2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-15866 | — | — | 2.0% | Sep 3, 2019 | The crelly-slider plugin before 1.3.5 for WordPress has arbitrary file upload via a PHP file inside a ZIP archive to wp_... |
| CVE-2019-15865 | — | — | 0.7% | Sep 3, 2019 | The breadcrumbs-by-menu plugin before 1.0.3 for WordPress has CSRF. |
| CVE-2019-15864 | — | — | 0.9% | Sep 3, 2019 | The breadcrumbs-by-menu plugin before 1.0.3 for WordPress has XSS. |
| CVE-2019-15863 | — | — | 1.6% | Sep 3, 2019 | The ConvertPlus plugin before 3.4.5 for WordPress has an unintended account creation (with the none role) via a request ... |
| CVE-2019-15043 | — | — | 63.4% | Sep 3, 2019 | In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run ... |
| CVE-2019-15860 | — | — | 0.9% | Sep 3, 2019 | Xpdf 2.00 allows a SIGSEGV in XRef::constructXRef in XRef.cc. NOTE: 2.00 is a version from November 2002. |
| CVE-2019-15858 | HIGH | 8.8 | 20.8% | Sep 3, 2019 | admin/includes/class.import.snippet.php in the "Woody ad snippets" plugin before 2.2.5 for WordPress allows unauthentica... |
| CVE-2019-15851 | — | — | — | Sep 3, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-13590. Reason: This candidate is a reservation d... |
| CVE-2019-15847 | HIGH | 7.5 | 3.2% | Sep 2, 2019 | The POWER9 backend in GNU Compiler Collection (GCC) before version 10 could optimize multiple calls of the __builtin_dar... |
| CVE-2019-15842 | — | — | 0.9% | Aug 30, 2019 | The easy-pdf-restaurant-menu-upload plugin before 1.1.2 for WordPress has XSS. |
| CVE-2019-15841 | — | — | 0.7% | Aug 30, 2019 | The facebook-for-woocommerce plugin before 1.9.15 for WordPress has CSRF via ajax_woo_infobanner_post_click, ajax_woo_in... |
| CVE-2019-15840 | — | — | 0.7% | Aug 30, 2019 | The facebook-for-woocommerce plugin before 1.9.14 for WordPress has CSRF. |
| CVE-2019-15839 | — | — | 2.4% | Aug 30, 2019 | The sina-extension-for-elementor plugin before 2.2.1 for WordPress has local file inclusion. |
| CVE-2019-15838 | — | — | 0.9% | Aug 30, 2019 | The custom-404-pro plugin before 3.2.8 for WordPress has reflected XSS, a different vulnerability than CVE-2019-14789. |
| CVE-2019-15837 | — | — | 0.8% | Aug 30, 2019 | The webp-express plugin before 0.14.8 for WordPress has stored XSS. |
| CVE-2019-15836 | — | — | 0.8% | Aug 30, 2019 | The wp-ultimate-recipe plugin before 3.12.7 for WordPress has stored XSS. |
| CVE-2019-15835 | — | — | 0.7% | Aug 30, 2019 | The wp-better-permalinks plugin before 3.0.5 for WordPress has CSRF. |
| CVE-2019-15834 | — | — | 0.7% | Aug 30, 2019 | The webp-converter-for-media plugin before 1.0.3 for WordPress has CSRF. |
| CVE-2019-15630 | — | — | 3.0% | Aug 30, 2019 | Directory Traversal in APIkit, HTTP connector, and OAuth2 Provider components in MuleSoft Mule Runtime 3.2.0 and higher ... |
| CVE-2019-12810 | — | — | 1.2% | Aug 30, 2019 | A memory corruption vulnerability exists in the .PSD parsing functionality of ALSee v5.3 ~ v8.39. A specially crafted .P... |
| CVE-2019-2390 | HIGH | 7.8 | 1.0% | Aug 30, 2019 | An unprivileged user or program on Microsoft Windows which can create OpenSSL configuration files in a fixed location ma... |
| CVE-2019-2389 | MEDIUM | 4.2 | 0.3% | Aug 30, 2019 | Incorrect scoping of kill operations in MongoDB Server's packaged SysV init scripts allow users with write access to the... |
| CVE-2019-15026 | — | — | 2.6% | Aug 30, 2019 | memcached 1.5.16, when UNIX sockets are used, has a stack-based buffer over-read in conn_to_str in memcached.c. |
| CVE-2019-15833 | MEDIUM | 6.1 | 1.0% | Aug 30, 2019 | The simple-mail-address-encoder plugin before 1.7 for WordPress has reflected XSS. |
| CVE-2019-15832 | — | — | 0.8% | Aug 30, 2019 | The visitors-traffic-real-time-statistics plugin before 1.13 for WordPress has CSRF. |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now