2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-5315HIGH7.2A command injection vulnerability is present in the web management interface of ArubaOS that permits an authenticated us...
CVE-2019-5314MEDIUM6.1Some web components in the ArubaOS software are vulnerable to HTTP Response splitting (CRLF injection) and Reflected XSS...
CVE-2019-16293HIGH8.8The Create Discoveries feature of Open-AudIT before 3.2.0 allows an authenticated attacker to execute arbitrary OS comma...
CVE-2019-13923CRITICAL9.6A vulnerability has been identified in IE/WSN-PA Link WirelessHART Gateway (All versions). The integrated configuration ...
CVE-2019-13922LOW2.7A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). An attacker with administ...
CVE-2019-13920MEDIUM4.3A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). Some parts of the web app...
CVE-2019-13919MEDIUM4.3A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). Some pages that should on...
CVE-2019-13918CRITICAL9.8A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). The web interface has no ...
CVE-2019-13548CRITICAL9.8CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted http or https reque...
CVE-2019-13532HIGH7.5CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted http or https reque...
CVE-2019-10937HIGH7.5A vulnerability has been identified in SIMATIC TDC CP51M1 (All versions < V1.1.7). An attacker with network access to th...
CVE-2019-16289MEDIUM5.4The insert-php (aka Woody ad snippets) plugin before 2.2.8 for WordPress allows authenticated XSS via the winp_item para...
CVE-2019-16288HIGH7.5On Tenda N301 wireless routers, a long string in the wifiSSID parameter of a goform/setWifi POST request causes the devi...
CVE-2019-3646MEDIUM6.5DLL Search Order Hijacking vulnerability in Microsoft Windows client in McAfee Total Protection (MTP) Free Antivirus Tri...
CVE-2019-15031MEDIUM4.4In the Linux kernel through 5.2.14 on the powerpc platform, a local user can read vector registers of other users' proce...
CVE-2019-15030MEDIUM4.4In the Linux kernel through 5.2.14 on the powerpc platform, a local user can read vector registers of other users' proce...
CVE-2019-13364CRITICAL9.6admin.php?page=account_billing in Piwigo 2.9.5 has XSS via the vat&#95;number, billing&#95;name, company, or billing&#95...
CVE-2019-13363CRITICAL9.6admin.php?page=notification_by_mail in Piwigo 2.9.5 has XSS via the nbm&#95;send&#95;html&#95;mail, nbm&#95;send&#95;mai...
CVE-2019-12922MEDIUM6.5A CSRF issue in phpMyAdmin 4.9.0.1 allows deletion of any server in the Setup page.
CVE-2019-12517MEDIUM6.1An XSS issue was discovered in the slickquiz plugin through 1.3.7.1 for WordPress. The save_quiz_score functionality ava...
CVE-2019-12516HIGH8.8The slickquiz plugin through 1.3.7.1 for WordPress allows SQL Injection by Subscriber users, as demonstrated by a /wp-ad...
CVE-2019-16277HIGH7.8PicoC 2.1 has a heap-based buffer overflow in StringStrcpy in cstdlib/string.c when called from ExpressionParseFunctionC...
CVE-2019-16275MEDIUM6.5hostapd before 2.10 and wpa_supplicant before 2.10 allow an incorrect indication of disconnection in certain situations ...
CVE-2019-13534HIGH7.2Philips IntelliVue WLAN, portable patient monitors, WLAN Version A, Firmware A.03.09, WLAN Version A, Firmware A.03.09, ...
CVE-2019-13530HIGH7.2Philips IntelliVue WLAN, portable patient monitors, WLAN Version A, Firmware A.03.09, WLAN Version A, Firmware A.03.09, ...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now