2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-15892An issue was discovered in Varnish Cache before 6.0.4 LTS, and 6.1.x and 6.2.x before 6.2.1. An HTTP/1 parsing failure a...
CVE-2019-5480A path traversal vulnerability in <= v0.9.7 of statichttpserver npm module allows attackers to list files in arbitrary f...
CVE-2019-5479HIGH7.5An unintended require vulnerability in <v0.5.5 larvitbase-api may allow an attacker to load arbitrary non-production cod...
CVE-2019-5478MEDIUM5.5A weakness was found in Encrypt Only boot mode in Zynq UltraScale+ devices. This could lead to an adversary being able t...
CVE-2019-5475The Nexus Yum Repository Plugin in v2 is vulnerable to Remote Code Execution when instances using CommandLineExecutor.ja...
CVE-2019-6182MEDIUM4.9A stored CSV Injection vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.5.0 that c...
CVE-2019-6181MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior...
CVE-2019-6180MEDIUM4.8A stored cross-site scripting (XSS) vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to...
CVE-2019-6179HIGH7.5An XML External Entity (XXE) processing vulnerability was reported in Lenovo XClarity Administrator (LXCA) prior to vers...
CVE-2019-1125MEDIUM5.6An information disclosure vulnerability exists when certain central processing units (CPU) speculatively access memory. ...
CVE-2019-15889MEDIUM6.1The download-manager plugin before 2.9.94 for WordPress has XSS via the category shortcode feature, as demonstrated by t...
CVE-2019-14261An issue was discovered on ABUS Secvest FUAA50000 3.01.01 devices. Due to an insufficient implementation of jamming dete...
CVE-2019-3754MEDIUM4.7Dell EMC Unity Operating Environment versions prior to 5.0.0.0.5.116, Dell EMC UnityVSA versions prior to 5.0.0.0.5.116 ...
CVE-2019-3751MEDIUM6.4Dell EMC Enterprise Copy Data Management (eCDM) versions 1.0, 1.1, 2.0, 2.1, and 3.0 contain a certificate validation vu...
CVE-2019-14817HIGH7.8A flaw was found in, ghostscript versions prior to 9.50, in the .pdfexectoken and other procedures where it did not prop...
CVE-2019-14811HIGH7.8A flaw was found in, ghostscript versions prior to 9.50, in the .pdf_hook_DSC_Creator procedure where it did not properl...
CVE-2019-13156HIGH7.5NDrive(1.2.2).sys in Naver Cloud Explorer has a stack-based buffer overflow, which allows attackers to cause a denial of...
CVE-2019-10197MEDIUM6.5A flaw was found in samba versions 4.9.x up to 4.9.13, samba 4.10.x up to 4.10.8 and samba 4.11.x up to 4.11.0rc3, when ...
CVE-2019-15873The profilegrid-user-profiles-groups-and-communities plugin before 2.8.6 for WordPress has remote code execution via an ...
CVE-2019-15872The LoginPress plugin before 1.1.4 for WordPress has SQL injection via an import of settings.
CVE-2019-15871The LoginPress plugin before 1.1.4 for WordPress has no capability check for updates to settings.
CVE-2019-15870The CarSpot theme before 2.1.7 for WordPress has stored XSS via the Phone Number field.
CVE-2019-15869The JobCareer theme before 2.5.1 for WordPress has stored XSS.
CVE-2019-15868The affiliates-manager plugin before 2.6.6 for WordPress has CSRF.
CVE-2019-15867The slick-popup plugin before 1.7.2 for WordPress has a hardcoded OmakPass13# password for the slickpopupteam account, a...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now