2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-25312 | MEDIUM | 5.4 | 0.2% | Feb 11, 2026 | InoERP 0.7.2 contains a persistent cross-site scripting vulnerability in the comment section that allows unauthenticated... |
| CVE-2019-25311 | MEDIUM | 5.4 | 0.2% | Feb 11, 2026 | thesystem version 1.0 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious... |
| CVE-2019-25301 | MEDIUM | 6.4 | 0.2% | Feb 6, 2026 | Millhouse-Project 1.414 contains a persistent cross-site scripting vulnerability in the comment submission functionality... |
| CVE-2019-25294 | MEDIUM | 6.1 | 0.2% | Feb 6, 2026 | html5_snmp 1.11 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scrip... |
| CVE-2019-25265 | MEDIUM | 6.4 | 0.3% | Feb 3, 2026 | Online Inventory Manager 3.2 contains a stored cross-site scripting vulnerability in the group description field of the ... |
| CVE-2019-25264 | MEDIUM | 6.4 | 0.2% | Feb 3, 2026 | Snipe-IT 4.7.5 contains a persistent cross-site scripting vulnerability that allows authorized users to upload malicious... |
| CVE-2019-25263 | MEDIUM | 6.4 | 0.2% | Feb 3, 2026 | Zendesk SweetHawk Survey 1.6 contains a persistent cross-site scripting vulnerability that allows attackers to inject ma... |
| CVE-2019-25297 | MEDIUM | 5.1 | 0.5% | Jan 16, 2026 | Poll, Survey & Quiz Maker Plugin by Opinion Stage Wordpress plugin versions prior to 19.6.25 contain a stored cross-site... |
| CVE-2019-25295 | MEDIUM | 6.5 | 0.5% | Jan 8, 2026 | The WP Cost Estimation plugin for WordPress is vulnerable to Upload Directory Traversal in versions before 9.660 via the... |
| CVE-2019-25290 | MEDIUM | 6.9 | 0.3% | Jan 8, 2026 | Smartliving SmartLAN/G/SI <=6.x contains an unauthenticated server-side request forgery vulnerability in the GetImage fu... |
| CVE-2019-25284 | MEDIUM | 6.1 | 0.2% | Jan 8, 2026 | V-SOL GPON/EPON OLT Platform v2.03 contains multiple reflected cross-site scripting vulnerabilities due to improper inpu... |
| CVE-2019-25280 | MEDIUM | 6.1 | 0.2% | Jan 8, 2026 | Yahei-PHP Prober 0.4.7 contains a remote HTML injection vulnerability that allows attackers to execute arbitrary HTML co... |
| CVE-2019-25277 | MEDIUM | 6.1 | 0.3% | Jan 8, 2026 | FaceSentry Access Control System 6.4.8 contains a cross-site scripting vulnerability in the 'msg' parameter of pluginIns... |
| CVE-2019-25270 | MEDIUM | 6.1 | 0.2% | Jan 8, 2026 | SOCA Access Control System 180612 contains a cross-site scripting vulnerability in the 'senddata' POST parameter of logg... |
| CVE-2019-25259 | MEDIUM | 5.3 | 0.1% | Jan 8, 2026 | Leica Geosystems GR10/GR25/GR30/GR50 GNSS 4.30.063 contains a cross-site request forgery vulnerability that allows attac... |
| CVE-2019-25262 | MEDIUM | 5.1 | 0.2% | Dec 31, 2025 | A security vulnerability has been detected in elinicksic Razgover up to db37dfc5c82f023a40f2f7834ded6633fb2b5262. This a... |
| CVE-2019-25252 | MEDIUM | 5.1 | 0.2% | Dec 24, 2025 | Teradek VidiU Pro 3.0.3 contains a cross-site request forgery vulnerability that allows attackers to change administrati... |
| CVE-2019-25251 | MEDIUM | 6.9 | 0.3% | Dec 24, 2025 | Teradek VidiU Pro 3.0.3 contains a server-side request forgery vulnerability in the management interface that allows att... |
| CVE-2019-25250 | MEDIUM | 5.3 | 0.1% | Dec 24, 2025 | Devolo dLAN 500 AV Wireless+ 3.1.0-1 contains a cross-site request forgery vulnerability that allows attackers to perfor... |
| CVE-2019-25247 | MEDIUM | 5.3 | 0.1% | Dec 24, 2025 | Beward N100 H.264 VGA IP Camera M2.1.6 contains a cross-site request forgery vulnerability that allows attackers to perf... |
| CVE-2019-25244 | MEDIUM | 5.3 | 0.2% | Dec 24, 2025 | Legrand BTicino Driver Manager F454 1.0.51 contains multiple web vulnerabilities that allow attackers to perform adminis... |
| CVE-2019-25242 | MEDIUM | 5.1 | 0.2% | Dec 24, 2025 | FaceSentry Access Control System 6.4.8 contains a cross-site request forgery vulnerability that allows attackers to perf... |
| CVE-2019-25238 | MEDIUM | 5.1 | 0.1% | Dec 24, 2025 | V-SOL GPON/EPON OLT Platform 2.03 contains a cross-site request forgery vulnerability that allows attackers to perform a... |
| CVE-2019-25234 | MEDIUM | 5.3 | 0.1% | Dec 24, 2025 | SmartHouse Webapp 6.5.33 contains multiple cross-site request forgery and cross-site scripting vulnerabilities that allo... |
| CVE-2019-25233 | MEDIUM | 5.3 | 0.2% | Dec 24, 2025 | AVE DOMINAplus 1.10.x contains cross-site request forgery and cross-site scripting vulnerabilities that allow attackers ... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now