2019 CVE Vulnerabilities

17,624 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-25284MEDIUM6.1V-SOL GPON/EPON OLT Platform v2.03 contains multiple reflected cross-site scripting vulnerabilities due to improper inpu...
CVE-2019-25282CRITICAL9.8V-SOL GPON/EPON OLT Platform v2.03 contains an open redirect vulnerability in the script that allows attackers to manipu...
CVE-2019-25280MEDIUM6.1Yahei-PHP Prober 0.4.7 contains a remote HTML injection vulnerability that allows attackers to execute arbitrary HTML co...
CVE-2019-25279HIGH7.5FaceSentry Access Control System 6.4.8 contains a cleartext password storage vulnerability that allows attackers to acce...
CVE-2019-25278CRITICAL9.1FaceSentry Access Control System 6.4.8 contains a cleartext transmission vulnerability that allows remote attackers to i...
CVE-2019-25277MEDIUM6.1FaceSentry Access Control System 6.4.8 contains a cross-site scripting vulnerability in the 'msg' parameter of pluginIns...
CVE-2019-25270MEDIUM6.1SOCA Access Control System 180612 contains a cross-site scripting vulnerability in the 'senddata' POST parameter of logg...
CVE-2019-25268CRITICAL9.8NREL BEopt 2.8.0.0 contains a DLL hijacking vulnerability that allows attackers to load arbitrary libraries by tricking ...
CVE-2019-25259MEDIUM5.3Leica Geosystems GR10/GR25/GR30/GR50 GNSS 4.30.063 contains a cross-site request forgery vulnerability that allows attac...
CVE-2019-25231HIGH8.5devolo dLAN Cockpit 4.3.1 contains an unquoted service path vulnerability in the 'DevoloNetworkService' that allows loca...
CVE-2019-25262MEDIUM5.1A security vulnerability has been detected in elinicksic Razgover up to db37dfc5c82f023a40f2f7834ded6633fb2b5262. This a...
CVE-2019-25258HIGH7.5LogicalDOC Enterprise 7.7.4 contains multiple post-authentication file disclosure vulnerabilities that allow attackers t...
CVE-2019-25257HIGH8.7LogicalDOC Enterprise 7.7.4 contains multiple authenticated OS command execution vulnerabilities that allow attackers to...
CVE-2019-25256HIGH7.1VideoFlow Digital Video Protection DVP 2.10 contains an authenticated directory traversal vulnerability that allows atta...
CVE-2019-25255HIGH8.7VideoFlow Digital Video Protection DVP 2.10 contains an authenticated remote code execution vulnerability that allows at...
CVE-2019-25254HIGH8.8KYOCERA Net Admin 3.4.0906 contains a cross-site request forgery vulnerability that allows attackers to create administr...
CVE-2019-25253HIGH7.5KYOCERA Net Admin 3.4.0906 contains an XML External Entity (XXE) injection vulnerability in the Multi-Set Template Edito...
CVE-2019-25252MEDIUM5.1Teradek VidiU Pro 3.0.3 contains a cross-site request forgery vulnerability that allows attackers to change administrati...
CVE-2019-25251MEDIUM6.9Teradek VidiU Pro 3.0.3 contains a server-side request forgery vulnerability in the management interface that allows att...
CVE-2019-25250MEDIUM5.3Devolo dLAN 500 AV Wireless+ 3.1.0-1 contains a cross-site request forgery vulnerability that allows attackers to perfor...
CVE-2019-25249CRITICAL9.8devolo dLAN 500 AV Wireless+ 3.1.0-1 contains an authentication bypass vulnerability that allows attackers to enable hid...
CVE-2019-25248HIGH8.7Beward N100 M2.1.6.04C014 contains an unauthenticated vulnerability that allows remote attackers to access live video st...
CVE-2019-25247MEDIUM5.3Beward N100 H.264 VGA IP Camera M2.1.6 contains a cross-site request forgery vulnerability that allows attackers to perf...
CVE-2019-25246HIGH8.8Beward N100 H.264 VGA IP Camera M2.1.6 contains an authenticated file disclosure vulnerability that allows attackers to ...
CVE-2019-25245HIGH8.8Ross Video DashBoard 8.5.1 contains an elevation of privileges vulnerability that allows authenticated users to modify e...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now