2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-25312MEDIUM5.4InoERP 0.7.2 contains a persistent cross-site scripting vulnerability in the comment section that allows unauthenticated...
CVE-2019-25311MEDIUM5.4thesystem version 1.0 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious...
CVE-2019-25310HIGH8.5ActiveFax Server 6.92 Build 0316 contains an unquoted service path vulnerability in the ActiveFaxServiceNT service that ...
CVE-2019-25309HIGH8.5Zilab Remote Console Server 3.2.9 contains an unquoted service path vulnerability that allows local attackers to potenti...
CVE-2019-25308HIGH8.5Mikogo 5.2.2.150317 contains an unquoted service path vulnerability in the Mikogo-Service Windows service configuration....
CVE-2019-25307HIGH8.5WorkgroupMail 7.5.1 contains an unquoted service path vulnerability in its Windows service configuration that allows loc...
CVE-2019-25306HIGH8.5BlackMoon FTP Server 3.1.2.1731 contains an unquoted service path vulnerability that allows local users to potentially e...
CVE-2019-25305HIGH8.5JumpStart 0.6.0.0 contains an unquoted service path vulnerability in the jswpbapi service running with LocalSystem privi...
CVE-2019-25304HIGH8.5SecurOS Enterprise 10.2 contains an unquoted service path vulnerability in the SecurosCtrlService that allows local user...
CVE-2019-25303HIGH7.1TheJshen ContentManagementSystem 1.04 contains a SQL injection vulnerability that allows attackers to manipulate databas...
CVE-2019-25302HIGH8.5Acer Launch Manager 6.1.7600.16385 contains an unquoted service path vulnerability in the DsiWMIService that allows loca...
CVE-2019-25301MEDIUM6.4Millhouse-Project 1.414 contains a persistent cross-site scripting vulnerability in the comment submission functionality...
CVE-2019-25300HIGH7.1thejshen Globitek CMS 1.4 contains a SQL injection vulnerability that allows attackers to manipulate database queries th...
CVE-2019-25299HIGH7.1RimbaLinux AhadPOS 1.11 contains a SQL injection vulnerability in the 'alamatCustomer' parameter that allows attackers t...
CVE-2019-25298CRITICAL9.1html5_snmp 1.11 contains multiple SQL injection vulnerabilities that allow attackers to manipulate database queries thro...
CVE-2019-25294MEDIUM6.1html5_snmp 1.11 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scrip...
CVE-2019-25293HIGH8.5BlueStacks App Player 2.4.44.62.57 contains an unquoted service path vulnerability in the BstHdLogRotatorSvc service tha...
CVE-2019-25292HIGH8.5Alps HID Monitor Service 8.1.0.10 contains an unquoted service path vulnerability that allows local attackers to potenti...
CVE-2019-25266HIGH8.5Wondershare Application Framework Service 2.4.3.231 contains an unquoted service path vulnerability that allows local at...
CVE-2019-25288HIGH8.5Wacom WTabletService 6.6.7-3 contains an unquoted service path vulnerability that allows local attackers to execute mali...
CVE-2019-25287HIGH8.5Adaware Web Companion version 4.8.2078.3950 contains an unquoted service path vulnerability in the WCAssistantService th...
CVE-2019-25286HIGH8.5GCafé 3.0 contains an unquoted service path vulnerability in the gbClientService that allows local attackers to potentia...
CVE-2019-25285HIGH8.5Alps Pointing-device Controller 8.1202.1711.04 contains an unquoted service path vulnerability in the ApHidMonitorServic...
CVE-2019-25283HIGH8.5Shrew Soft VPN Client 2.2.2 contains an unquoted service path vulnerability that allows local users to execute arbitrary...
CVE-2019-25281HIGH8.5NCP Secure Entry Client 9.2 contains an unquoted service path vulnerability in multiple Windows services that allows loc...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now