2019 CVE Vulnerabilities

17,621 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-19021CRITICAL9.8An issue was discovered in TitanHQ WebTitan before 5.18. It has a hidden support account (with a hard-coded password) in...
CVE-2019-19020HIGH7.2An issue was discovered in TitanHQ WebTitan before 5.18. In the administration web interface it is possible to upload a ...
CVE-2019-19019HIGH7.5An issue was discovered in TitanHQ WebTitan before 5.18. It contains a Remote Code Execution issue through which an atta...
CVE-2019-19018LOW2.7An issue was discovered in TitanHQ WebTitan before 5.18. It exposes a database configuration file under /include/dbconfi...
CVE-2019-19017HIGH8.1An issue was discovered in TitanHQ WebTitan before 5.18. The appliance has a hard-coded root password set during install...
CVE-2019-19016HIGH7.5An issue was discovered in TitanHQ WebTitan before 5.18. Some functions, such as /history-x.php, of the administration i...
CVE-2019-19015CRITICAL9.8An issue was discovered in TitanHQ WebTitan before 5.18. The proxy service (which is typically exposed to all users) all...
CVE-2019-19014HIGH7.8An issue was discovered in TitanHQ WebTitan before 5.18. It has a sudoers file that enables low-privilege users to execu...
CVE-2019-12518CRITICAL9.8Anviz CrossChex access control management software 4.3.8.0 and 4.3.12 is vulnerable to a buffer overflow vulnerability.
CVE-2019-12503CRITICAL9.8Due to unencrypted and unauthenticated data communication, the wireless barcode scanner Inateck BCST-60 is prone to keys...
CVE-2019-12394CRITICAL9.8Anviz access control devices allow unverified password change which allows remote attackers to change the administrator ...
CVE-2019-12393HIGH7.5Anviz access control devices are vulnerable to replay attacks which could allow attackers to intercept and replay open d...
CVE-2019-12392CRITICAL9.8Anviz access control devices allow remote attackers to issue commands without a password.
CVE-2019-12391HIGH7.5The Anviz Management System for access control has insufficient logging for device events such as door open requests.
CVE-2019-12390MEDIUM5.3Anviz access control devices expose private Information (pin code and name) by allowing remote attackers to query this i...
CVE-2019-12389HIGH7.5Anviz access control devices expose credentials (names and passwords) by allowing remote attackers to query this informa...
CVE-2019-12388HIGH7.5Anviz access control devices perform cleartext transmission of sensitive information (passwords/pins and names) when rep...
CVE-2019-19502CRITICAL9.8Code injection in pluginconfig.php in Image Uploader and Browser for CKEditor before 4.1.9 allows remote authenticated u...
CVE-2019-15628HIGH7.8Trend Micro Security (Consumer) 2020 (v16.0.1221 and below) is affected by a DLL hijacking vulnerability that could allo...
CVE-2019-19245CRITICAL9.8NAPC Xinet Elegant 6 Asset Library 6.1.655 allows Pre-Authentication SQL Injection via the /elegant6/login LoginForm[use...
CVE-2019-19118MEDIUM6.5Django 2.1 before 2.1.15 and 2.2 before 2.2.8 allows unintended model editing. A Django model admin displaying inline re...
CVE-2019-19496MEDIUM5.4Alfresco Enterprise before 5.2.5 allows stored XSS via an uploaded HTML document.
CVE-2019-19493MEDIUM5.4Kentico before 12.0.50 allows file uploads in which the Content-Type header is inconsistent with the file extension, lea...
CVE-2019-19362MEDIUM6.5An issue was discovered in the Chat functionality of the TeamViewer desktop application 14.3.4730 on Windows. (The vendo...
CVE-2019-19492CRITICAL9.8FreeSWITCH 1.6.10 through 1.10.1 has a default password in event_socket.conf.xml.

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now