2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-15782WebTorrent before 0.107.6 allows XSS in the HTTP server via a title or file name.
CVE-2019-15780CRITICAL9.8The formidable plugin before 4.02.01 for WordPress has unsafe deserialization.
CVE-2019-15777The shapepress-dsgvo plugin before 2.2.19 for WordPress has wp-admin/admin-ajax.php?action=admin-common-settings&admin_e...
CVE-2019-15776The simple-301-redirects-addon-bulk-uploader plugin before 1.2.5 for WordPress has no protection against 301 redirect ru...
CVE-2019-15775The nd-learning plugin before 4.8 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl settin...
CVE-2019-15774The nd-booking plugin before 2.5 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting...
CVE-2019-15773The nd-travel plugin before 1.7 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.
CVE-2019-15772The nd-donations plugin before 1.4 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setti...
CVE-2019-15770The woo-address-book plugin before 1.6.0 for WordPress has save calls without nonce verification checks.
CVE-2019-15769The handl-utm-grabber plugin before 2.6.5 for WordPress has CSRF via add_option and update_option.
CVE-2019-14943An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.1.4. It uses Hard-coded Credentials.
CVE-2019-15767In GNU Chess 6.2.5, there is a stack-based buffer overflow in the cmd_load function in frontend/cmd.cc via a crafted che...
CVE-2019-15759MEDIUM6.5An issue was discovered in Binaryen 1.38.32. Two visitors in ir/ExpressionManipulator.cpp can lead to a NULL pointer der...
CVE-2019-15758MEDIUM6.5An issue was discovered in Binaryen 1.38.32. Missing validation rules in asmjs/asmangle.cpp can lead to an Assertion Fai...
CVE-2019-5530Windows binaries generated with InstallBuilder versions earlier than 19.7.0 are vulnerable to tampering even if they con...
CVE-2019-15757libMirage 3.2.2 in CDemu has a NULL pointer dereference in the NRG parser in parser.c.
CVE-2019-13408HIGH7.5A relative path traversal vulnerability found in Advan VD-1 firmware versions up to 230. It allows attackers to download...
CVE-2019-13407A XSS found in Advan VD-1 firmware versions up to 230. VD-1 responses a path error message when a requested resource was...
CVE-2019-13406A broken access control vulnerability found in Advan VD-1 firmware versions up to 230. An attacker can send a POST reque...
CVE-2019-13405A broken access control vulnerability found in Advan VD-1 firmware version 230 leads to insecure ADB service. An attacke...
CVE-2019-11250MEDIUM6.5The Kubernetes client-go library logs request headers at verbosity levels of 7 or higher. This can disclose credentials ...
CVE-2019-11249MEDIUM6.5The kubectl cp command allows copying files between containers and the user machine. To copy files from a container, Kub...
CVE-2019-11248HIGH8.2The debugging endpoint /debug/pprof is exposed over the unauthenticated Kubelet healthz port. The go pprof endpoint is e...
CVE-2019-11247HIGH8.1The Kubernetes kube-apiserver mistakenly allows access to a cluster-scoped custom resource if the request is made as if ...
CVE-2019-11246MEDIUM6.5The kubectl cp command allows copying files between containers and the user machine. To copy files from a container, Kub...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now