2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-14968An issue was discovered in imcat 4.9. There is SQL Injection via the index.php order parameter in a mod=faqs action.
CVE-2019-14967An issue was discovered in Frappe Framework 10, 11 before 11.1.46, and 12. There exists an XSS vulnerability.
CVE-2019-14966An issue was discovered in Frappe Framework 10 through 12 before 12.0.4. There exists an authenticated SQL injection.
CVE-2019-14965An issue was discovered in Frappe Framework 10 through 12 before 12.0.4. A server side template injection (SSTI) issue e...
CVE-2019-13462Lansweeper before 7.1.117.4 allows unauthenticated SQL injection.
CVE-2019-12618HashiCorp Nomad 0.9.0 through 0.9.1 has Incorrect Access Control via the exec driver.
CVE-2019-14951The Telenav Scout GPS Link app 1.x for iOS, as used with Toyota and Lexus vehicles, has an incorrect protection mechanis...
CVE-2019-14947The ultimate-member plugin before 2.0.52 for WordPress has XSS during an account upgrade.
CVE-2019-14946The ultimate-member plugin before 2.0.52 for WordPress has XSS related to UM Roles create and edit operations.
CVE-2019-14945The ultimate-member plugin before 2.0.54 for WordPress has XSS.
CVE-2019-14950The wp-live-chat-support plugin before 8.0.27 for WordPress has XSS via the GDPR page.
CVE-2019-14949MEDIUM6.1The wp-database-backup plugin before 5.1.2 for WordPress has XSS.
CVE-2019-14948MEDIUM5.4The woocommerce-product-addon plugin before 18.4 for WordPress has XSS via an import of a new meta data structure.
CVE-2019-14932The Recruitment module in Humanica Humatrix 7 1.0.0.681 and 1.0.0.203 allows remote attackers to access all candidates' ...
CVE-2019-14940In Storage Performance Development Kit (SPDK) before 19.07, a user of a vhost can cause a crash if the target is sent in...
CVE-2019-14939An issue was discovered in the mysql (aka mysqljs) module 2.17.1 for Node.js. The LOAD DATA LOCAL INFILE option is open ...
CVE-2019-149353CX Phone 15 on Windows has insecure permissions on the "%PROGRAMDATA%\3CXPhone for Windows\PhoneApp" installation direc...
CVE-2019-14934HIGH7.8An issue was discovered in PDFResurrect before 0.18. pdf_load_pages_kids in pdf.c doesn't validate a certain size value,...
CVE-2019-14933Bagisto 0.1.5 allows CSRF under /admin URIs.
CVE-2019-14924An issue was discovered in GCDWebServer before 3.5.3. The method moveItem in the GCDWebUploader class checks the FileExt...
CVE-2019-14357On Mooltipass Mini devices, a side channel for the row-based OLED display was found. The power consumption of each row-b...
CVE-2019-14355On ShapeShift KeepKey devices, a side channel for the row-based OLED display was found. The power consumption of each ro...
CVE-2019-14354On Ledger Nano S and Nano X devices, a side channel for the row-based OLED display was found. The power consumption of e...
CVE-2019-14807MEDIUM6.1In the MobileFrontend extension 1.31 through 1.33 for MediaWiki, XSS exists within the edit summary field in includes/sp...
CVE-2019-12261CRITICAL9.8Wind River VxWorks 6.7 though 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 3 of 4). This is an IPNET se...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now