2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-18285MEDIUM5.9A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The RMI com...
CVE-2019-18284CRITICAL9.8A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The AdminSe...
CVE-2019-18283CRITICAL9.8A vulnerability has been identified in SPPA-T3000 Application Server (All versions < Service Pack R8.2 SP2). The AdminSe...
CVE-2019-13947MEDIUM4.9A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The user configuration menu ...
CVE-2019-13944MEDIUM5.3A vulnerability has been identified in EN100 Ethernet module DNP3 variant (All versions), EN100 Ethernet module IEC 6185...
CVE-2019-13943MEDIUM6.1A vulnerability has been identified in EN100 Ethernet module DNP3 variant (All versions), EN100 Ethernet module IEC 6185...
CVE-2019-13942HIGH7.5A vulnerability has been identified in EN100 Ethernet module DNP3 variant (All versions), EN100 Ethernet module IEC 6185...
CVE-2019-13932CRITICAL9.1A vulnerability has been identified in XHQ (All versions < V6.0.0.2). The web application requests could be manipulated,...
CVE-2019-13931MEDIUM5.4A vulnerability has been identified in XHQ (All versions < V6.0.0.2). The web interface could allow for an an attacker t...
CVE-2019-13930HIGH8.1A vulnerability has been identified in XHQ (All versions < V6.0.0.2). The web interface could allow a Cross-Site Request...
CVE-2019-19750CRITICAL9.8minerstat msOS before 2019-10-23 does not have a unique SSH key for each instance of the product.
CVE-2019-4606HIGH7.8IBM DB2 High Performance Unload load for LUW 6.1 and 6.5 could allow a local attacker to execute arbitrary code on the s...
CVE-2019-19248HIGH7.8Electronic Arts Origin through 10.5.x allows Elevation of Privilege (issue 2 of 2).
CVE-2019-19247HIGH7.8Electronic Arts Origin through 10.5.x allows Elevation of Privilege (issue 1 of 2).
CVE-2019-19198MEDIUM5.4The Scoutnet Kalender plugin 1.1.0 for WordPress allows XSS.
CVE-2019-18345CRITICAL9.3A reflected XSS issue was discovered in DAViCal through 1.1.8. It echoes the action parameter without encoding. If a use...
CVE-2019-17428MEDIUM5.9An issue was discovered in Intesync Solismed 3.3sp1. An flaw in the encryption implementation exists, allowing for all e...
CVE-2019-17358HIGH8.1Cacti through 1.2.7 is affected by multiple instances of lib/functions.php unsafe deserialization of user-controlled dat...
CVE-2019-16246CRITICAL9.8Intesync Solismed 3.3sp1 allows Local File Inclusion (LFI), a different vulnerability than CVE-2019-15931. This leads to...
CVE-2019-15936CRITICAL9.8Intesync Solismed 3.3sp allows Insecure File Upload.
CVE-2019-15935MEDIUM6.1Intesync Solismed 3.3sp has XSS.
CVE-2019-15934HIGH8.8Intesync Solismed 3.3sp has CSRF.
CVE-2019-15933CRITICAL9.8Intesync Solismed 3.3sp has SQL Injection.
CVE-2019-15932CRITICAL9.8Intesync Solismed 3.3sp has Incorrect Access Control.
CVE-2019-15931CRITICAL9.8Intesync Solismed 3.3sp allows Directory Traversal, a different vulnerability than CVE-2019-16246.

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now