2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-25230 | MEDIUM | 4.3 | 0.2% | Dec 18, 2025 | An information disclosure vulnerability in Kentico Xperience allows authenticated users to view sensitive system objects... |
| CVE-2019-25228 | MEDIUM | 5.3 | 0.3% | Dec 18, 2025 | An information disclosure vulnerability in Kentico Xperience allows attackers to leak virtual context URLs via the HTTP ... |
| CVE-2019-25225 | MEDIUM | 6.1 | 0.3% | Sep 8, 2025 | `sanitize-html` prior to version 2.0.0-beta is vulnerable to Cross-site Scripting (XSS). The `sanitizeHtml()` function i... |
| CVE-2019-19145 | MEDIUM | 5.8 | 0.3% | Aug 1, 2025 | Quantum SuperLoader 3 V94.0 005E.0h devices allow attackers to access the hardcoded fa account because there are only 65... |
| CVE-2019-25223 | MEDIUM | 4.9 | 0.3% | Apr 8, 2025 | The Team Circle Image Slider With Lightbox plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in... |
| CVE-2019-16149 | MEDIUM | 6.1 | 0.3% | Mar 28, 2025 | An Improper Neutralization of Input During Web Page Generation in FortiClientEMS version 6.2.0 may allow a remote attack... |
| CVE-2019-16151 | MEDIUM | 6.1 | 0.4% | Mar 21, 2025 | An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS 6.4.1 and below, 6.2.9 ... |
| CVE-2019-6697 | MEDIUM | 6.1 | 0.3% | Mar 17, 2025 | An Improper Neutralization of Input vulnerability affecting FortiGate version 6.2.0 through 6.2.1, 6.0.0 through 6.0.6 i... |
| CVE-2019-15706 | MEDIUM | 5.4 | 0.4% | Mar 17, 2025 | An improper neutralization of input during web page generation in the SSL VPN portal of FortiProxy version 2.0.0, versio... |
| CVE-2019-25222 | MEDIUM | 4.9 | 0.4% | Mar 15, 2025 | The Thumbnail carousel slider plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions... |
| CVE-2019-1815 | MEDIUM | 5.3 | 0.3% | Mar 4, 2025 | A security vulnerability was discovered in the local status page functionality of Cisco Meraki’s MX67 and MX68 security ... |
| CVE-2019-8900 | MEDIUM | 6.8 | 67.1% | Feb 21, 2025 | A vulnerability in the SecureROM of some Apple devices can be exploited by an unauthenticated local attacker to execute ... |
| CVE-2019-15002 | MEDIUM | 4.3 | 0.3% | Feb 11, 2025 | An exploitable CSRF vulnerability exists in Atlassian Jira, from versions 7.6.4 to 8.1.0. The login form doesn’t require... |
| CVE-2019-25221 | MEDIUM | 4.9 | 0.5% | Dec 13, 2024 | The Responsive Filterable Portfolio plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all ve... |
| CVE-2019-20472 | MEDIUM | 6.2 | 0.3% | Nov 7, 2024 | An issue was discovered on One2Track 2019-12-08 devices. Any SIM card used with the device cannot have a PIN configured.... |
| CVE-2019-20469 | MEDIUM | 4.6 | 0.3% | Nov 7, 2024 | An issue was discovered on One2Track 2019-12-08 devices. Confidential information is needlessly stored on the smartwatch... |
| CVE-2019-20462 | MEDIUM | 5.3 | 0.3% | Nov 7, 2024 | An issue was discovered on Alecto IVM-100 2019-11-12 devices. The device comes with a serial interface at the board leve... |
| CVE-2019-25218 | MEDIUM | 4.9 | 0.5% | Oct 19, 2024 | The Photo Gallery Slideshow & Masonry Tiled Gallery plugin for WordPress is vulnerable to SQL Injection via the 'id' par... |
| CVE-2019-25216 | MEDIUM | 6.1 | 0.5% | Oct 16, 2024 | The Rich Review plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the POST body 'update' parameter i... |
| CVE-2019-25214 | MEDIUM | 6.1 | 0.3% | Oct 16, 2024 | The ShopWP plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several REST ... |
| CVE-2019-25212 | MEDIUM | 4.9 | 0.5% | Sep 11, 2024 | The video carousel slider with lightbox plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in al... |
| CVE-2019-19754 | MEDIUM | 5.7 | 0.2% | Apr 30, 2024 | HiveOS through 0.6-102@191212 ships with SSH host keys baked into the installation image, which allows man-in-the-middle... |
| CVE-2019-19751 | MEDIUM | 5.6 | 0.3% | Apr 30, 2024 | easyMINE before 2019-12-05 ships with SSH host keys baked into the installation image, which allows man-in-the-middle at... |
| CVE-2019-25210 | MEDIUM | 6.5 | 0.7% | Mar 3, 2024 | An issue was discovered in Cloud Native Computing Foundation (CNCF) Helm through 3.13.3. It displays values of secrets w... |
| CVE-2019-25157 | MEDIUM | 4.3 | 0.7% | Dec 19, 2023 | A vulnerability was found in Ethex Contracts. It has been classified as critical. This affects an unknown part of the fi... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now