2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-5397 | — | — | 4.3% | Aug 9, 2019 | A remote bypass of security restrictions vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to... |
| CVE-2019-12257 | HIGH | 8.8 | 84.2% | Aug 9, 2019 | Wind River VxWorks 6.6 through 6.9 has a Buffer Overflow in the DHCP client component. There is an IPNET security vulner... |
| CVE-2019-12256 | CRITICAL | 9.8 | 26.6% | Aug 9, 2019 | Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the IPv4 component. There is an IPNET security vulnerability: St... |
| CVE-2019-5396 | — | — | 5.1% | Aug 9, 2019 | A remote authentication bypass vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1. |
| CVE-2019-5395 | — | — | 2.3% | Aug 9, 2019 | A remote arbitrary file upload vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1. |
| CVE-2019-12805 | HIGH | 8.8 | 2.9% | Aug 9, 2019 | NCSOFT Game Launcher, NC Launcher2 2.4.1.691 and earlier versions have a vulnerability in the custom protocol handler th... |
| CVE-2019-14806 | HIGH | 7.5 | 2.3% | Aug 9, 2019 | Pallets Werkzeug before 0.15.3, when used with Docker, has insufficient debugger PIN randomness because Docker container... |
| CVE-2019-14805 | — | — | 0.7% | Aug 9, 2019 | studio/builder_menu.php?page=sets in UNA 10.0.0-RC1 allows XSS via the System Name field under Sets during set editing. |
| CVE-2019-14804 | — | — | 2.7% | Aug 9, 2019 | studio/polyglot.php?page=etemplates in UNA 10.0.0-RC1 allows XSS via the System Name field under Emails during template ... |
| CVE-2019-14801 | — | — | 1.9% | Aug 9, 2019 | The FV Flowplayer Video Player plugin before 7.3.15.727 for WordPress allows email subscription SQL injection. |
| CVE-2019-14798 | — | — | 4.4% | Aug 9, 2019 | The 10Web Photo Gallery plugin before 1.5.25 for WordPress has Authenticated Local File Inclusion via directory traversa... |
| CVE-2019-14797 | — | — | 1.3% | Aug 9, 2019 | The 10Web Photo Gallery plugin before 1.5.23 for WordPress has authenticated stored XSS. |
| CVE-2019-14796 | MEDIUM | 5.4 | 1.0% | Aug 9, 2019 | The mq-woocommerce-products-price-bulk-edit (aka Woocommerce Products Price Bulk Edit) plugin 2.0 for WordPress allows X... |
| CVE-2019-14794 | — | — | 1.4% | Aug 9, 2019 | The Meta Box plugin before 4.16.2 for WordPress mishandles the uploading of files to custom folders. |
| CVE-2019-14791 | — | — | 1.4% | Aug 9, 2019 | The Appointment Booking Calendar plugin 1.3.18 for WordPress allows XSS via the wp-admin/admin-post.php editionarea para... |
| CVE-2019-14799 | MEDIUM | 6.1 | 2.0% | Aug 9, 2019 | The FV Flowplayer Video Player plugin before 7.3.14.727 for WordPress allows email subscription XSS. |
| CVE-2019-14793 | — | — | 1.0% | Aug 9, 2019 | The Meta Box plugin before 4.16.3 for WordPress allows file deletion via ajax, with the wp-admin/admin-ajax.php?action=r... |
| CVE-2019-14792 | — | — | 1.1% | Aug 9, 2019 | The WP Google Maps plugin before 7.11.35 for WordPress allows XSS via the wp-admin/ rectangle_name or rectangle_opacity ... |
| CVE-2019-14787 | MEDIUM | 5.4 | 1.0% | Aug 9, 2019 | The Tribulant Newsletters plugin before 4.6.19 for WordPress allows XSS via the wp-admin/admin-ajax.php?action=newslette... |
| CVE-2019-14785 | — | — | 0.8% | Aug 9, 2019 | The "CP Contact Form with PayPal" plugin before 1.2.99 for WordPress has XSS in the publishing wizard via the wp-admin/a... |
| CVE-2019-14312 | — | — | 20.6% | Aug 9, 2019 | Aptana Jaxer 1.0.3.4547 is vulnerable to a local file inclusion vulnerability in the wikilite source code viewer. This v... |
| CVE-2019-14234 | — | — | 46.3% | Aug 9, 2019 | An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. Due to an error in... |
| CVE-2019-14783 | MEDIUM | 5.5 | 0.2% | Aug 8, 2019 | On Samsung mobile devices with N(7.x), and O(8.x), P(9.0) software, FotaAgent allows a malicious application to create p... |
| CVE-2019-14774 | MEDIUM | 6.1 | 1.0% | Aug 8, 2019 | The woo-variation-swatches (aka Variation Swatches for WooCommerce) plugin 1.0.61 for WordPress allows XSS via the wp-ad... |
| CVE-2019-14773 | — | — | 1.6% | Aug 8, 2019 | admin/includes/class.actions.snippet.php in the "Woody ad snippets" plugin through 2.2.5 for WordPress allows wp-admin/a... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now