2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-12618 | — | — | 2.4% | Aug 12, 2019 | HashiCorp Nomad 0.9.0 through 0.9.1 has Incorrect Access Control via the exec driver. |
| CVE-2019-14951 | — | — | 1.7% | Aug 12, 2019 | The Telenav Scout GPS Link app 1.x for iOS, as used with Toyota and Lexus vehicles, has an incorrect protection mechanis... |
| CVE-2019-14947 | — | — | 0.9% | Aug 12, 2019 | The ultimate-member plugin before 2.0.52 for WordPress has XSS during an account upgrade. |
| CVE-2019-14946 | — | — | 0.8% | Aug 12, 2019 | The ultimate-member plugin before 2.0.52 for WordPress has XSS related to UM Roles create and edit operations. |
| CVE-2019-14945 | — | — | 0.9% | Aug 12, 2019 | The ultimate-member plugin before 2.0.54 for WordPress has XSS. |
| CVE-2019-14950 | — | — | 1.2% | Aug 12, 2019 | The wp-live-chat-support plugin before 8.0.27 for WordPress has XSS via the GDPR page. |
| CVE-2019-14932 | — | — | 2.1% | Aug 12, 2019 | The Recruitment module in Humanica Humatrix 7 1.0.0.681 and 1.0.0.203 allows remote attackers to access all candidates' ... |
| CVE-2019-14940 | — | — | 1.2% | Aug 12, 2019 | In Storage Performance Development Kit (SPDK) before 19.07, a user of a vhost can cause a crash if the target is sent in... |
| CVE-2019-14939 | — | — | 0.4% | Aug 12, 2019 | An issue was discovered in the mysql (aka mysqljs) module 2.17.1 for Node.js. The LOAD DATA LOCAL INFILE option is open ... |
| CVE-2019-14935 | — | — | 0.4% | Aug 12, 2019 | 3CX Phone 15 on Windows has insecure permissions on the "%PROGRAMDATA%\3CXPhone for Windows\PhoneApp" installation direc... |
| CVE-2019-14933 | — | — | 0.6% | Aug 11, 2019 | Bagisto 0.1.5 allows CSRF under /admin URIs. |
| CVE-2019-14924 | — | — | 2.0% | Aug 10, 2019 | An issue was discovered in GCDWebServer before 3.5.3. The method moveItem in the GCDWebUploader class checks the FileExt... |
| CVE-2019-14357 | — | — | 0.3% | Aug 10, 2019 | On Mooltipass Mini devices, a side channel for the row-based OLED display was found. The power consumption of each row-b... |
| CVE-2019-14355 | — | — | 0.3% | Aug 10, 2019 | On ShapeShift KeepKey devices, a side channel for the row-based OLED display was found. The power consumption of each ro... |
| CVE-2019-14354 | — | — | 0.4% | Aug 10, 2019 | On Ledger Nano S and Nano X devices, a side channel for the row-based OLED display was found. The power consumption of e... |
| CVE-2019-5498 | — | — | 1.1% | Aug 9, 2019 | OnCommand Insight versions through 7.3.6 may disclose sensitive account information to an authenticated user. |
| CVE-2019-5408 | — | — | 1.6% | Aug 9, 2019 | Command View Advanced Edition (CVAE) products contain a vulnerability that could expose configuration information of hos... |
| CVE-2019-5407 | — | — | 1.0% | Aug 9, 2019 | A remote information disclosure vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media ve... |
| CVE-2019-5406 | — | — | 1.4% | Aug 9, 2019 | A remote session reuse vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s):... |
| CVE-2019-5405 | — | — | 1.6% | Aug 9, 2019 | A remote authorization bypass vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media vers... |
| CVE-2019-5404 | — | — | 1.6% | Aug 9, 2019 | A remote script injection vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(... |
| CVE-2019-5403 | — | — | 0.5% | Aug 9, 2019 | A remote multiple cross-site scripting vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software M... |
| CVE-2019-5402 | — | — | 4.3% | Aug 9, 2019 | A remote authorization bypass vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media vers... |
| CVE-2019-5400 | — | — | 0.9% | Aug 9, 2019 | A remote session reuse vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1. |
| CVE-2019-5399 | — | — | 2.4% | Aug 9, 2019 | A remote gain authorized access vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1. |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now