2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-25023MEDIUM6.5An issue was discovered in Scytl sVote 2.1. Because the IP address from an X-Forwarded-For header (which can be manipula...
CVE-2019-25022CRITICAL9.8An issue was discovered in Scytl sVote 2.1. An attacker can inject code that gets executed by creating an election-event...
CVE-2019-25021HIGH7.5An issue was discovered in Scytl sVote 2.1. Due to the implementation of the database manager, an attacker can access th...
CVE-2019-25020HIGH7.5An issue was discovered in Scytl sVote 2.1. Because the sdm-ws-rest API does not require authentication, an attacker can...
CVE-2019-11684CRITICAL9.8Improper Access Control in the RCP+ server of the Bosch Video Recording Manager (VRM) component allows arbitrary and una...
CVE-2019-18947LOW3.5Micro Focus Solutions Business Manager Application Repository versions prior to 11.7.1 are vulnerable to information dis...
CVE-2019-18946MEDIUM4.8Micro Focus Solutions Business Manager Application Repository versions prior to 11.7.1 are vulnerable to session fixatio...
CVE-2019-18945HIGH8Micro Focus Solutions Business Manager Application Repository versions prior to 11.7.1 are vulnerable to privilege escal...
CVE-2019-18944MEDIUM4.8Micro Focus Solutions Business Manager Application Repository versions prior to 11.7.1 are vulnerable to reflected XSS.
CVE-2019-18943HIGH8Micro Focus Solutions Business Manager versions prior to 11.7.1 are vulnerable to XML External Entity Processing (XXE) o...
CVE-2019-18942MEDIUM4.8Micro Focus Solutions Business Manager versions prior to 11.7.1 are vulnerable to stored XSS. The application reflects p...
CVE-2019-25024CRITICAL9.8OpenRepeater (ORP) before 2.2 allows unauthenticated command injection via shell metacharacters in the functions/ajax_sy...
CVE-2019-18243MEDIUM5.5HMI/SCADA iFIX (Versions 6.1 and prior) allows a local authenticated user to modify system-wide iFIX configurations thro...
CVE-2019-18255MEDIUM5.5HMI/SCADA iFIX (Versions 6.1 and prior) allows a local authenticated user to modify system-wide iFIX configurations thro...
CVE-2019-25019CRITICAL9.8LimeSurvey before 4.0.0-RC4 allows SQL injection via the participant model.
CVE-2019-19005HIGH7.8A bitmap double free in main.c in autotrace 0.31.1 allows attackers to cause an unspecified impact via a malformed bitma...
CVE-2019-19004LOW3.3A biWidth*biBitCnt integer overflow in input-bmp.c in autotrace 0.31.1 allows attackers to provide an unexpected input v...
CVE-2019-17582CRITICAL9.8A use-after-free in the _zip_dirent_read function of zip_dirent.c in libzip 1.2.0 allows attackers to have an unspecifie...
CVE-2019-16268MEDIUM4.8Zoho ManageEngine Remote Access Plus 10.0.259 allows HTML injection via the Description field on the Admin - User Admini...
CVE-2019-25018HIGH7.5In the rcp client in MIT krb5-appl through 1.0.3, malicious servers could bypass intended access restrictions via the fi...
CVE-2019-25017MEDIUM5.9An issue was discovered in rcp in MIT krb5-appl through 1.0.3. Due to the rcp implementation being derived from 1983 rcp...
CVE-2019-20473MEDIUM6.8An issue was discovered on TK-Star Q90 Junior GPS horloge 3.1042.9.8656 devices. Any SIM card used with the device canno...
CVE-2019-20471HIGH7.8An issue was discovered on TK-Star Q90 Junior GPS horloge 3.1042.9.8656 devices. When using the device at initial setup,...
CVE-2019-20470HIGH7.5An issue was discovered on TK-Star Q90 Junior GPS horloge 3.1042.9.8656 devices. It performs actions based on certain SM...
CVE-2019-20468CRITICAL9.8An issue was discovered in SeTracker2 for TK-Star Q90 Junior GPS horloge 3.1042.9.8656 devices. It has unnecessary permi...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now