2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-18871 | HIGH | 8.8 | 2.5% | May 7, 2020 | A path traversal in debug.php accessed via default.php in Blaauw Remote Kiln Control through v3.00r4 allows an authentic... |
| CVE-2019-18866 | HIGH | 7.5 | 1.2% | May 7, 2020 | Unauthenticated SQL injection via the username in the login mechanism in Blaauw Remote Kiln Control through v3.00r4 allo... |
| CVE-2019-18864 | HIGH | 7.5 | 1.3% | May 7, 2020 | /server-info and /server-status in Blaauw Remote Kiln Control through v3.00r4 allow an unauthenticated attacker to gain ... |
| CVE-2019-18867 | HIGH | 7.5 | 1.2% | May 7, 2020 | Browsable directories in Blaauw Remote Kiln Control through v3.00r4 allow an attacker to enumerate sensitive filenames a... |
| CVE-2019-19166 | HIGH | 7.8 | 0.4% | May 6, 2020 | Tobesoft XPlatform v9.1, 9.2.0, 9.2.1 and 9.2.2 have a vulnerability that can load unauthorized DLL files. It allows att... |
| CVE-2019-19517 | HIGH | 8.8 | 0.5% | May 5, 2020 | Intelbras RF1200 1.1.3 devices allow CSRF to bypass the login.html form, as demonstrated by launching a scrapy process. |
| CVE-2019-13285 | HIGH | 7.5 | 1.0% | May 4, 2020 | CoSoSys Endpoint Protector 5.1.0.2 allows Host Header Injection. |
| CVE-2019-11823 | HIGH | 7.5 | 2.4% | May 4, 2020 | CRLF injection vulnerability in Network Center in Synology Router Manager (SRM) before 1.2.3-8017-2 allows remote attack... |
| CVE-2019-12425 | HIGH | 7.5 | 4.7% | Apr 30, 2020 | Apache OFBiz 17.12.01 is vulnerable to Host header injection by accepting arbitrary host |
| CVE-2019-0235 | HIGH | 8.8 | 32.7% | Apr 30, 2020 | Apache OFBiz 17.12.01 is vulnerable to some CSRF attacks. |
| CVE-2019-19220 | HIGH | 8.8 | 1.8% | Apr 30, 2020 | BMC Control-M/Agent 7.0.00.000 allows OS Command Injection (issue 2 of 2). |
| CVE-2019-19219 | HIGH | 7.5 | 1.1% | Apr 30, 2020 | BMC Control-M/Agent 7.0.00.000 allows Arbitrary File Download. |
| CVE-2019-19218 | HIGH | 7.5 | 1.0% | Apr 30, 2020 | BMC Control-M/Agent 7.0.00.000 has Insecure Password Storage. |
| CVE-2019-19217 | HIGH | 8.8 | 1.8% | Apr 30, 2020 | BMC Control-M/Agent 7.0.00.000 allows OS Command Injection. |
| CVE-2019-19216 | HIGH | 8.8 | 1.1% | Apr 30, 2020 | BMC Control-M/Agent 7.0.00.000 has an Insecure File Copy. |
| CVE-2019-19215 | HIGH | 8.8 | 1.6% | Apr 30, 2020 | A buffer overflow vulnerability in BMC Control-M/Agent 7.0.00.000 when the On-Do action destination is Mail and the Cont... |
| CVE-2019-5621 | HIGH | 7.8 | 2.2% | Apr 29, 2020 | ABBS Software Audio Media Player version 3.1 suffers from an instance of CWE-121: Stack-based Buffer Overflow. |
| CVE-2019-5618 | HIGH | 7.8 | 2.2% | Apr 29, 2020 | A-PDF WAV to MP3 version 1.0.0 suffers from an instance of CWE-121: Stack-based Buffer Overflow. |
| CVE-2019-16011 | HIGH | 7.8 | 0.4% | Apr 29, 2020 | A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to inject arbitr... |
| CVE-2019-19165 | HIGH | 7.2 | 0.6% | Apr 29, 2020 | AxECM.cab(ActiveX Control) in Inogard Ebiz4u contains a vulnerability that could allow remote files to be downloaded and... |
| CVE-2019-20781 | HIGH | 7.8 | 0.3% | Apr 29, 2020 | An issue was discovered in LG Bridge before April 2019 on Windows. DLL Hijacking can occur. |
| CVE-2019-16653 | HIGH | 8.8 | 2.0% | Apr 29, 2020 | An application plugin in Genius Bytes Genius Server (Genius CDDS) 3.2.2 allows remote authenticated users to gain admin ... |
| CVE-2019-16652 | HIGH | 7.2 | 2.4% | Apr 29, 2020 | The BPM component in Genius Bytes Genius Server (Genius CDDS) 3.2.2 allows remote authenticated users to execute arbitra... |
| CVE-2019-19102 | HIGH | 7.5 | 1.2% | Apr 29, 2020 | A directory traversal vulnerability in SharpZipLib used in the upgrade service in B&R Automation Studio versions 4.0.x, ... |
| CVE-2019-19100 | HIGH | 7.1 | 0.3% | Apr 29, 2020 | A privilege escalation vulnerability in the upgrade service in B&R Automation Studio versions 4.0.x, 4.1.x, 4.2.x, < 4.3... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now