2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-15866The crelly-slider plugin before 1.3.5 for WordPress has arbitrary file upload via a PHP file inside a ZIP archive to wp_...
CVE-2019-15865The breadcrumbs-by-menu plugin before 1.0.3 for WordPress has CSRF.
CVE-2019-15864The breadcrumbs-by-menu plugin before 1.0.3 for WordPress has XSS.
CVE-2019-15863The ConvertPlus plugin before 3.4.5 for WordPress has an unintended account creation (with the none role) via a request ...
CVE-2019-15043In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run ...
CVE-2019-15860Xpdf 2.00 allows a SIGSEGV in XRef::constructXRef in XRef.cc. NOTE: 2.00 is a version from November 2002.
CVE-2019-15858HIGH8.8admin/includes/class.import.snippet.php in the "Woody ad snippets" plugin before 2.2.5 for WordPress allows unauthentica...
CVE-2019-15851Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-13590. Reason: This candidate is a reservation d...
CVE-2019-15847HIGH7.5The POWER9 backend in GNU Compiler Collection (GCC) before version 10 could optimize multiple calls of the __builtin_dar...
CVE-2019-15842The easy-pdf-restaurant-menu-upload plugin before 1.1.2 for WordPress has XSS.
CVE-2019-15841The facebook-for-woocommerce plugin before 1.9.15 for WordPress has CSRF via ajax_woo_infobanner_post_click, ajax_woo_in...
CVE-2019-15840The facebook-for-woocommerce plugin before 1.9.14 for WordPress has CSRF.
CVE-2019-15839The sina-extension-for-elementor plugin before 2.2.1 for WordPress has local file inclusion.
CVE-2019-15838The custom-404-pro plugin before 3.2.8 for WordPress has reflected XSS, a different vulnerability than CVE-2019-14789.
CVE-2019-15837The webp-express plugin before 0.14.8 for WordPress has stored XSS.
CVE-2019-15836The wp-ultimate-recipe plugin before 3.12.7 for WordPress has stored XSS.
CVE-2019-15835The wp-better-permalinks plugin before 3.0.5 for WordPress has CSRF.
CVE-2019-15834The webp-converter-for-media plugin before 1.0.3 for WordPress has CSRF.
CVE-2019-15630Directory Traversal in APIkit, HTTP connector, and OAuth2 Provider components in MuleSoft Mule Runtime 3.2.0 and higher ...
CVE-2019-12810A memory corruption vulnerability exists in the .PSD parsing functionality of ALSee v5.3 ~ v8.39. A specially crafted .P...
CVE-2019-2390HIGH7.8An unprivileged user or program on Microsoft Windows which can create OpenSSL configuration files in a fixed location ma...
CVE-2019-2389MEDIUM4.2Incorrect scoping of kill operations in MongoDB Server's packaged SysV init scripts allow users with write access to the...
CVE-2019-15026memcached 1.5.16, when UNIX sockets are used, has a stack-based buffer over-read in conn_to_str in memcached.c.
CVE-2019-15833MEDIUM6.1The simple-mail-address-encoder plugin before 1.7 for WordPress has reflected XSS.
CVE-2019-15832The visitors-traffic-real-time-statistics plugin before 1.13 for WordPress has CSRF.

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now