2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-15508 | — | — | 0.7% | Aug 23, 2019 | In Octopus Tentacle versions 3.0.8 to 5.0.0, when a web request proxy is configured, an authenticated user (in certain l... |
| CVE-2019-15507 | — | — | 0.6% | Aug 23, 2019 | In Octopus Deploy versions 2018.8.4 to 2019.7.6, when a web request proxy is configured, an authenticated user (in certa... |
| CVE-2019-15498 | — | — | 3.4% | Aug 23, 2019 | cgi-bin/cmh/webcam.sh in Vera Edge Home Controller 1.7.4452 allows remote unauthenticated users to execute arbitrary OS ... |
| CVE-2019-15329 | — | — | 0.7% | Aug 22, 2019 | The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has CSRF. |
| CVE-2019-15328 | — | — | 0.9% | Aug 22, 2019 | The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has XSS. |
| CVE-2019-15327 | — | — | 0.9% | Aug 22, 2019 | The import-users-from-csv-with-meta plugin before 1.14.1.3 for WordPress has XSS via imported data. |
| CVE-2019-15326 | — | — | 2.3% | Aug 22, 2019 | The import-users-from-csv-with-meta plugin before 1.14.2.1 for WordPress has directory traversal. |
| CVE-2019-15325 | — | — | 1.3% | Aug 22, 2019 | In GalliumOS 3.0, CONFIG_SECURITY_YAMA is disabled but /etc/sysctl.d/10-ptrace.conf tries to set /proc/sys/kernel/yama/p... |
| CVE-2019-13139 | — | — | 1.9% | Aug 22, 2019 | In Docker before 18.09.4, an attacker who is capable of supplying or manipulating the build path for the "docker build" ... |
| CVE-2019-15331 | — | — | 0.9% | Aug 22, 2019 | The wp-support-plus-responsive-ticket-system plugin before 9.1.2 for WordPress has HTML injection. |
| CVE-2019-15330 | — | — | 1.8% | Aug 22, 2019 | The webp-express plugin before 0.14.11 for WordPress has insufficient protection against arbitrary file reading. |
| CVE-2019-15060 | — | — | 4.0% | Aug 22, 2019 | The traceroute function on the TP-Link TL-WR840N v4 router with firmware through 0.9.1 3.16 is vulnerable to remote code... |
| CVE-2019-12386 | — | — | 0.8% | Aug 22, 2019 | An issue was discovered in Ampache through 3.9.1. A stored XSS exists in the localplay.php LocalPlay "add instance" func... |
| CVE-2019-12385 | — | — | 1.6% | Aug 22, 2019 | An issue was discovered in Ampache through 3.9.1. The search engine is affected by a SQL Injection, so any user able to ... |
| CVE-2019-14469 | — | — | 1.1% | Aug 22, 2019 | In Nexus Repository Manager before 3.18.0, users with elevated privileges can create stored XSS. |
| CVE-2019-7617 | — | — | 1.5% | Aug 22, 2019 | When the Elastic APM agent for Python versions before 5.1.0 is run as a CGI script, there is a variable name clash flaw ... |
| CVE-2019-9155 | — | — | 1.5% | Aug 22, 2019 | A cryptographic issue in OpenPGP.js <=4.2.0 allows an attacker who is able provide forged messages and gain feedback abo... |
| CVE-2019-9154 | — | — | 1.6% | Aug 22, 2019 | Improper Verification of a Cryptographic Signature in OpenPGP.js <=4.1.2 allows an attacker to pass off unsigned data as... |
| CVE-2019-9153 | — | — | 2.0% | Aug 22, 2019 | Improper Verification of a Cryptographic Signature in OpenPGP.js <=4.1.2 allows an attacker to forge signed messages by ... |
| CVE-2019-14751 | — | — | 5.8% | Aug 22, 2019 | NLTK Downloader before 3.4.5 is vulnerable to a directory traversal, allowing attackers to write arbitrary files via a .... |
| CVE-2019-11031 | — | — | 1.9% | Aug 22, 2019 | Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the auto-update feature of IDVRUpdateService2 in DVRServer.ex... |
| CVE-2019-11030 | — | — | 2.0% | Aug 22, 2019 | Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the Mirasys.Common.Utils.Security.DataCrypt method in Common.... |
| CVE-2019-11029 | — | — | 2.4% | Aug 22, 2019 | Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the Download() method of AutoUpdateService in SMServer.exe, l... |
| CVE-2019-11013 | — | — | 24.0% | Aug 22, 2019 | Nimble Streamer 3.0.2-2 through 3.5.4-9 has a ../ directory traversal vulnerability. Successful exploitation could allow... |
| CVE-2019-15324 | — | — | 3.6% | Aug 22, 2019 | The ad-inserter plugin before 2.4.22 for WordPress has remote code execution. |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now