2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-25687CRITICAL9.8Pegasus CMS 1.0 contains a remote code execution vulnerability in the extra_fields.php plugin that allows unauthenticate...
CVE-2019-25686HIGH8.7Core FTP 2.0 build 653 contains a denial of service vulnerability in the PBSZ command that allows unauthenticated attack...
CVE-2019-25685Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2019-25684HIGH8.2OpenDocMan 1.3.4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database qu...
CVE-2019-25683MEDIUM5.5FileZilla 3.40.0 contains a denial of service vulnerability in the local search functionality that allows local attacker...
CVE-2019-25682MEDIUM4.3CMSsite 1.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized administra...
CVE-2019-25681HIGH7.8Xlight FTP Server 3.9.1 contains a structured exception handler (SEH) overwrite vulnerability that allows local attacker...
CVE-2019-25680CRITICAL9.8Advance Gift Shop Pro Script 2.0.3 contains an SQL injection vulnerability that allows unauthenticated attackers to exec...
CVE-2019-25679HIGH8.5RealTerm Serial Terminal 2.0.0.70 contains a structured exception handling (SEH) buffer overflow vulnerability in the Ec...
CVE-2019-25678HIGH7.5C4G Basic Laboratory Information System 3.4 contains multiple SQL injection vulnerabilities that allow unauthenticated a...
CVE-2019-25677MEDIUM5.5WinRAR 5.61 contains a denial of service vulnerability that allows local attackers to crash the application by placing a...
CVE-2019-25676CRITICAL9.8Ask Expert Script 3.0.5 contains cross-site scripting and SQL injection vulnerabilities that allow unauthenticated attac...
CVE-2019-25675HIGH7.5eDirectory contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to bypass administrator ...
CVE-2019-25674CRITICAL9.8CMSsite 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries...
CVE-2019-25673HIGH8.8UniSharp Laravel File Manager v2.0.0-alpha7 and v2.0 contain an arbitrary file upload vulnerability that allows authenti...
CVE-2019-25672HIGH8.2PilusCart 1.4.1 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database quer...
CVE-2019-25671HIGH8.8VA MAX 8.3.4 contains a remote code execution vulnerability that allows authenticated attackers to execute arbitrary com...
CVE-2019-25670HIGH7.8River Past Video Cleaner 7.6.3 contains a structured exception handler buffer overflow vulnerability that allows local a...
CVE-2019-25669HIGH8.2qdPM 9.1 contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL c...
CVE-2019-25668HIGH8.2News Website Script 2.0.5 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate da...
CVE-2019-25667MEDIUM5.5TaskInfo 8.2.0.280 contains a local buffer overflow vulnerability that allows attackers to crash the application by supp...
CVE-2019-25666MEDIUM5.5SpotAuditor 3.6.7 contains a local buffer overflow vulnerability in the Base64 Password Decoder component that allows at...
CVE-2019-25665MEDIUM5.5River Past Ringtone Converter 2.7.6.1601 contains a local buffer overflow vulnerability that allows attackers to crash t...
CVE-2019-25664HIGH7.1SuiteCRM 7.10.7 contains a time-based SQL injection vulnerability in the record parameter of the Users module DetailView...
CVE-2019-25663HIGH7.1SuiteCRM 7.10.7 contains a SQL injection vulnerability that allows authenticated attackers to manipulate database querie...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now