2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-15716 | — | — | 0.5% | Aug 28, 2019 | WTF before 0.19.0 does not set the permissions of config.yml, which might make it easier for local attackers to read pas... |
| CVE-2019-15714 | — | — | 1.8% | Aug 28, 2019 | cli/lib/main.js in Entropic before 2019-06-13 does not reject / and \ in command names, which might allow a directory tr... |
| CVE-2019-15713 | — | — | 2.5% | Aug 28, 2019 | The my-calendar plugin before 3.1.10 for WordPress has XSS. |
| CVE-2019-15294 | — | — | 1.2% | Aug 28, 2019 | An issue was discovered in Gallagher Command Centre 8.10 before 8.10.1092(MR2). Upon an upgrade, if a custom service acc... |
| CVE-2019-15701 | — | — | 2.0% | Aug 27, 2019 | components/Modals/HelpModal.jsx in BloodHound 2.2.0 allows remote attackers to execute arbitrary OS commands (by spawnin... |
| CVE-2019-15700 | — | — | 0.9% | Aug 27, 2019 | public/js/frappe/form/footer/timeline.js in Frappe Framework 12 through 12.0.8 does not escape HTML in the timeline and ... |
| CVE-2019-13270 | — | — | 0.9% | Aug 27, 2019 | Edimax BR-6208AC V1 devices have Insufficient Compartmentalization between a host network and a guest network that are e... |
| CVE-2019-13269 | — | — | 0.9% | Aug 27, 2019 | Edimax BR-6208AC V1 devices have Insufficient Compartmentalization between a host network and a guest network that are e... |
| CVE-2019-13268 | — | — | 0.9% | Aug 27, 2019 | TP-Link Archer C3200 V1 and Archer C2 V1 devices have Insufficient Compartmentalization between a host network and a gue... |
| CVE-2019-13267 | — | — | 1.0% | Aug 27, 2019 | TP-Link Archer C3200 V1 and Archer C2 V1 devices have Insufficient Compartmentalization between a host network and a gue... |
| CVE-2019-13266 | — | — | 1.0% | Aug 27, 2019 | TP-Link Archer C3200 V1 and Archer C2 V1 devices have Insufficient Compartmentalization between a host network and a gue... |
| CVE-2019-15698 | — | — | 0.9% | Aug 27, 2019 | In Octopus Deploy 2019.7.3 through 2019.7.9, in certain circumstances, an authenticated user with VariableView permissio... |
| CVE-2019-13486 | — | — | 1.8% | Aug 27, 2019 | In Xymon through 4.3.28, a stack-based buffer overflow exists in the status-log viewer component because of expan... |
| CVE-2019-13485 | — | — | 1.8% | Aug 27, 2019 | In Xymon through 4.3.28, a stack-based buffer overflow vulnerability exists in the history viewer component via a long h... |
| CVE-2019-13484 | — | — | 1.8% | Aug 27, 2019 | In Xymon through 4.3.28, a buffer overflow exists in the status-log viewer CGI because of expansion in appfeed.c. |
| CVE-2019-13455 | — | — | 2.0% | Aug 27, 2019 | In Xymon through 4.3.28, a stack-based buffer overflow vulnerability exists in the alert acknowledgment CGI tool because... |
| CVE-2019-13452 | — | — | 1.8% | Aug 27, 2019 | In Xymon through 4.3.28, a buffer overflow vulnerability exists in reportlog.c. |
| CVE-2019-13451 | — | — | 2.4% | Aug 27, 2019 | In Xymon through 4.3.28, a buffer overflow vulnerability exists in history.c. |
| CVE-2019-13274 | — | — | 0.9% | Aug 27, 2019 | In Xymon through 4.3.28, an XSS vulnerability exists in the csvinfo CGI script due to insufficient filtering of the db p... |
| CVE-2019-13273 | — | — | 1.5% | Aug 27, 2019 | In Xymon through 4.3.28, a buffer overflow vulnerability exists in the csvinfo CGI script. The overflow may be exploited... |
| CVE-2019-13271 | — | — | 1.0% | Aug 27, 2019 | Edimax BR-6208AC V1 devices have Insufficient Compartmentalization between a host network and a guest network that are e... |
| CVE-2019-14314 | — | — | 43.4% | Aug 27, 2019 | A SQL injection vulnerability exists in the Imagely NextGEN Gallery plugin before 3.2.11 for WordPress. Successful explo... |
| CVE-2019-15660 | — | — | 0.7% | Aug 27, 2019 | The wp-members plugin before 3.2.8 for WordPress has CSRF. |
| CVE-2019-15650 | — | — | 0.9% | Aug 27, 2019 | The stops-core-theme-and-plugin-updates plugin before 8.0.5 for WordPress has insufficient restrictions on option change... |
| CVE-2019-15659 | — | — | 1.9% | Aug 27, 2019 | The pie-register plugin before 3.1.2 for WordPress has SQL injection, a different issue than CVE-2018-10969. |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now