2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-25277MEDIUM6.1FaceSentry Access Control System 6.4.8 contains a cross-site scripting vulnerability in the 'msg' parameter of pluginIns...
CVE-2019-25270MEDIUM6.1SOCA Access Control System 180612 contains a cross-site scripting vulnerability in the 'senddata' POST parameter of logg...
CVE-2019-25268CRITICAL9.8NREL BEopt 2.8.0.0 contains a DLL hijacking vulnerability that allows attackers to load arbitrary libraries by tricking ...
CVE-2019-25259MEDIUM5.3Leica Geosystems GR10/GR25/GR30/GR50 GNSS 4.30.063 contains a cross-site request forgery vulnerability that allows attac...
CVE-2019-25231HIGH8.5devolo dLAN Cockpit 4.3.1 contains an unquoted service path vulnerability in the 'DevoloNetworkService' that allows loca...
CVE-2019-25262MEDIUM5.1A security vulnerability has been detected in elinicksic Razgover up to db37dfc5c82f023a40f2f7834ded6633fb2b5262. This a...
CVE-2019-25258HIGH7.5LogicalDOC Enterprise 7.7.4 contains multiple post-authentication file disclosure vulnerabilities that allow attackers t...
CVE-2019-25257HIGH8.7LogicalDOC Enterprise 7.7.4 contains multiple authenticated OS command execution vulnerabilities that allow attackers to...
CVE-2019-25256HIGH7.1VideoFlow Digital Video Protection DVP 2.10 contains an authenticated directory traversal vulnerability that allows atta...
CVE-2019-25255HIGH8.7VideoFlow Digital Video Protection DVP 2.10 contains an authenticated remote code execution vulnerability that allows at...
CVE-2019-25254HIGH8.8KYOCERA Net Admin 3.4.0906 contains a cross-site request forgery vulnerability that allows attackers to create administr...
CVE-2019-25253HIGH7.5KYOCERA Net Admin 3.4.0906 contains an XML External Entity (XXE) injection vulnerability in the Multi-Set Template Edito...
CVE-2019-25252MEDIUM5.1Teradek VidiU Pro 3.0.3 contains a cross-site request forgery vulnerability that allows attackers to change administrati...
CVE-2019-25251MEDIUM6.9Teradek VidiU Pro 3.0.3 contains a server-side request forgery vulnerability in the management interface that allows att...
CVE-2019-25250MEDIUM5.3Devolo dLAN 500 AV Wireless+ 3.1.0-1 contains a cross-site request forgery vulnerability that allows attackers to perfor...
CVE-2019-25249CRITICAL9.8devolo dLAN 500 AV Wireless+ 3.1.0-1 contains an authentication bypass vulnerability that allows attackers to enable hid...
CVE-2019-25248HIGH8.7Beward N100 M2.1.6.04C014 contains an unauthenticated vulnerability that allows remote attackers to access live video st...
CVE-2019-25247MEDIUM5.3Beward N100 H.264 VGA IP Camera M2.1.6 contains a cross-site request forgery vulnerability that allows attackers to perf...
CVE-2019-25246HIGH8.8Beward N100 H.264 VGA IP Camera M2.1.6 contains an authenticated file disclosure vulnerability that allows attackers to ...
CVE-2019-25245HIGH8.8Ross Video DashBoard 8.5.1 contains an elevation of privileges vulnerability that allows authenticated users to modify e...
CVE-2019-25244MEDIUM5.3Legrand BTicino Driver Manager F454 1.0.51 contains multiple web vulnerabilities that allow attackers to perform adminis...
CVE-2019-25243HIGH8.8FaceSentry 6.4.8 contains an authenticated remote command injection vulnerability in pingTest.php and tcpPortTest.php sc...
CVE-2019-25242MEDIUM5.1FaceSentry Access Control System 6.4.8 contains a cross-site request forgery vulnerability that allows attackers to perf...
CVE-2019-25241CRITICAL9.8FaceSentry Access Control System 6.4.8 contains a critical authentication vulnerability with hard-coded SSH credentials ...
CVE-2019-25240CRITICAL9.8Rifatron 5brid DVR contains an unauthenticated vulnerability in the animate.cgi script that allows unauthorized access t...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now