2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-25687 | CRITICAL | 9.8 | 1.4% | Apr 5, 2026 | Pegasus CMS 1.0 contains a remote code execution vulnerability in the extra_fields.php plugin that allows unauthenticate... |
| CVE-2019-25686 | HIGH | 8.7 | 0.5% | Apr 5, 2026 | Core FTP 2.0 build 653 contains a denial of service vulnerability in the PBSZ command that allows unauthenticated attack... |
| CVE-2019-25685 | — | — | — | Apr 5, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2019-25684 | HIGH | 8.2 | 0.3% | Apr 5, 2026 | OpenDocMan 1.3.4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database qu... |
| CVE-2019-25683 | MEDIUM | 5.5 | 0.2% | Apr 5, 2026 | FileZilla 3.40.0 contains a denial of service vulnerability in the local search functionality that allows local attacker... |
| CVE-2019-25682 | MEDIUM | 4.3 | 0.1% | Apr 5, 2026 | CMSsite 1.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized administra... |
| CVE-2019-25681 | HIGH | 7.8 | 0.2% | Apr 5, 2026 | Xlight FTP Server 3.9.1 contains a structured exception handler (SEH) overwrite vulnerability that allows local attacker... |
| CVE-2019-25680 | CRITICAL | 9.8 | 0.4% | Apr 5, 2026 | Advance Gift Shop Pro Script 2.0.3 contains an SQL injection vulnerability that allows unauthenticated attackers to exec... |
| CVE-2019-25679 | HIGH | 8.5 | 0.3% | Apr 5, 2026 | RealTerm Serial Terminal 2.0.0.70 contains a structured exception handling (SEH) buffer overflow vulnerability in the Ec... |
| CVE-2019-25678 | HIGH | 7.5 | 0.3% | Apr 5, 2026 | C4G Basic Laboratory Information System 3.4 contains multiple SQL injection vulnerabilities that allow unauthenticated a... |
| CVE-2019-25677 | MEDIUM | 5.5 | 0.4% | Apr 5, 2026 | WinRAR 5.61 contains a denial of service vulnerability that allows local attackers to crash the application by placing a... |
| CVE-2019-25676 | CRITICAL | 9.8 | 0.5% | Apr 5, 2026 | Ask Expert Script 3.0.5 contains cross-site scripting and SQL injection vulnerabilities that allow unauthenticated attac... |
| CVE-2019-25675 | HIGH | 7.5 | 0.5% | Apr 5, 2026 | eDirectory contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to bypass administrator ... |
| CVE-2019-25674 | CRITICAL | 9.8 | 0.4% | Apr 5, 2026 | CMSsite 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries... |
| CVE-2019-25673 | HIGH | 8.8 | 0.4% | Apr 5, 2026 | UniSharp Laravel File Manager v2.0.0-alpha7 and v2.0 contain an arbitrary file upload vulnerability that allows authenti... |
| CVE-2019-25672 | HIGH | 8.2 | 0.4% | Apr 5, 2026 | PilusCart 1.4.1 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database quer... |
| CVE-2019-25671 | HIGH | 8.8 | 0.7% | Apr 5, 2026 | VA MAX 8.3.4 contains a remote code execution vulnerability that allows authenticated attackers to execute arbitrary com... |
| CVE-2019-25670 | HIGH | 7.8 | 0.2% | Apr 5, 2026 | River Past Video Cleaner 7.6.3 contains a structured exception handler buffer overflow vulnerability that allows local a... |
| CVE-2019-25669 | HIGH | 8.2 | 0.3% | Apr 5, 2026 | qdPM 9.1 contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL c... |
| CVE-2019-25668 | HIGH | 8.2 | 0.4% | Apr 5, 2026 | News Website Script 2.0.5 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate da... |
| CVE-2019-25667 | MEDIUM | 5.5 | 0.2% | Apr 5, 2026 | TaskInfo 8.2.0.280 contains a local buffer overflow vulnerability that allows attackers to crash the application by supp... |
| CVE-2019-25666 | MEDIUM | 5.5 | 0.2% | Apr 5, 2026 | SpotAuditor 3.6.7 contains a local buffer overflow vulnerability in the Base64 Password Decoder component that allows at... |
| CVE-2019-25665 | MEDIUM | 5.5 | 0.2% | Apr 5, 2026 | River Past Ringtone Converter 2.7.6.1601 contains a local buffer overflow vulnerability that allows attackers to crash t... |
| CVE-2019-25664 | HIGH | 7.1 | 0.3% | Apr 5, 2026 | SuiteCRM 7.10.7 contains a time-based SQL injection vulnerability in the record parameter of the Users module DetailView... |
| CVE-2019-25663 | HIGH | 7.1 | 0.3% | Apr 5, 2026 | SuiteCRM 7.10.7 contains a SQL injection vulnerability that allows authenticated attackers to manipulate database querie... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now