2019 CVE Vulnerabilities

17,624 CVEs published in 2019.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2019-10169HIGH7.2A flaw was found in Keycloak’s user-managed access interface, where it would permit a script to be set in the UMA policy...
CVE-2019-19164HIGH8.8dext5.ocx ActiveX Control in Dext5 Upload 5.0.0.112 and earlier versions contains a vulnerability that could allow remot...
CVE-2019-18872HIGH7.5Weak password requirements in Blaauw Remote Kiln Control through v3.00r4 allow a user to set short or guessable password...
CVE-2019-18871HIGH8.8A path traversal in debug.php accessed via default.php in Blaauw Remote Kiln Control through v3.00r4 allows an authentic...
CVE-2019-18866HIGH7.5Unauthenticated SQL injection via the username in the login mechanism in Blaauw Remote Kiln Control through v3.00r4 allo...
CVE-2019-18864HIGH7.5/server-info and /server-status in Blaauw Remote Kiln Control through v3.00r4 allow an unauthenticated attacker to gain ...
CVE-2019-18867HIGH7.5Browsable directories in Blaauw Remote Kiln Control through v3.00r4 allow an attacker to enumerate sensitive filenames a...
CVE-2019-19166HIGH7.8Tobesoft XPlatform v9.1, 9.2.0, 9.2.1 and 9.2.2 have a vulnerability that can load unauthorized DLL files. It allows att...
CVE-2019-19517HIGH8.8Intelbras RF1200 1.1.3 devices allow CSRF to bypass the login.html form, as demonstrated by launching a scrapy process.
CVE-2019-13285HIGH7.5CoSoSys Endpoint Protector 5.1.0.2 allows Host Header Injection.
CVE-2019-11823HIGH7.5CRLF injection vulnerability in Network Center in Synology Router Manager (SRM) before 1.2.3-8017-2 allows remote attack...
CVE-2019-12425HIGH7.5Apache OFBiz 17.12.01 is vulnerable to Host header injection by accepting arbitrary host
CVE-2019-0235HIGH8.8Apache OFBiz 17.12.01 is vulnerable to some CSRF attacks.
CVE-2019-19220HIGH8.8BMC Control-M/Agent 7.0.00.000 allows OS Command Injection (issue 2 of 2).
CVE-2019-19219HIGH7.5BMC Control-M/Agent 7.0.00.000 allows Arbitrary File Download.
CVE-2019-19218HIGH7.5BMC Control-M/Agent 7.0.00.000 has Insecure Password Storage.
CVE-2019-19217HIGH8.8BMC Control-M/Agent 7.0.00.000 allows OS Command Injection.
CVE-2019-19216HIGH8.8BMC Control-M/Agent 7.0.00.000 has an Insecure File Copy.
CVE-2019-19215HIGH8.8A buffer overflow vulnerability in BMC Control-M/Agent 7.0.00.000 when the On-Do action destination is Mail and the Cont...
CVE-2019-5621HIGH7.8ABBS Software Audio Media Player version 3.1 suffers from an instance of CWE-121: Stack-based Buffer Overflow.
CVE-2019-5618HIGH7.8A-PDF WAV to MP3 version 1.0.0 suffers from an instance of CWE-121: Stack-based Buffer Overflow.
CVE-2019-16011HIGH7.8A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to inject arbitr...
CVE-2019-19165HIGH7.2AxECM.cab(ActiveX Control) in Inogard Ebiz4u contains a vulnerability that could allow remote files to be downloaded and...
CVE-2019-20781HIGH7.8An issue was discovered in LG Bridge before April 2019 on Windows. DLL Hijacking can occur.
CVE-2019-16653HIGH8.8An application plugin in Genius Bytes Genius Server (Genius CDDS) 3.2.2 allows remote authenticated users to gain admin ...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now