2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-15892 | — | — | 5.7% | Sep 3, 2019 | An issue was discovered in Varnish Cache before 6.0.4 LTS, and 6.1.x and 6.2.x before 6.2.1. An HTTP/1 parsing failure a... |
| CVE-2019-5480 | — | — | 1.6% | Sep 3, 2019 | A path traversal vulnerability in <= v0.9.7 of statichttpserver npm module allows attackers to list files in arbitrary f... |
| CVE-2019-5479 | HIGH | 7.5 | 1.3% | Sep 3, 2019 | An unintended require vulnerability in <v0.5.5 larvitbase-api may allow an attacker to load arbitrary non-production cod... |
| CVE-2019-5478 | MEDIUM | 5.5 | 0.2% | Sep 3, 2019 | A weakness was found in Encrypt Only boot mode in Zynq UltraScale+ devices. This could lead to an adversary being able t... |
| CVE-2019-5475 | — | — | 18.4% | Sep 3, 2019 | The Nexus Yum Repository Plugin in v2 is vulnerable to Remote Code Execution when instances using CommandLineExecutor.ja... |
| CVE-2019-6182 | MEDIUM | 4.9 | 0.7% | Sep 3, 2019 | A stored CSV Injection vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.5.0 that c... |
| CVE-2019-6181 | MEDIUM | 6.1 | 0.8% | Sep 3, 2019 | A reflected cross-site scripting (XSS) vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior... |
| CVE-2019-6180 | MEDIUM | 4.8 | 0.7% | Sep 3, 2019 | A stored cross-site scripting (XSS) vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to... |
| CVE-2019-6179 | HIGH | 7.5 | 1.4% | Sep 3, 2019 | An XML External Entity (XXE) processing vulnerability was reported in Lenovo XClarity Administrator (LXCA) prior to vers... |
| CVE-2019-1125 | MEDIUM | 5.6 | 4.5% | Sep 3, 2019 | An information disclosure vulnerability exists when certain central processing units (CPU) speculatively access memory. ... |
| CVE-2019-15889 | MEDIUM | 6.1 | 12.5% | Sep 3, 2019 | The download-manager plugin before 2.9.94 for WordPress has XSS via the category shortcode feature, as demonstrated by t... |
| CVE-2019-14261 | — | — | 2.5% | Sep 3, 2019 | An issue was discovered on ABUS Secvest FUAA50000 3.01.01 devices. Due to an insufficient implementation of jamming dete... |
| CVE-2019-3754 | MEDIUM | 4.7 | 1.1% | Sep 3, 2019 | Dell EMC Unity Operating Environment versions prior to 5.0.0.0.5.116, Dell EMC UnityVSA versions prior to 5.0.0.0.5.116 ... |
| CVE-2019-3751 | MEDIUM | 6.4 | 0.7% | Sep 3, 2019 | Dell EMC Enterprise Copy Data Management (eCDM) versions 1.0, 1.1, 2.0, 2.1, and 3.0 contain a certificate validation vu... |
| CVE-2019-14817 | HIGH | 7.8 | 2.0% | Sep 3, 2019 | A flaw was found in, ghostscript versions prior to 9.50, in the .pdfexectoken and other procedures where it did not prop... |
| CVE-2019-14811 | HIGH | 7.8 | 3.8% | Sep 3, 2019 | A flaw was found in, ghostscript versions prior to 9.50, in the .pdf_hook_DSC_Creator procedure where it did not properl... |
| CVE-2019-13156 | HIGH | 7.5 | 1.0% | Sep 3, 2019 | NDrive(1.2.2).sys in Naver Cloud Explorer has a stack-based buffer overflow, which allows attackers to cause a denial of... |
| CVE-2019-10197 | MEDIUM | 6.5 | 3.2% | Sep 3, 2019 | A flaw was found in samba versions 4.9.x up to 4.9.13, samba 4.10.x up to 4.10.8 and samba 4.11.x up to 4.11.0rc3, when ... |
| CVE-2019-15873 | — | — | 3.9% | Sep 3, 2019 | The profilegrid-user-profiles-groups-and-communities plugin before 2.8.6 for WordPress has remote code execution via an ... |
| CVE-2019-15872 | — | — | 2.2% | Sep 3, 2019 | The LoginPress plugin before 1.1.4 for WordPress has SQL injection via an import of settings. |
| CVE-2019-15871 | — | — | 0.9% | Sep 3, 2019 | The LoginPress plugin before 1.1.4 for WordPress has no capability check for updates to settings. |
| CVE-2019-15870 | — | — | 0.7% | Sep 3, 2019 | The CarSpot theme before 2.1.7 for WordPress has stored XSS via the Phone Number field. |
| CVE-2019-15869 | — | — | 0.7% | Sep 3, 2019 | The JobCareer theme before 2.5.1 for WordPress has stored XSS. |
| CVE-2019-15868 | — | — | 0.7% | Sep 3, 2019 | The affiliates-manager plugin before 2.6.6 for WordPress has CSRF. |
| CVE-2019-15867 | — | — | 2.1% | Sep 3, 2019 | The slick-popup plugin before 1.7.2 for WordPress has a hardcoded OmakPass13# password for the slickpopupteam account, a... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now