2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-5398 | — | — | 0.7% | Aug 9, 2019 | A remote multiple multiple cross-site vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.... |
| CVE-2019-5397 | — | — | 4.3% | Aug 9, 2019 | A remote bypass of security restrictions vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to... |
| CVE-2019-5396 | — | — | 5.1% | Aug 9, 2019 | A remote authentication bypass vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1. |
| CVE-2019-5395 | — | — | 2.3% | Aug 9, 2019 | A remote arbitrary file upload vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1. |
| CVE-2019-14805 | — | — | 0.7% | Aug 9, 2019 | studio/builder_menu.php?page=sets in UNA 10.0.0-RC1 allows XSS via the System Name field under Sets during set editing. |
| CVE-2019-14804 | — | — | 2.7% | Aug 9, 2019 | studio/polyglot.php?page=etemplates in UNA 10.0.0-RC1 allows XSS via the System Name field under Emails during template ... |
| CVE-2019-14801 | — | — | 1.9% | Aug 9, 2019 | The FV Flowplayer Video Player plugin before 7.3.15.727 for WordPress allows email subscription SQL injection. |
| CVE-2019-14798 | — | — | 4.4% | Aug 9, 2019 | The 10Web Photo Gallery plugin before 1.5.25 for WordPress has Authenticated Local File Inclusion via directory traversa... |
| CVE-2019-14797 | — | — | 1.3% | Aug 9, 2019 | The 10Web Photo Gallery plugin before 1.5.23 for WordPress has authenticated stored XSS. |
| CVE-2019-14794 | — | — | 1.4% | Aug 9, 2019 | The Meta Box plugin before 4.16.2 for WordPress mishandles the uploading of files to custom folders. |
| CVE-2019-14791 | — | — | 1.4% | Aug 9, 2019 | The Appointment Booking Calendar plugin 1.3.18 for WordPress allows XSS via the wp-admin/admin-post.php editionarea para... |
| CVE-2019-14793 | — | — | 1.0% | Aug 9, 2019 | The Meta Box plugin before 4.16.3 for WordPress allows file deletion via ajax, with the wp-admin/admin-ajax.php?action=r... |
| CVE-2019-14792 | — | — | 1.1% | Aug 9, 2019 | The WP Google Maps plugin before 7.11.35 for WordPress allows XSS via the wp-admin/ rectangle_name or rectangle_opacity ... |
| CVE-2019-14785 | — | — | 0.8% | Aug 9, 2019 | The "CP Contact Form with PayPal" plugin before 1.2.99 for WordPress has XSS in the publishing wizard via the wp-admin/a... |
| CVE-2019-14312 | — | — | 20.6% | Aug 9, 2019 | Aptana Jaxer 1.0.3.4547 is vulnerable to a local file inclusion vulnerability in the wikilite source code viewer. This v... |
| CVE-2019-14234 | — | — | 46.3% | Aug 9, 2019 | An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. Due to an error in... |
| CVE-2019-14773 | — | — | 1.6% | Aug 8, 2019 | admin/includes/class.actions.snippet.php in the "Woody ad snippets" plugin through 2.2.5 for WordPress allows wp-admin/a... |
| CVE-2019-14682 | — | — | 0.7% | Aug 8, 2019 | The acf-better-search (aka ACF: Better Search) plugin before 3.3.1 for WordPress allows wp-admin/options-general.php?pag... |
| CVE-2019-14681 | — | — | 0.8% | Aug 8, 2019 | The Deny All Firewall plugin before 1.1.7 for WordPress allows wp-admin/options-general.php?page=daf_settings&daf_remove... |
| CVE-2019-14679 | — | — | 0.7% | Aug 8, 2019 | core/views/arprice_import_export.php in the ARPrice Lite plugin 2.2 for WordPress allows wp-admin/admin.php?page=arplite... |
| CVE-2019-14353 | — | — | 0.4% | Aug 8, 2019 | On Trezor One devices before 1.8.2, a side channel for the row-based OLED display was found. The power consumption of ea... |
| CVE-2019-12994 | — | — | 4.4% | Aug 8, 2019 | Server Side Request Forgery (SSRF) exists in Zoho ManageEngine AssetExplorer version 6.2.0 for the AJaxServlet servlet v... |
| CVE-2019-12959 | — | — | 3.1% | Aug 8, 2019 | Server Side Request Forgery (SSRF) exists in Zoho ManageEngine AssetExplorer 6.2.0 and before for the ClientUtilServlet ... |
| CVE-2019-12397 | — | — | 3.0% | Aug 8, 2019 | Policy import functionality in Apache Ranger 0.7.0 to 1.2.0 is vulnerable to a cross-site scripting issue. Upgrade to 2.... |
| CVE-2019-5301 | — | — | 0.5% | Aug 8, 2019 | Huawei smart phones Honor V20 with the versions before 9.0.1.161(C00E161R2P2) have an information leak vulnerability. An... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now