2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-15782 | — | — | 1.5% | Aug 29, 2019 | WebTorrent before 0.107.6 allows XSS in the HTTP server via a title or file name. |
| CVE-2019-15780 | CRITICAL | 9.8 | 2.4% | Aug 29, 2019 | The formidable plugin before 4.02.01 for WordPress has unsafe deserialization. |
| CVE-2019-15777 | — | — | 1.1% | Aug 29, 2019 | The shapepress-dsgvo plugin before 2.2.19 for WordPress has wp-admin/admin-ajax.php?action=admin-common-settings&admin_e... |
| CVE-2019-15776 | — | — | 1.3% | Aug 29, 2019 | The simple-301-redirects-addon-bulk-uploader plugin before 1.2.5 for WordPress has no protection against 301 redirect ru... |
| CVE-2019-15775 | — | — | 1.3% | Aug 29, 2019 | The nd-learning plugin before 4.8 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl settin... |
| CVE-2019-15774 | — | — | 1.7% | Aug 29, 2019 | The nd-booking plugin before 2.5 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting... |
| CVE-2019-15773 | — | — | 1.3% | Aug 29, 2019 | The nd-travel plugin before 1.7 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting. |
| CVE-2019-15772 | — | — | 1.3% | Aug 29, 2019 | The nd-donations plugin before 1.4 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setti... |
| CVE-2019-15770 | — | — | 0.7% | Aug 29, 2019 | The woo-address-book plugin before 1.6.0 for WordPress has save calls without nonce verification checks. |
| CVE-2019-15769 | — | — | 0.8% | Aug 29, 2019 | The handl-utm-grabber plugin before 2.6.5 for WordPress has CSRF via add_option and update_option. |
| CVE-2019-14943 | — | — | 2.0% | Aug 29, 2019 | An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.1.4. It uses Hard-coded Credentials. |
| CVE-2019-15767 | — | — | 1.5% | Aug 29, 2019 | In GNU Chess 6.2.5, there is a stack-based buffer overflow in the cmd_load function in frontend/cmd.cc via a crafted che... |
| CVE-2019-15759 | MEDIUM | 6.5 | 1.3% | Aug 29, 2019 | An issue was discovered in Binaryen 1.38.32. Two visitors in ir/ExpressionManipulator.cpp can lead to a NULL pointer der... |
| CVE-2019-15758 | MEDIUM | 6.5 | 1.2% | Aug 29, 2019 | An issue was discovered in Binaryen 1.38.32. Missing validation rules in asmjs/asmangle.cpp can lead to an Assertion Fai... |
| CVE-2019-5530 | — | — | 0.9% | Aug 29, 2019 | Windows binaries generated with InstallBuilder versions earlier than 19.7.0 are vulnerable to tampering even if they con... |
| CVE-2019-15757 | — | — | 1.6% | Aug 29, 2019 | libMirage 3.2.2 in CDemu has a NULL pointer dereference in the NRG parser in parser.c. |
| CVE-2019-13408 | HIGH | 7.5 | 1.9% | Aug 29, 2019 | A relative path traversal vulnerability found in Advan VD-1 firmware versions up to 230. It allows attackers to download... |
| CVE-2019-13407 | — | — | 1.1% | Aug 29, 2019 | A XSS found in Advan VD-1 firmware versions up to 230. VD-1 responses a path error message when a requested resource was... |
| CVE-2019-13406 | — | — | 1.6% | Aug 29, 2019 | A broken access control vulnerability found in Advan VD-1 firmware versions up to 230. An attacker can send a POST reque... |
| CVE-2019-13405 | — | — | 2.9% | Aug 29, 2019 | A broken access control vulnerability found in Advan VD-1 firmware version 230 leads to insecure ADB service. An attacke... |
| CVE-2019-11250 | MEDIUM | 6.5 | 1.8% | Aug 29, 2019 | The Kubernetes client-go library logs request headers at verbosity levels of 7 or higher. This can disclose credentials ... |
| CVE-2019-11249 | MEDIUM | 6.5 | 3.7% | Aug 29, 2019 | The kubectl cp command allows copying files between containers and the user machine. To copy files from a container, Kub... |
| CVE-2019-11248 | HIGH | 8.2 | 61.1% | Aug 29, 2019 | The debugging endpoint /debug/pprof is exposed over the unauthenticated Kubelet healthz port. The go pprof endpoint is e... |
| CVE-2019-11247 | HIGH | 8.1 | 2.1% | Aug 29, 2019 | The Kubernetes kube-apiserver mistakenly allows access to a cluster-scoped custom resource if the request is made as if ... |
| CVE-2019-11246 | MEDIUM | 6.5 | 3.6% | Aug 29, 2019 | The kubectl cp command allows copying files between containers and the user machine. To copy files from a container, Kub... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now