICAL | 9.1 | 0.3% | Jan 8, 2026 | FaceSentry Access Control System 6.4.8 contains a cleartext transmission vulnerability that allows remote attackers to i... |
| CVE-2019-25268 | CRITICAL | 9.8 | 0.4% | Jan 8, 2026 | NREL BEopt 2.8.0.0 contains a DLL hijacking vulnerability that allows attackers to load arbitrary libraries by tricking ... |
| CVE-2019-25249 | CRITICAL | 9.8 | 0.4% | Dec 24, 2025 | devolo dLAN 500 AV Wireless+ 3.1.0-1 contains an authentication bypass vulnerability that allows attackers to enable hid... |
| CVE-2019-25241 | CRITICAL | 9.8 | 0.7% | Dec 24, 2025 | FaceSentry Access Control System 6.4.8 contains a critical authentication vulnerability with hard-coded SSH credentials ... |
| CVE-2019-25240 | CRITICAL | 9.8 | 0.4% | Dec 24, 2025 | Rifatron 5brid DVR contains an unauthenticated vulnerability in the animate.cgi script that allows unauthorized access t... |
| CVE-2019-25237 | CRITICAL | 9.8 | 0.3% | Dec 24, 2025 | V-SOL GPON/EPON OLT Platform v2.03 contains a privilege escalation vulnerability that allows normal users to gain admini... |
| CVE-2019-25236 | CRITICAL | 9.8 | 0.4% | Dec 24, 2025 | iSeeQ Hybrid DVR WH-H4 1.03R contains an unauthenticated vulnerability in the get_jpeg script that allows unauthorized a... |
| CVE-2019-25235 | CRITICAL | 9.8 | 0.4% | Dec 24, 2025 | Smartwares HOME easy 1.0.9 contains an authentication bypass vulnerability that allows unauthenticated attackers to acce... |
| CVE-2019-19144 | CRITICAL | 9.8 | 0.7% | Aug 1, 2025 | XML External Entity Injection vulnerability in Quantum DXi6702 2.3.0.3 (11449-53631 Build304) devices via rest/Users?act... |
| CVE-2019-25224 | CRITICAL | 9.8 | 16.7% | Jul 25, 2025 | The WP Database Backup plugin for WordPress is vulnerable to OS Command Injection in versions before 5.2 via the mysqldu... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now