2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-25230MEDIUM4.3An information disclosure vulnerability in Kentico Xperience allows authenticated users to view sensitive system objects...
CVE-2019-25228MEDIUM5.3An information disclosure vulnerability in Kentico Xperience allows attackers to leak virtual context URLs via the HTTP ...
CVE-2019-25225MEDIUM6.1`sanitize-html` prior to version 2.0.0-beta is vulnerable to Cross-site Scripting (XSS). The `sanitizeHtml()` function i...
CVE-2019-19145MEDIUM5.8Quantum SuperLoader 3 V94.0 005E.0h devices allow attackers to access the hardcoded fa account because there are only 65...
CVE-2019-25223MEDIUM4.9The Team Circle Image Slider With Lightbox plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in...
CVE-2019-16149MEDIUM6.1An Improper Neutralization of Input During Web Page Generation in FortiClientEMS version 6.2.0 may allow a remote attack...
CVE-2019-16151MEDIUM6.1An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS 6.4.1 and below, 6.2.9 ...
CVE-2019-6697MEDIUM6.1An Improper Neutralization of Input vulnerability affecting FortiGate version 6.2.0 through 6.2.1, 6.0.0 through 6.0.6 i...
CVE-2019-15706MEDIUM5.4An improper neutralization of input during web page generation in the SSL VPN portal of FortiProxy version 2.0.0, versio...
CVE-2019-25222MEDIUM4.9The Thumbnail carousel slider plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions...
CVE-2019-1815MEDIUM5.3A security vulnerability was discovered in the local status page functionality of Cisco Meraki’s MX67 and MX68 security ...
CVE-2019-8900MEDIUM6.8A vulnerability in the SecureROM of some Apple devices can be exploited by an unauthenticated local attacker to execute ...
CVE-2019-15002MEDIUM4.3An exploitable CSRF vulnerability exists in Atlassian Jira, from versions 7.6.4 to 8.1.0. The login form doesn’t require...
CVE-2019-25221MEDIUM4.9The Responsive Filterable Portfolio plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all ve...
CVE-2019-20472MEDIUM6.2An issue was discovered on One2Track 2019-12-08 devices. Any SIM card used with the device cannot have a PIN configured....
CVE-2019-20469MEDIUM4.6An issue was discovered on One2Track 2019-12-08 devices. Confidential information is needlessly stored on the smartwatch...
CVE-2019-20462MEDIUM5.3An issue was discovered on Alecto IVM-100 2019-11-12 devices. The device comes with a serial interface at the board leve...
CVE-2019-25218MEDIUM4.9The Photo Gallery Slideshow & Masonry Tiled Gallery plugin for WordPress is vulnerable to SQL Injection via the 'id' par...
CVE-2019-25216MEDIUM6.1The Rich Review plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the POST body 'update' parameter i...
CVE-2019-25214MEDIUM6.1The ShopWP plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several REST ...
CVE-2019-25212MEDIUM4.9The video carousel slider with lightbox plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in al...
CVE-2019-19754MEDIUM5.7HiveOS through 0.6-102@191212 ships with SSH host keys baked into the installation image, which allows man-in-the-middle...
CVE-2019-19751MEDIUM5.6easyMINE before 2019-12-05 ships with SSH host keys baked into the installation image, which allows man-in-the-middle at...
CVE-2019-25210MEDIUM6.5An issue was discovered in Cloud Native Computing Foundation (CNCF) Helm through 3.13.3. It displays values of secrets w...
CVE-2019-25157MEDIUM4.3A vulnerability was found in Ethex Contracts. It has been classified as critical. This affects an unknown part of the fi...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now