Skip to main content

Year archive

CVEs published in 2019

Archive summary

17,305 CVEs published in 2019 — 2,593 Critical, 7,142 High, 7,228 Medium, 342 Low, 0 Unrated.

CVE-2019-6012

Published Dec 26, 2019

SQL injection vulnerability in the wpDataTables Lite Version 2.0.11 and earlier allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2019-6011

Published Dec 26, 2019

Cross-site scripting vulnerability in wpDataTables Lite Version 2.0.11 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-19681

Published Dec 26, 2019

Pandora FMS 7.x suffers from remote code execution vulnerability. With an authenticated user who can modify the alert system, it is possible to define and execute commands as root…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-19542

Published Dec 26, 2019

The ListingPro theme before v2.0.14.2 for WordPress has Persistent XSS via the Good For field on the new listing submit page.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-19541

Published Dec 26, 2019

The ListingPro theme before v2.0.14.2 for WordPress has Persistent XSS via the Best Day/Night field on the new listing submit page.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-19540

Published Dec 26, 2019

The ListingPro theme before v2.0.14.2 for WordPress has Reflected XSS via the What field on the homepage.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-15694

Published Dec 26, 2019

TigerVNC version prior to 1.10.1 is vulnerable to heap buffer overflow, which could be triggered from DecodeManager::decodeRect. Vulnerability occurs due to the signdness error in…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2019-15693

Published Dec 26, 2019

TigerVNC version prior to 1.10.1 is vulnerable to heap buffer overflow, which occurs in TightDecoder::FilterGradient. Exploitation of this vulnerability could potentially result i…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2019-15692

Published Dec 26, 2019

TigerVNC version prior to 1.10.1 is vulnerable to heap buffer overflow. Vulnerability could be triggered from CopyRectDecoder due to incorrect value checks. Exploitation of this v…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2019-15691

Published Dec 26, 2019

TigerVNC version prior to 1.10.1 is vulnerable to stack use-after-return, which occurs due to incorrect usage of stack memory in ZRLEDecoder. If decoding routine would throw an ex…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2019-20000

Published Dec 26, 2019

The malware scan function in BullGuard Premium Protection 20.0.371.8 has a TOCTOU issue that enables a symbolic link attack, allowing privileged files to be deleted.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-19999

Published Dec 26, 2019

Halo before 1.2.0-beta.1 allows Server Side Template Injection (SSTI) because TemplateClassResolver.SAFER_RESOLVER is not used in the FreeMarker configuration.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2019-19985

Published Dec 26, 2019

The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed unauthenticated file download with user information disclosure.

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2019-19984

Published Dec 26, 2019

The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed users with edit_post capabilities to manage plugin settings and email campaigns.

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2019-19983

Published Dec 26, 2019

In the WordPress plugin, Fast Velocity Minify before 2.7.7, the full web root path to the running WordPress application can be discovered. In order to exploit this vulnerability,…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2019-19982

Published Dec 26, 2019

The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for unauthenticated option creation. In order to exploit this vulnerability, an attacke…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2019-19981

Published Dec 26, 2019

The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for CSRF to be exploited on all plugin settings.

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2019-19980

Published Dec 26, 2019

The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a privilege bypass flaw that allowed authenticated users (Subscriber or greater access) to send test emails…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2019-19979

Published Dec 26, 2019

A flaw in the WordPress plugin, WP Maintenance before 5.0.6, allowed attackers to enable a vulnerable site's maintenance mode and inject malicious code affecting site visitors. Th…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2019-19977

Published Dec 26, 2019

libESMTP through 1.0.6 mishandles domain copying into a fixed-size buffer in ntlm_build_type_2 in ntlm/ntlmstruct.c, as demonstrated by a stack-based buffer over-read.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 251-275 of 17,305 CVEsPage 11 of 693