2019 CVE Vulnerabilities
17,621 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-19021 | CRITICAL | 9.8 | 1.4% | Dec 2, 2019 | An issue was discovered in TitanHQ WebTitan before 5.18. It has a hidden support account (with a hard-coded password) in... |
| CVE-2019-19020 | HIGH | 7.2 | 2.3% | Dec 2, 2019 | An issue was discovered in TitanHQ WebTitan before 5.18. In the administration web interface it is possible to upload a ... |
| CVE-2019-19019 | HIGH | 7.5 | 1.6% | Dec 2, 2019 | An issue was discovered in TitanHQ WebTitan before 5.18. It contains a Remote Code Execution issue through which an atta... |
| CVE-2019-19018 | LOW | 2.7 | 0.8% | Dec 2, 2019 | An issue was discovered in TitanHQ WebTitan before 5.18. It exposes a database configuration file under /include/dbconfi... |
| CVE-2019-19017 | HIGH | 8.1 | 1.1% | Dec 2, 2019 | An issue was discovered in TitanHQ WebTitan before 5.18. The appliance has a hard-coded root password set during install... |
| CVE-2019-19016 | HIGH | 7.5 | 1.2% | Dec 2, 2019 | An issue was discovered in TitanHQ WebTitan before 5.18. Some functions, such as /history-x.php, of the administration i... |
| CVE-2019-19015 | CRITICAL | 9.8 | 3.3% | Dec 2, 2019 | An issue was discovered in TitanHQ WebTitan before 5.18. The proxy service (which is typically exposed to all users) all... |
| CVE-2019-19014 | HIGH | 7.8 | 0.5% | Dec 2, 2019 | An issue was discovered in TitanHQ WebTitan before 5.18. It has a sudoers file that enables low-privilege users to execu... |
| CVE-2019-12518 | CRITICAL | 9.8 | 50.7% | Dec 2, 2019 | Anviz CrossChex access control management software 4.3.8.0 and 4.3.12 is vulnerable to a buffer overflow vulnerability. |
| CVE-2019-12503 | CRITICAL | 9.8 | 2.0% | Dec 2, 2019 | Due to unencrypted and unauthenticated data communication, the wireless barcode scanner Inateck BCST-60 is prone to keys... |
| CVE-2019-12394 | CRITICAL | 9.8 | 2.1% | Dec 2, 2019 | Anviz access control devices allow unverified password change which allows remote attackers to change the administrator ... |
| CVE-2019-12393 | HIGH | 7.5 | 1.1% | Dec 2, 2019 | Anviz access control devices are vulnerable to replay attacks which could allow attackers to intercept and replay open d... |
| CVE-2019-12392 | CRITICAL | 9.8 | 1.9% | Dec 2, 2019 | Anviz access control devices allow remote attackers to issue commands without a password. |
| CVE-2019-12391 | HIGH | 7.5 | 1.1% | Dec 2, 2019 | The Anviz Management System for access control has insufficient logging for device events such as door open requests. |
| CVE-2019-12390 | MEDIUM | 5.3 | 1.4% | Dec 2, 2019 | Anviz access control devices expose private Information (pin code and name) by allowing remote attackers to query this i... |
| CVE-2019-12389 | HIGH | 7.5 | 1.8% | Dec 2, 2019 | Anviz access control devices expose credentials (names and passwords) by allowing remote attackers to query this informa... |
| CVE-2019-12388 | HIGH | 7.5 | 0.8% | Dec 2, 2019 | Anviz access control devices perform cleartext transmission of sensitive information (passwords/pins and names) when rep... |
| CVE-2019-19502 | CRITICAL | 9.8 | 1.9% | Dec 2, 2019 | Code injection in pluginconfig.php in Image Uploader and Browser for CKEditor before 4.1.9 allows remote authenticated u... |
| CVE-2019-15628 | HIGH | 7.8 | 0.5% | Dec 2, 2019 | Trend Micro Security (Consumer) 2020 (v16.0.1221 and below) is affected by a DLL hijacking vulnerability that could allo... |
| CVE-2019-19245 | CRITICAL | 9.8 | 7.9% | Dec 2, 2019 | NAPC Xinet Elegant 6 Asset Library 6.1.655 allows Pre-Authentication SQL Injection via the /elegant6/login LoginForm[use... |
| CVE-2019-19118 | MEDIUM | 6.5 | 1.7% | Dec 2, 2019 | Django 2.1 before 2.1.15 and 2.2 before 2.2.8 allows unintended model editing. A Django model admin displaying inline re... |
| CVE-2019-19496 | MEDIUM | 5.4 | 0.6% | Dec 2, 2019 | Alfresco Enterprise before 5.2.5 allows stored XSS via an uploaded HTML document. |
| CVE-2019-19493 | MEDIUM | 5.4 | 2.0% | Dec 2, 2019 | Kentico before 12.0.50 allows file uploads in which the Content-Type header is inconsistent with the file extension, lea... |
| CVE-2019-19362 | MEDIUM | 6.5 | 2.1% | Dec 2, 2019 | An issue was discovered in the Chat functionality of the TeamViewer desktop application 14.3.4730 on Windows. (The vendo... |
| CVE-2019-19492 | CRITICAL | 9.8 | 29.0% | Dec 2, 2019 | FreeSWITCH 1.6.10 through 1.10.1 has a default password in event_socket.conf.xml. |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now