2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-14683 | MEDIUM | 5.7 | 0.7% | Aug 8, 2019 | The codection "Import users from CSV with meta" plugin before 1.14.2.2 for WordPress allows wp-admin/admin-ajax.php?acti... |
| CVE-2019-14682 | — | — | 0.7% | Aug 8, 2019 | The acf-better-search (aka ACF: Better Search) plugin before 3.3.1 for WordPress allows wp-admin/options-general.php?pag... |
| CVE-2019-14681 | — | — | 0.8% | Aug 8, 2019 | The Deny All Firewall plugin before 1.1.7 for WordPress allows wp-admin/options-general.php?page=daf_settings&daf_remove... |
| CVE-2019-14680 | MEDIUM | 5.7 | 0.5% | Aug 8, 2019 | The admin-renamer-extended (aka Admin renamer extended) plugin 3.2.1 for WordPress allows wp-admin/plugins.php?page=admi... |
| CVE-2019-14679 | — | — | 0.7% | Aug 8, 2019 | core/views/arprice_import_export.php in the ARPrice Lite plugin 2.2 for WordPress allows wp-admin/admin.php?page=arplite... |
| CVE-2019-14353 | — | — | 0.4% | Aug 8, 2019 | On Trezor One devices before 1.8.2, a side channel for the row-based OLED display was found. The power consumption of ea... |
| CVE-2019-14693 | HIGH | 8.5 | 4.2% | Aug 8, 2019 | Zoho ManageEngine AssetExplorer 6.2.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing lic... |
| CVE-2019-12994 | — | — | 4.4% | Aug 8, 2019 | Server Side Request Forgery (SSRF) exists in Zoho ManageEngine AssetExplorer version 6.2.0 for the AJaxServlet servlet v... |
| CVE-2019-12959 | — | — | 3.1% | Aug 8, 2019 | Server Side Request Forgery (SSRF) exists in Zoho ManageEngine AssetExplorer 6.2.0 and before for the ClientUtilServlet ... |
| CVE-2019-12397 | — | — | 3.0% | Aug 8, 2019 | Policy import functionality in Apache Ranger 0.7.0 to 1.2.0 is vulnerable to a cross-site scripting issue. Upgrade to 2.... |
| CVE-2019-5301 | — | — | 0.5% | Aug 8, 2019 | Huawei smart phones Honor V20 with the versions before 9.0.1.161(C00E161R2P2) have an information leak vulnerability. An... |
| CVE-2019-5239 | — | — | 0.7% | Aug 8, 2019 | Huawei PCManager with the versions before 9.0.1.66 (Oversea) and versions before 9.0.1.70 (China) have an information le... |
| CVE-2019-5238 | — | — | 0.9% | Aug 8, 2019 | Huawei PCManager with the versions before 9.0.1.66 (Oversea) and versions before 9.0.1.70 (China) have a code execution ... |
| CVE-2019-5237 | — | — | 0.9% | Aug 8, 2019 | Huawei PCManager with the versions before 9.0.1.66 (Oversea) and versions before 9.0.1.70 (China) have a code execution ... |
| CVE-2019-5236 | — | — | 0.6% | Aug 8, 2019 | Huawei smart phones Emily-L29C with versions of 8.1.0.132a(C432), 8.1.0.135(C782), 8.1.0.154(C10), 8.1.0.154(C461), 8.1.... |
| CVE-2019-11208 | CRITICAL | 9.9 | 0.9% | Aug 8, 2019 | The authorization component of TIBCO Software Inc.'s TIBCO API Exchange Gateway, and TIBCO API Exchange Gateway Distribu... |
| CVE-2019-14335 | MEDIUM | 5.5 | 0.8% | Aug 8, 2019 | An issue was discovered on D-Link 6600-AP and DWL-3600AP Ax 4.2.0.14 21/03/2019 devices. There is post-authenticated den... |
| CVE-2019-13176 | — | — | 2.5% | Aug 8, 2019 | An issue was discovered in the 3CX Phone system (web) management console 12.5.44178.1002 through 12.5 SP2. The Content.M... |
| CVE-2019-14772 | — | — | 0.9% | Aug 8, 2019 | verdaccio before 3.12.0 allows XSS. |
| CVE-2019-14754 | — | — | 1.5% | Aug 8, 2019 | Open-School 3.0, and Community Edition 2.3, allows SQL Injection via the index.php?r=students/students/document id param... |
| CVE-2019-14255 | — | — | 2.2% | Aug 8, 2019 | A Server Side Request Forgery (SSRF) vulnerability in go-camo up to version 1.1.4 allows a remote attacker to perform HT... |
| CVE-2019-14221 | — | — | 1.7% | Aug 8, 2019 | 1CRM On-Premise Software 8.5.7 allows XSS via a payload that is mishandled during a Run Report operation. |
| CVE-2019-13101 | CRITICAL | 9.8 | 67.1% | Aug 8, 2019 | An issue was discovered on D-Link DIR-600M 3.02, 3.03, 3.04, and 3.06 devices. wan.htm can be accessed directly without ... |
| CVE-2019-1973 | MEDIUM | 4.8 | 0.8% | Aug 8, 2019 | A vulnerability in the web portal framework of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authe... |
| CVE-2019-1972 | MEDIUM | 6.7 | 0.5% | Aug 8, 2019 | A vulnerability the Cisco Enterprise NFV Infrastructure Software (NFVIS) restricted CLI could allow an authenticated, lo... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now