2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2019-11604An issue was discovered in Quest KACE Systems Management Appliance before 9.1. The script at /service/kbot_service_notso...
CVE-2019-10848Computrols CBAS 18.0.0 allows Username Enumeration.
CVE-2019-10847Computrols CBAS 18.0.0 allows Cross-Site Request Forgery.
CVE-2019-12315Samsung SCX-824 printers allow a reflected Cross-Site-Scripting (XSS) vulnerability that can be triggered by using the "...
CVE-2019-12195TP-Link TL-WR840N v5 00000005 devices allow XSS via the network name. The attacker must log into the router by breaking ...
CVE-2019-12155interface_release_resource in hw/display/qxl.c in QEMU 3.1.x through 4.0.0 has a NULL pointer dereference.
CVE-2019-12150Karamasoft UltimateEditor 1 does not ensure that an uploaded file is an image or document (neither file types nor extens...
CVE-2019-11876In PrestaShop 1.7.5.2, the shop_country parameter in the install/index.php installation script/component is affected by ...
CVE-2019-11875In AutomateAppCore.dll in Blue Prism Robotic Process Automation 6.4.0.8445, a vulnerability in access control can be exp...
CVE-2019-12314Deltek Maconomy 2.2.5 is prone to local file inclusion via absolute path traversal in the WS.macx1.W_MCS/ PATH_INFO, as ...
CVE-2019-12313XSS exists in Shave before 2.5.3 because output encoding is mishandled during the overwrite of an HTML element.
CVE-2019-12312In Libreswan 3.27 an assertion failure can lead to a pluto IKE daemon restart. An attacker can trigger a NULL pointer de...
CVE-2019-12309dotCMS before 5.1.0 has a path traversal vulnerability exploitable by an administrator to create files. The vulnerabilit...
CVE-2019-10850Computrols CBAS 18.0.0 has Default Credentials.
CVE-2019-10849Computrols CBAS 18.0.0 allows unprotected Subversion (SVN) directory / source code disclosure.
CVE-2019-10866In the Form Maker plugin before 1.13.3 for WordPress, it's possible to achieve SQL injection in the function get_labels_...
CVE-2019-10855Computrols CBAS 18.0.0 mishandles password hashes. The approach is MD5 with a pw prefix, e.g., if the password is admin,...
CVE-2019-10854Computrols CBAS 18.0.0 allows Authenticated Command Injection.
CVE-2019-10853Computrols CBAS 18.0.0 allows Authentication Bypass.
CVE-2019-10852Computrols CBAS 18.0.0 allows Authenticated Blind SQL Injection via the id GET parameter, as demonstrated by the index.p...
CVE-2019-10851Computrols CBAS 18.0.0 has hard-coded encryption keys.
CVE-2019-7128Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier ver...
CVE-2019-7127Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier ver...
CVE-2019-7124Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier ver...
CVE-2019-7123Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier ver...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now