2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-5475 | — | — | 18.4% | Sep 3, 2019 | The Nexus Yum Repository Plugin in v2 is vulnerable to Remote Code Execution when instances using CommandLineExecutor.ja... |
| CVE-2019-14261 | — | — | 2.5% | Sep 3, 2019 | An issue was discovered on ABUS Secvest FUAA50000 3.01.01 devices. Due to an insufficient implementation of jamming dete... |
| CVE-2019-15873 | — | — | 3.9% | Sep 3, 2019 | The profilegrid-user-profiles-groups-and-communities plugin before 2.8.6 for WordPress has remote code execution via an ... |
| CVE-2019-15872 | — | — | 2.2% | Sep 3, 2019 | The LoginPress plugin before 1.1.4 for WordPress has SQL injection via an import of settings. |
| CVE-2019-15871 | — | — | 0.9% | Sep 3, 2019 | The LoginPress plugin before 1.1.4 for WordPress has no capability check for updates to settings. |
| CVE-2019-15870 | — | — | 0.7% | Sep 3, 2019 | The CarSpot theme before 2.1.7 for WordPress has stored XSS via the Phone Number field. |
| CVE-2019-15869 | — | — | 0.7% | Sep 3, 2019 | The JobCareer theme before 2.5.1 for WordPress has stored XSS. |
| CVE-2019-15868 | — | — | 0.7% | Sep 3, 2019 | The affiliates-manager plugin before 2.6.6 for WordPress has CSRF. |
| CVE-2019-15867 | — | — | 2.1% | Sep 3, 2019 | The slick-popup plugin before 1.7.2 for WordPress has a hardcoded OmakPass13# password for the slickpopupteam account, a... |
| CVE-2019-15866 | — | — | 2.0% | Sep 3, 2019 | The crelly-slider plugin before 1.3.5 for WordPress has arbitrary file upload via a PHP file inside a ZIP archive to wp_... |
| CVE-2019-15865 | — | — | 0.7% | Sep 3, 2019 | The breadcrumbs-by-menu plugin before 1.0.3 for WordPress has CSRF. |
| CVE-2019-15864 | — | — | 0.9% | Sep 3, 2019 | The breadcrumbs-by-menu plugin before 1.0.3 for WordPress has XSS. |
| CVE-2019-15863 | — | — | 1.6% | Sep 3, 2019 | The ConvertPlus plugin before 3.4.5 for WordPress has an unintended account creation (with the none role) via a request ... |
| CVE-2019-15043 | — | — | 63.4% | Sep 3, 2019 | In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run ... |
| CVE-2019-15860 | — | — | 0.9% | Sep 3, 2019 | Xpdf 2.00 allows a SIGSEGV in XRef::constructXRef in XRef.cc. NOTE: 2.00 is a version from November 2002. |
| CVE-2019-15851 | — | — | — | Sep 3, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-13590. Reason: This candidate is a reservation d... |
| CVE-2019-15842 | — | — | 0.9% | Aug 30, 2019 | The easy-pdf-restaurant-menu-upload plugin before 1.1.2 for WordPress has XSS. |
| CVE-2019-15841 | — | — | 0.7% | Aug 30, 2019 | The facebook-for-woocommerce plugin before 1.9.15 for WordPress has CSRF via ajax_woo_infobanner_post_click, ajax_woo_in... |
| CVE-2019-15840 | — | — | 0.7% | Aug 30, 2019 | The facebook-for-woocommerce plugin before 1.9.14 for WordPress has CSRF. |
| CVE-2019-15839 | — | — | 2.4% | Aug 30, 2019 | The sina-extension-for-elementor plugin before 2.2.1 for WordPress has local file inclusion. |
| CVE-2019-15838 | — | — | 0.9% | Aug 30, 2019 | The custom-404-pro plugin before 3.2.8 for WordPress has reflected XSS, a different vulnerability than CVE-2019-14789. |
| CVE-2019-15837 | — | — | 0.8% | Aug 30, 2019 | The webp-express plugin before 0.14.8 for WordPress has stored XSS. |
| CVE-2019-15836 | — | — | 0.8% | Aug 30, 2019 | The wp-ultimate-recipe plugin before 3.12.7 for WordPress has stored XSS. |
| CVE-2019-15835 | — | — | 0.7% | Aug 30, 2019 | The wp-better-permalinks plugin before 3.0.5 for WordPress has CSRF. |
| CVE-2019-15834 | — | — | 0.7% | Aug 30, 2019 | The webp-converter-for-media plugin before 1.0.3 for WordPress has CSRF. |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now