2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-11604 | — | — | 1.8% | May 24, 2019 | An issue was discovered in Quest KACE Systems Management Appliance before 9.1. The script at /service/kbot_service_notso... |
| CVE-2019-10848 | — | — | 8.5% | May 24, 2019 | Computrols CBAS 18.0.0 allows Username Enumeration. |
| CVE-2019-10847 | — | — | 2.4% | May 24, 2019 | Computrols CBAS 18.0.0 allows Cross-Site Request Forgery. |
| CVE-2019-12315 | — | — | 0.8% | May 24, 2019 | Samsung SCX-824 printers allow a reflected Cross-Site-Scripting (XSS) vulnerability that can be triggered by using the "... |
| CVE-2019-12195 | — | — | 1.8% | May 24, 2019 | TP-Link TL-WR840N v5 00000005 devices allow XSS via the network name. The attacker must log into the router by breaking ... |
| CVE-2019-12155 | — | — | 5.5% | May 24, 2019 | interface_release_resource in hw/display/qxl.c in QEMU 3.1.x through 4.0.0 has a NULL pointer dereference. |
| CVE-2019-12150 | — | — | 1.7% | May 24, 2019 | Karamasoft UltimateEditor 1 does not ensure that an uploaded file is an image or document (neither file types nor extens... |
| CVE-2019-11876 | — | — | 0.9% | May 24, 2019 | In PrestaShop 1.7.5.2, the shop_country parameter in the install/index.php installation script/component is affected by ... |
| CVE-2019-11875 | — | — | 2.3% | May 24, 2019 | In AutomateAppCore.dll in Blue Prism Robotic Process Automation 6.4.0.8445, a vulnerability in access control can be exp... |
| CVE-2019-12314 | — | — | 84.2% | May 24, 2019 | Deltek Maconomy 2.2.5 is prone to local file inclusion via absolute path traversal in the WS.macx1.W_MCS/ PATH_INFO, as ... |
| CVE-2019-12313 | — | — | 1.3% | May 24, 2019 | XSS exists in Shave before 2.5.3 because output encoding is mishandled during the overwrite of an HTML element. |
| CVE-2019-12312 | — | — | 2.7% | May 24, 2019 | In Libreswan 3.27 an assertion failure can lead to a pluto IKE daemon restart. An attacker can trigger a NULL pointer de... |
| CVE-2019-12309 | — | — | 1.3% | May 23, 2019 | dotCMS before 5.1.0 has a path traversal vulnerability exploitable by an administrator to create files. The vulnerabilit... |
| CVE-2019-10850 | — | — | 1.9% | May 23, 2019 | Computrols CBAS 18.0.0 has Default Credentials. |
| CVE-2019-10849 | — | — | 9.0% | May 23, 2019 | Computrols CBAS 18.0.0 allows unprotected Subversion (SVN) directory / source code disclosure. |
| CVE-2019-10866 | — | — | 6.2% | May 23, 2019 | In the Form Maker plugin before 1.13.3 for WordPress, it's possible to achieve SQL injection in the function get_labels_... |
| CVE-2019-10855 | — | — | 1.0% | May 23, 2019 | Computrols CBAS 18.0.0 mishandles password hashes. The approach is MD5 with a pw prefix, e.g., if the password is admin,... |
| CVE-2019-10854 | — | — | 3.0% | May 23, 2019 | Computrols CBAS 18.0.0 allows Authenticated Command Injection. |
| CVE-2019-10853 | — | — | 1.7% | May 23, 2019 | Computrols CBAS 18.0.0 allows Authentication Bypass. |
| CVE-2019-10852 | — | — | 1.8% | May 23, 2019 | Computrols CBAS 18.0.0 allows Authenticated Blind SQL Injection via the id GET parameter, as demonstrated by the index.p... |
| CVE-2019-10851 | — | — | 0.7% | May 23, 2019 | Computrols CBAS 18.0.0 has hard-coded encryption keys. |
| CVE-2019-7128 | — | — | 6.5% | May 23, 2019 | Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier ver... |
| CVE-2019-7127 | — | — | 12.1% | May 23, 2019 | Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier ver... |
| CVE-2019-7124 | — | — | 6.0% | May 23, 2019 | Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier ver... |
| CVE-2019-7123 | — | — | 3.2% | May 23, 2019 | Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier ver... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now