2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-16781 | MEDIUM | 5.4 | 1.4% | Dec 26, 2019 | In WordPress before 5.3.1, authenticated users with lower privileges (like contributors) can inject JavaScript code in t... |
| CVE-2019-16780 | MEDIUM | 5.4 | 1.7% | Dec 26, 2019 | WordPress users with lower privileges (like contributors) can inject JavaScript code in the block editor using a specifi... |
| CVE-2019-6035 | MEDIUM | 6.1 | 1.1% | Dec 26, 2019 | Open redirect vulnerability in Athenz v1.8.24 and earlier allows remote attackers to redirect users to arbitrary web sit... |
| CVE-2019-6034 | MEDIUM | 6.1 | 0.7% | Dec 26, 2019 | a-blog cms versions prior to Ver.2.10.23 (Ver.2.10.x), Ver.2.9.26 (Ver.2.9.x), and Ver.2.8.64 (Ver.2.8.x) allows arbitra... |
| CVE-2019-6033 | MEDIUM | 6.1 | 0.8% | Dec 26, 2019 | Cross-site scripting vulnerability in a-blog cms versions prior to Ver.2.10.23 (Ver.2.10.x), Ver.2.9.26 (Ver.2.9.x), and... |
| CVE-2019-6031 | MEDIUM | 6.1 | 0.8% | Dec 26, 2019 | Cross-site scripting vulnerability in KINZA for Windows version 5.9.2 and earlier and for Mac version 5.0.0 and earlier ... |
| CVE-2019-6029 | MEDIUM | 6.1 | 0.9% | Dec 26, 2019 | Cross-site scripting vulnerability in Custom Body Class 0.6.0 and earlier allows remote attackers to inject arbitrary we... |
| CVE-2019-6025 | MEDIUM | 6.1 | 0.9% | Dec 26, 2019 | Open redirect vulnerability in Movable Type series Movable Type 7 r.4602 (7.1.3) and earlier (Movable Type 7), Movable T... |
| CVE-2019-6024 | MEDIUM | 6.5 | 2.0% | Dec 26, 2019 | Rakuma App for Android version 7.15.0 and earlier, and for iOS version 7.16.4 and earlier allows an attacker to bypass a... |
| CVE-2019-6023 | MEDIUM | 4.3 | 1.0% | Dec 26, 2019 | Cybozu Office 10.0.0 to 10.8.3 allows remote authenticated attackers to bypass access restriction which may result in ob... |
| CVE-2019-6022 | MEDIUM | 6.5 | 2.0% | Dec 26, 2019 | Directory traversal vulnerability in Cybozu Office 10.0.0 to 10.8.3 allows remote authenticated attackers to alter arbit... |
| CVE-2019-6021 | MEDIUM | 6.1 | 0.9% | Dec 26, 2019 | Open redirect vulnerability in Library Information Management System LIMEDIO all versions allows remote attackers to red... |
| CVE-2019-6020 | MEDIUM | 6.1 | 0.9% | Dec 26, 2019 | Open redirect vulnerability in PowerCMS 5.12 and earlier (PowerCMS 5.x), 4.42 and earlier (PowerCMS 4.x), and 3.293 and ... |
| CVE-2019-6018 | MEDIUM | 6.1 | 0.8% | Dec 26, 2019 | Cross-site scripting vulnerability in NetCommons 3.2.2 and earlier (NetCommons3.x) allows remote attackers to inject arb... |
| CVE-2019-6017 | MEDIUM | 5.3 | 1.1% | Dec 26, 2019 | REMISE Payment Module (2.11, 2.12 and 2.13) version 3.0.12 and earlier allow remote attackers to [Disclosed_Information_... |
| CVE-2019-6016 | MEDIUM | 6.1 | 0.8% | Dec 26, 2019 | Cross-site scripting vulnerability in REMISE Payment Module (2.11, 2.12 and 2.13) version 3.0.12 and earlier allows remo... |
| CVE-2019-6013 | MEDIUM | 6.6 | 0.6% | Dec 26, 2019 | DBA-1510P firmware 1.70b009 and earlier allows authenticated attackers to execute arbitrary OS commands via Command Line... |
| CVE-2019-6011 | MEDIUM | 6.1 | 0.9% | Dec 26, 2019 | Cross-site scripting vulnerability in wpDataTables Lite Version 2.0.11 and earlier allows remote attackers to inject arb... |
| CVE-2019-19542 | MEDIUM | 5.4 | 0.7% | Dec 26, 2019 | The ListingPro theme before v2.0.14.2 for WordPress has Persistent XSS via the Good For field on the new listing submit ... |
| CVE-2019-19541 | MEDIUM | 5.4 | 0.7% | Dec 26, 2019 | The ListingPro theme before v2.0.14.2 for WordPress has Persistent XSS via the Best Day/Night field on the new listing s... |
| CVE-2019-19540 | MEDIUM | 6.1 | 0.9% | Dec 26, 2019 | The ListingPro theme before v2.0.14.2 for WordPress has Reflected XSS via the What field on the homepage. |
| CVE-2019-20000 | MEDIUM | 5.9 | 0.6% | Dec 26, 2019 | The malware scan function in BullGuard Premium Protection 20.0.371.8 has a TOCTOU issue that enables a symbolic link att... |
| CVE-2019-19985 | MEDIUM | 5.3 | 71.4% | Dec 26, 2019 | The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed unauthenticated file downloa... |
| CVE-2019-19984 | MEDIUM | 6.3 | 1.0% | Dec 26, 2019 | The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed users with edit_post capabil... |
| CVE-2019-19983 | MEDIUM | 4.3 | 1.2% | Dec 26, 2019 | In the WordPress plugin, Fast Velocity Minify before 2.7.7, the full web root path to the running WordPress application ... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now