2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-15322 | — | — | 2.0% | Aug 22, 2019 | The shortcode-factory plugin before 2.8 for WordPress has Local File Inclusion. |
| CVE-2019-15321 | — | — | 2.1% | Aug 22, 2019 | The option-tree plugin before 2.7.3 for WordPress has Object Injection because serialized classes are mishandled. |
| CVE-2019-15320 | — | — | 2.1% | Aug 22, 2019 | The option-tree plugin before 2.7.3 for WordPress has Object Injection because the + character is mishandled. |
| CVE-2019-15319 | — | — | 2.1% | Aug 22, 2019 | The option-tree plugin before 2.7.0 for WordPress has Object Injection by leveraging a valid nonce. |
| CVE-2019-15318 | — | — | 2.2% | Aug 22, 2019 | The yikes-inc-easy-mailchimp-extender plugin before 6.5.3 for WordPress has code injection via the admin input field. |
| CVE-2019-15317 | — | — | 1.2% | Aug 22, 2019 | The give plugin before 2.4.7 for WordPress has XSS via a donor name. |
| CVE-2019-15314 | — | — | 0.9% | Aug 22, 2019 | tiki/tiki-upload_file.php in Tiki 18.4 allows remote attackers to upload JavaScript code that is executed upon visiting ... |
| CVE-2019-14511 | — | — | 2.0% | Aug 22, 2019 | Sphinx Technologies Sphinx 3.1.1 by default has no authentication and listens on 0.0.0.0, making it exposed to the inter... |
| CVE-2019-15316 | — | — | 0.4% | Aug 21, 2019 | Valve Steam Client for Windows through 2019-08-20 has weak folder permissions, leading to privilege escalation (to NT AU... |
| CVE-2019-15315 | — | — | 0.4% | Aug 21, 2019 | Valve Steam Client for Windows through 2019-08-16 allows privilege escalation (to NT AUTHORITY\SYSTEM) because local use... |
| CVE-2019-14686 | — | — | 1.2% | Aug 21, 2019 | A DLL hijacking vulnerability exists in the Trend Micro Security's 2019 consumer family of products (v15) Folder Shield ... |
| CVE-2019-14685 | — | — | 0.6% | Aug 21, 2019 | A local privilege escalation vulnerability exists in Trend Micro Security 2019 (v15.0) in which, if exploited, would all... |
| CVE-2019-13476 | — | — | 6.5% | Aug 21, 2019 | In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.837, XSS in the domain parameter allows a low-privilege user to ... |
| CVE-2019-10687 | — | — | 2.9% | Aug 21, 2019 | KBPublisher 6.0.2.1 has SQL Injection via the admin/index.php?module=report entry_id[0] parameter, the admin/index.php?m... |
| CVE-2019-15127 | — | — | 0.5% | Aug 21, 2019 | REDCap before 9.3.0 allows XSS attacks against non-administrator accounts on the Data Import Tool page via a CSV data im... |
| CVE-2019-15074 | — | — | 2.1% | Aug 21, 2019 | The Timeline feature in my_view_page.php in MantisBT through 2.21.1 has a stored cross-site scripting (XSS) vulnerabilit... |
| CVE-2019-15045 | — | — | 4.9% | Aug 21, 2019 | AjaxDomainServlet in Zoho ManageEngine ServiceDesk Plus 10 allows User Enumeration. NOTE: the vendor's position is that ... |
| CVE-2019-14258 | — | — | 1.7% | Aug 21, 2019 | The XML-RPC subsystem in Zenoss 2.5.3 allows XXE attacks that lead to unauthenticated information disclosure via port 99... |
| CVE-2019-14257 | — | — | 0.6% | Aug 21, 2019 | pyraw in Zenoss 2.5.3 allows local privilege escalation by modifying environment variables to redirect execution before ... |
| CVE-2019-13477 | — | — | 0.7% | Aug 21, 2019 | In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.837, CSRF in the forgot password function allows an attacker to ... |
| CVE-2019-15295 | — | — | 1.4% | Aug 21, 2019 | An Untrusted Search Path vulnerability in the ServiceInstance.dll library versions 1.0.15.119 and lower, as used in Bitd... |
| CVE-2019-11551 | — | — | 0.3% | Aug 21, 2019 | In Code42 Enterprise and Crashplan for Small Business through Client version 6.9.1, an attacker can craft a restore requ... |
| CVE-2019-15111 | — | — | 2.1% | Aug 21, 2019 | The wp-front-end-profile plugin before 0.2.2 for WordPress has a privilege escalation issue. |
| CVE-2019-15110 | — | — | 0.9% | Aug 21, 2019 | The wp-front-end-profile plugin before 0.2.2 for WordPress has XSS. |
| CVE-2019-15109 | — | — | 1.1% | Aug 21, 2019 | The the-events-calendar plugin before 4.8.2 for WordPress has XSS via the tribe_paged URL parameter. |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now