2019 CVE Vulnerabilities

17,624 CVEs published in 2019.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2019-15892——An issue was discovered in Varnish Cache before 6.0.4 LTS, and 6.1.x and 6.2.x before 6.2.1. An HTTP/1 parsing failure a...
CVE-2019-5480——A path traversal vulnerability in <= v0.9.7 of statichttpserver npm module allows attackers to list files in arbitrary f...
CVE-2019-5475——The Nexus Yum Repository Plugin in v2 is vulnerable to Remote Code Execution when instances using CommandLineExecutor.ja...
CVE-2019-14261——An issue was discovered on ABUS Secvest FUAA50000 3.01.01 devices. Due to an insufficient implementation of jamming dete...
CVE-2019-15873——The profilegrid-user-profiles-groups-and-communities plugin before 2.8.6 for WordPress has remote code execution via an ...
CVE-2019-15872——The LoginPress plugin before 1.1.4 for WordPress has SQL injection via an import of settings.
CVE-2019-15871——The LoginPress plugin before 1.1.4 for WordPress has no capability check for updates to settings.
CVE-2019-15870——The CarSpot theme before 2.1.7 for WordPress has stored XSS via the Phone Number field.
CVE-2019-15869——The JobCareer theme before 2.5.1 for WordPress has stored XSS.
CVE-2019-15868——The affiliates-manager plugin before 2.6.6 for WordPress has CSRF.
CVE-2019-15867——The slick-popup plugin before 1.7.2 for WordPress has a hardcoded OmakPass13# password for the slickpopupteam account, a...
CVE-2019-15866——The crelly-slider plugin before 1.3.5 for WordPress has arbitrary file upload via a PHP file inside a ZIP archive to wp_...
CVE-2019-15865——The breadcrumbs-by-menu plugin before 1.0.3 for WordPress has CSRF.
CVE-2019-15864——The breadcrumbs-by-menu plugin before 1.0.3 for WordPress has XSS.
CVE-2019-15863——The ConvertPlus plugin before 3.4.5 for WordPress has an unintended account creation (with the none role) via a request ...
CVE-2019-15043——In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run ...
CVE-2019-15860——Xpdf 2.00 allows a SIGSEGV in XRef::constructXRef in XRef.cc. NOTE: 2.00 is a version from November 2002.
CVE-2019-15851——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-13590. Reason: This candidate is a reservation d...
CVE-2019-15842——The easy-pdf-restaurant-menu-upload plugin before 1.1.2 for WordPress has XSS.
CVE-2019-15841——The facebook-for-woocommerce plugin before 1.9.15 for WordPress has CSRF via ajax_woo_infobanner_post_click, ajax_woo_in...
CVE-2019-15840——The facebook-for-woocommerce plugin before 1.9.14 for WordPress has CSRF.
CVE-2019-15839——The sina-extension-for-elementor plugin before 2.2.1 for WordPress has local file inclusion.
CVE-2019-15838——The custom-404-pro plugin before 3.2.8 for WordPress has reflected XSS, a different vulnerability than CVE-2019-14789.
CVE-2019-15837——The webp-express plugin before 0.14.8 for WordPress has stored XSS.
CVE-2019-15836——The wp-ultimate-recipe plugin before 3.12.7 for WordPress has stored XSS.

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now