2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-11030 | — | — | 2.0% | Aug 22, 2019 | Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the Mirasys.Common.Utils.Security.DataCrypt method in Common.... |
| CVE-2019-11029 | — | — | 2.4% | Aug 22, 2019 | Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the Download() method of AutoUpdateService in SMServer.exe, l... |
| CVE-2019-11013 | — | — | 24.0% | Aug 22, 2019 | Nimble Streamer 3.0.2-2 through 3.5.4-9 has a ../ directory traversal vulnerability. Successful exploitation could allow... |
| CVE-2019-5635 | HIGH | 7.5 | 0.4% | Aug 22, 2019 | A cleartext transmission of sensitive information vulnerability is present in Hickory Smart Ethernet Bridge from Belwith... |
| CVE-2019-5634 | MEDIUM | 6.5 | 0.4% | Aug 22, 2019 | An inclusion of sensitive information in log files vulnerability is present in Hickory Smart for Android mobile devices ... |
| CVE-2019-5633 | MEDIUM | 5.5 | 0.4% | Aug 22, 2019 | An insecure storage of sensitive information vulnerability is present in Hickory Smart for iOS mobile devices from Belwi... |
| CVE-2019-5632 | MEDIUM | 5.5 | 0.4% | Aug 22, 2019 | An insecure storage of sensitive information vulnerability is present in Hickory Smart for Android mobile devices from B... |
| CVE-2019-15324 | — | — | 3.6% | Aug 22, 2019 | The ad-inserter plugin before 2.4.22 for WordPress has remote code execution. |
| CVE-2019-15323 | HIGH | 7.5 | 2.0% | Aug 22, 2019 | The ad-inserter plugin before 2.4.20 for WordPress has path traversal. |
| CVE-2019-15322 | — | — | 2.0% | Aug 22, 2019 | The shortcode-factory plugin before 2.8 for WordPress has Local File Inclusion. |
| CVE-2019-15321 | — | — | 2.1% | Aug 22, 2019 | The option-tree plugin before 2.7.3 for WordPress has Object Injection because serialized classes are mishandled. |
| CVE-2019-15320 | — | — | 2.1% | Aug 22, 2019 | The option-tree plugin before 2.7.3 for WordPress has Object Injection because the + character is mishandled. |
| CVE-2019-15319 | — | — | 2.1% | Aug 22, 2019 | The option-tree plugin before 2.7.0 for WordPress has Object Injection by leveraging a valid nonce. |
| CVE-2019-15318 | — | — | 2.2% | Aug 22, 2019 | The yikes-inc-easy-mailchimp-extender plugin before 6.5.3 for WordPress has code injection via the admin input field. |
| CVE-2019-15317 | — | — | 1.2% | Aug 22, 2019 | The give plugin before 2.4.7 for WordPress has XSS via a donor name. |
| CVE-2019-15314 | — | — | 0.9% | Aug 22, 2019 | tiki/tiki-upload_file.php in Tiki 18.4 allows remote attackers to upload JavaScript code that is executed upon visiting ... |
| CVE-2019-14511 | — | — | 2.0% | Aug 22, 2019 | Sphinx Technologies Sphinx 3.1.1 by default has no authentication and listens on 0.0.0.0, making it exposed to the inter... |
| CVE-2019-6177 | CRITICAL | 9.8 | 1.1% | Aug 21, 2019 | A vulnerability reported in Lenovo Solution Center version 03.12.003, which is no longer supported, could allow log file... |
| CVE-2019-5638 | HIGH | 8.7 | 1.0% | Aug 21, 2019 | Rapid7 Nexpose versions 6.5.50 and prior suffer from insufficient session expiration when an administrator performs a se... |
| CVE-2019-15316 | — | — | 0.4% | Aug 21, 2019 | Valve Steam Client for Windows through 2019-08-20 has weak folder permissions, leading to privilege escalation (to NT AU... |
| CVE-2019-15315 | — | — | 0.4% | Aug 21, 2019 | Valve Steam Client for Windows through 2019-08-16 allows privilege escalation (to NT AUTHORITY\SYSTEM) because local use... |
| CVE-2019-14686 | — | — | 1.2% | Aug 21, 2019 | A DLL hijacking vulnerability exists in the Trend Micro Security's 2019 consumer family of products (v15) Folder Shield ... |
| CVE-2019-14685 | — | — | 0.6% | Aug 21, 2019 | A local privilege escalation vulnerability exists in Trend Micro Security 2019 (v15.0) in which, if exploited, would all... |
| CVE-2019-13476 | — | — | 6.5% | Aug 21, 2019 | In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.837, XSS in the domain parameter allows a low-privilege user to ... |
| CVE-2019-11603 | HIGH | 7.5 | 2.4% | Aug 21, 2019 | A HTTP Traversal Attack in earlier versions than ProSyst mBS SDK 8.2.6 and Bosch IoT Gateway Software 9.0.2 allows remot... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now