2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-15630 | — | — | 3.0% | Aug 30, 2019 | Directory Traversal in APIkit, HTTP connector, and OAuth2 Provider components in MuleSoft Mule Runtime 3.2.0 and higher ... |
| CVE-2019-12810 | — | — | 1.2% | Aug 30, 2019 | A memory corruption vulnerability exists in the .PSD parsing functionality of ALSee v5.3 ~ v8.39. A specially crafted .P... |
| CVE-2019-15026 | — | — | 2.6% | Aug 30, 2019 | memcached 1.5.16, when UNIX sockets are used, has a stack-based buffer over-read in conn_to_str in memcached.c. |
| CVE-2019-15832 | — | — | 0.8% | Aug 30, 2019 | The visitors-traffic-real-time-statistics plugin before 1.13 for WordPress has CSRF. |
| CVE-2019-15831 | — | — | 0.7% | Aug 30, 2019 | The visitors-traffic-real-time-statistics plugin before 1.12 for WordPress has CSRF in the settings page. |
| CVE-2019-15830 | — | — | 1.0% | Aug 30, 2019 | The icegram plugin before 1.10.29 for WordPress has ig_cat_list XSS. |
| CVE-2019-15829 | — | — | 1.3% | Aug 30, 2019 | The photoblocks-grid-gallery plugin before 1.1.33 for WordPress has wp-admin/admin.php?page=photoblocks-edit&id= XSS. |
| CVE-2019-15828 | — | — | 0.8% | Aug 30, 2019 | The one-click-ssl plugin before 1.4.7 for WordPress has CSRF. |
| CVE-2019-15827 | — | — | 1.1% | Aug 30, 2019 | The onesignal-free-web-push-notifications plugin before 1.17.8 for WordPress has XSS via the subdomain parameter. |
| CVE-2019-15826 | — | — | 3.0% | Aug 30, 2019 | The wps-hide-login plugin before 1.5.3 for WordPress has a protection bypass via wp-login.php in the Referer field. |
| CVE-2019-15825 | — | — | 3.0% | Aug 30, 2019 | The wps-hide-login plugin before 1.5.3 for WordPress has an action=rp&key&login protection bypass. |
| CVE-2019-15824 | — | — | 3.0% | Aug 30, 2019 | The wps-hide-login plugin before 1.5.3 for WordPress has an adminhash protection bypass. |
| CVE-2019-15823 | — | — | 8.6% | Aug 30, 2019 | The wps-hide-login plugin before 1.5.3 for WordPress has an action=confirmaction protection bypass. |
| CVE-2019-15822 | — | — | 3.4% | Aug 30, 2019 | The wps-child-theme-generator plugin before 1.2 for WordPress has classes/helpers.php directory traversal. |
| CVE-2019-15821 | — | — | 11.0% | Aug 30, 2019 | The bold-page-builder plugin before 2.3.2 for WordPress has no protection against modifying settings and importing data. |
| CVE-2019-15820 | — | — | 1.5% | Aug 30, 2019 | The login-or-logout-menu-item plugin before 1.2.0 for WordPress has no requirement for lolmi_save_settings authenticatio... |
| CVE-2019-15819 | — | — | 3.2% | Aug 30, 2019 | The nd-restaurant-reservations plugin before 1.5 for WordPress has no requirement for nd_rst_import_settings_php_functio... |
| CVE-2019-15818 | — | — | 1.5% | Aug 30, 2019 | The simple-301-redirects-addon-bulk-uploader plugin through 1.2.4 for WordPress has no requirement for authentication fo... |
| CVE-2019-15817 | — | — | 1.0% | Aug 30, 2019 | The easy-property-listings plugin before 3.4 for WordPress has XSS. |
| CVE-2019-15816 | — | — | 2.0% | Aug 30, 2019 | The wp-private-content-plus plugin before 2.0 for WordPress has no protection against option changes via save_settings_p... |
| CVE-2019-9697 | — | — | 1.0% | Aug 30, 2019 | An information disclosure vulnerability in the Management Center (MC) REST API 2.0, 2.1, and 2.2 prior to 2.2.2.1 allows... |
| CVE-2019-6113 | — | — | 3.0% | Aug 30, 2019 | Directory traversal vulnerability on ONKYO TX-NR686 1030-5000-1040-0010 A/V Receiver devices allows remote attackers to ... |
| CVE-2019-13526 | — | — | 2.4% | Aug 30, 2019 | Datalogic AV7000 Linear barcode scanner all versions prior to 4.6.0.0 is vulnerable to authentication bypass, which may ... |
| CVE-2019-12754 | — | — | 0.6% | Aug 30, 2019 | Symantec My VIP portal, previous version which has already been auto updated, was susceptible to a cross-site scripting ... |
| CVE-2019-12753 | — | — | 1.0% | Aug 30, 2019 | An information disclosure vulnerability in Symantec Reporter web UI 10.3 prior to 10.3.2.5 allows a malicious authentica... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now