2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-11030Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the Mirasys.Common.Utils.Security.DataCrypt method in Common....
CVE-2019-11029Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the Download() method of AutoUpdateService in SMServer.exe, l...
CVE-2019-11013Nimble Streamer 3.0.2-2 through 3.5.4-9 has a ../ directory traversal vulnerability. Successful exploitation could allow...
CVE-2019-5635HIGH7.5A cleartext transmission of sensitive information vulnerability is present in Hickory Smart Ethernet Bridge from Belwith...
CVE-2019-5634MEDIUM6.5An inclusion of sensitive information in log files vulnerability is present in Hickory Smart for Android mobile devices ...
CVE-2019-5633MEDIUM5.5An insecure storage of sensitive information vulnerability is present in Hickory Smart for iOS mobile devices from Belwi...
CVE-2019-5632MEDIUM5.5An insecure storage of sensitive information vulnerability is present in Hickory Smart for Android mobile devices from B...
CVE-2019-15324The ad-inserter plugin before 2.4.22 for WordPress has remote code execution.
CVE-2019-15323HIGH7.5The ad-inserter plugin before 2.4.20 for WordPress has path traversal.
CVE-2019-15322The shortcode-factory plugin before 2.8 for WordPress has Local File Inclusion.
CVE-2019-15321The option-tree plugin before 2.7.3 for WordPress has Object Injection because serialized classes are mishandled.
CVE-2019-15320The option-tree plugin before 2.7.3 for WordPress has Object Injection because the + character is mishandled.
CVE-2019-15319The option-tree plugin before 2.7.0 for WordPress has Object Injection by leveraging a valid nonce.
CVE-2019-15318The yikes-inc-easy-mailchimp-extender plugin before 6.5.3 for WordPress has code injection via the admin input field.
CVE-2019-15317The give plugin before 2.4.7 for WordPress has XSS via a donor name.
CVE-2019-15314tiki/tiki-upload_file.php in Tiki 18.4 allows remote attackers to upload JavaScript code that is executed upon visiting ...
CVE-2019-14511Sphinx Technologies Sphinx 3.1.1 by default has no authentication and listens on 0.0.0.0, making it exposed to the inter...
CVE-2019-6177CRITICAL9.8A vulnerability reported in Lenovo Solution Center version 03.12.003, which is no longer supported, could allow log file...
CVE-2019-5638HIGH8.7Rapid7 Nexpose versions 6.5.50 and prior suffer from insufficient session expiration when an administrator performs a se...
CVE-2019-15316Valve Steam Client for Windows through 2019-08-20 has weak folder permissions, leading to privilege escalation (to NT AU...
CVE-2019-15315Valve Steam Client for Windows through 2019-08-16 allows privilege escalation (to NT AUTHORITY\SYSTEM) because local use...
CVE-2019-14686A DLL hijacking vulnerability exists in the Trend Micro Security's 2019 consumer family of products (v15) Folder Shield ...
CVE-2019-14685A local privilege escalation vulnerability exists in Trend Micro Security 2019 (v15.0) in which, if exploited, would all...
CVE-2019-13476In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.837, XSS in the domain parameter allows a low-privilege user to ...
CVE-2019-11603HIGH7.5A HTTP Traversal Attack in earlier versions than ProSyst mBS SDK 8.2.6 and Bosch IoT Gateway Software 9.0.2 allows remot...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now