2019 CVE Vulnerabilities

17,624 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-19110MEDIUM4.8The wpForo plugin 1.6.5 for WordPress allows XSS via the wp-admin/admin.php?page=wpforo-phrases s parameter.
CVE-2019-19109HIGH8.8The wpForo plugin 1.6.5 for WordPress allows wp-admin/admin.php?page=wpforo-usergroups CSRF.
CVE-2019-16252MEDIUM5.9Missing SSL Certificate Validation in the Nutfind.com application through 3.9.12 for Android allows a man-in-the-middle ...
CVE-2019-15123HIGH7.2The Branding Module in Viki Vera 4.9.1.26180 allows an authenticated user to change the logo on the website. An attacker...
CVE-2019-5735——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2019-5732——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2019-5731——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2019-4576CRITICAL9.8IBM QRadar Network Packet Capture 7.3.0 - 7.3.3 Patch 1 and 7.4.0 GA does not require that users should have strong pass...
CVE-2019-3588MEDIUM6.8Privilege Escalation vulnerability in Microsoft Windows client (McTray.exe) in McAfee VirusScan Enterprise (VSE) 8.8 pri...
CVE-2019-3585HIGH7.8Privilege Escalation vulnerability in Microsoft Windows client (McTray.exe) in McAfee VirusScan Enterprise (VSE) 8.8 pri...
CVE-2019-3613HIGH7.3DLL Search Order Hijacking vulnerability in McAfee Agent (MA) prior to 5.6.4 allows attackers with local access to execu...
CVE-2019-3617HIGH8.2Privilege escalation vulnerability in McAfee Total Protection (ToPS) for Mac OS prior to 4.6 allows local users to gain ...
CVE-2019-6196HIGH7.3A symbolic link vulnerability in some Lenovo installation packages, prior to version 1.2.9.3, could allow privileged fil...
CVE-2019-6173MEDIUM6.5A DLL search path vulnerability could allow privilege escalation in some Lenovo installation packages, prior to version ...
CVE-2019-19412MEDIUM4.6Huawei smart phones have a Factory Reset Protection (FRP) bypass security vulnerability. When re-configuring the mobile ...
CVE-2019-20837HIGH7.5An issue was discovered in Foxit Reader and PhantomPDF before 9.5. It allows signature validation bypass via a modified ...
CVE-2019-20836HIGH7.5An issue was discovered in Foxit Reader and PhantomPDF before 9.5. It has mishandling of cloud credentials, as demonstra...
CVE-2019-20835MEDIUM4.3An issue was discovered in Foxit Reader and PhantomPDF before 9.5. It has homograph mishandling.
CVE-2019-20834HIGH7.5An issue was discovered in Foxit PhantomPDF before 8.3.10. It allows signature validation bypass via a modified file or ...
CVE-2019-20833HIGH7.5An issue was discovered in Foxit PhantomPDF before 8.3.10. It has mishandling of cloud credentials, as demonstrated by G...
CVE-2019-20832MEDIUM4.3An issue was discovered in Foxit PhantomPDF before 8.3.10. It has homograph mishandling.
CVE-2019-20831HIGH7.5An issue was discovered in the 3D Plugin Beta for Foxit Reader and PhantomPDF before 9.5.0.20733. It has void data misha...
CVE-2019-20830CRITICAL9.8An issue was discovered in Foxit Reader and PhantomPDF before 9.6. It has an out-of-bounds write when Internet Explorer ...
CVE-2019-20829HIGH7.5An issue was discovered in Foxit Reader and PhantomPDF before 9.6. It has a NULL pointer dereference via FXSYS_wcslen in...
CVE-2019-20828HIGH7.5An issue was discovered in Foxit Reader and PhantomPDF before 9.6. It has a buffer overflow because a looping correction...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now