2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-15788 | — | — | 1.8% | Aug 29, 2019 | Clara Genomics Analysis before 0.2.0 has an integer overflow for cudapoa memory management in allocate_block.cpp. |
| CVE-2019-15786 | — | — | 1.6% | Aug 29, 2019 | ROBOTIS Dynamixel SDK through 3.7.11 has a buffer overflow via a large rxpacket. |
| CVE-2019-15785 | — | — | 2.7% | Aug 29, 2019 | FontForge 20190813 through 20190820 has a buffer overflow in PrefsUI_LoadPrefs in prefs.c. |
| CVE-2019-15784 | — | — | 2.0% | Aug 29, 2019 | Secure Reliable Transport (SRT) through 1.3.4 has a CSndUList array overflow if there are many SRT connections. |
| CVE-2019-15781 | — | — | 0.7% | Aug 29, 2019 | The facebook-by-weblizar plugin before 2.8.5 for WordPress has CSRF. |
| CVE-2019-15779 | — | — | 0.7% | Aug 29, 2019 | The insta-gallery plugin before 2.4.8 for WordPress has no nonce validation for qligg_dismiss_notice or qligg_form_item_... |
| CVE-2019-15778 | — | — | 1.0% | Aug 29, 2019 | The woo-variation-gallery plugin before 1.1.29 for WordPress has XSS. |
| CVE-2019-15771 | — | — | 1.3% | Aug 29, 2019 | The nd-shortcodes plugin before 6.0 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl sett... |
| CVE-2019-15745 | — | — | 1.4% | Aug 29, 2019 | The Eques elf smart plug and the mobile app use a hardcoded AES 256 bit key to encrypt the commands and responses betwee... |
| CVE-2019-15787 | — | — | 1.4% | Aug 29, 2019 | libZetta.rs through 0.1.2 has an integer overflow in the zpool parser (for error stats) that leads to a panic. |
| CVE-2019-15783 | — | — | 1.5% | Aug 29, 2019 | Lute-Tab before 2019-08-23 has a buffer overflow in pdf_print.cc. |
| CVE-2019-15782 | — | — | 1.5% | Aug 29, 2019 | WebTorrent before 0.107.6 allows XSS in the HTTP server via a title or file name. |
| CVE-2019-15777 | — | — | 1.1% | Aug 29, 2019 | The shapepress-dsgvo plugin before 2.2.19 for WordPress has wp-admin/admin-ajax.php?action=admin-common-settings&admin_e... |
| CVE-2019-15776 | — | — | 1.3% | Aug 29, 2019 | The simple-301-redirects-addon-bulk-uploader plugin before 1.2.5 for WordPress has no protection against 301 redirect ru... |
| CVE-2019-15775 | — | — | 1.3% | Aug 29, 2019 | The nd-learning plugin before 4.8 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl settin... |
| CVE-2019-15774 | — | — | 1.7% | Aug 29, 2019 | The nd-booking plugin before 2.5 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting... |
| CVE-2019-15773 | — | — | 1.3% | Aug 29, 2019 | The nd-travel plugin before 1.7 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting. |
| CVE-2019-15772 | — | — | 1.3% | Aug 29, 2019 | The nd-donations plugin before 1.4 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setti... |
| CVE-2019-15770 | — | — | 0.7% | Aug 29, 2019 | The woo-address-book plugin before 1.6.0 for WordPress has save calls without nonce verification checks. |
| CVE-2019-15769 | — | — | 0.8% | Aug 29, 2019 | The handl-utm-grabber plugin before 2.6.5 for WordPress has CSRF via add_option and update_option. |
| CVE-2019-14943 | — | — | 2.0% | Aug 29, 2019 | An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.1.4. It uses Hard-coded Credentials. |
| CVE-2019-15767 | — | — | 1.5% | Aug 29, 2019 | In GNU Chess 6.2.5, there is a stack-based buffer overflow in the cmd_load function in frontend/cmd.cc via a crafted che... |
| CVE-2019-5530 | — | — | 0.9% | Aug 29, 2019 | Windows binaries generated with InstallBuilder versions earlier than 19.7.0 are vulnerable to tampering even if they con... |
| CVE-2019-15757 | — | — | 1.6% | Aug 29, 2019 | libMirage 3.2.2 in CDemu has a NULL pointer dereference in the NRG parser in parser.c. |
| CVE-2019-13407 | — | — | 1.1% | Aug 29, 2019 | A XSS found in Advan VD-1 firmware versions up to 230. VD-1 responses a path error message when a requested resource was... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now