2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-25023 | MEDIUM | 6.5 | 0.9% | Feb 27, 2021 | An issue was discovered in Scytl sVote 2.1. Because the IP address from an X-Forwarded-For header (which can be manipula... |
| CVE-2019-25022 | CRITICAL | 9.8 | 1.4% | Feb 27, 2021 | An issue was discovered in Scytl sVote 2.1. An attacker can inject code that gets executed by creating an election-event... |
| CVE-2019-25021 | HIGH | 7.5 | 1.2% | Feb 27, 2021 | An issue was discovered in Scytl sVote 2.1. Due to the implementation of the database manager, an attacker can access th... |
| CVE-2019-25020 | HIGH | 7.5 | 1.3% | Feb 27, 2021 | An issue was discovered in Scytl sVote 2.1. Because the sdm-ws-rest API does not require authentication, an attacker can... |
| CVE-2019-11684 | CRITICAL | 9.8 | 1.0% | Feb 26, 2021 | Improper Access Control in the RCP+ server of the Bosch Video Recording Manager (VRM) component allows arbitrary and una... |
| CVE-2019-18947 | LOW | 3.5 | 0.3% | Feb 26, 2021 | Micro Focus Solutions Business Manager Application Repository versions prior to 11.7.1 are vulnerable to information dis... |
| CVE-2019-18946 | MEDIUM | 4.8 | 0.3% | Feb 26, 2021 | Micro Focus Solutions Business Manager Application Repository versions prior to 11.7.1 are vulnerable to session fixatio... |
| CVE-2019-18945 | HIGH | 8 | 0.3% | Feb 26, 2021 | Micro Focus Solutions Business Manager Application Repository versions prior to 11.7.1 are vulnerable to privilege escal... |
| CVE-2019-18944 | MEDIUM | 4.8 | 0.3% | Feb 26, 2021 | Micro Focus Solutions Business Manager Application Repository versions prior to 11.7.1 are vulnerable to reflected XSS. |
| CVE-2019-18943 | HIGH | 8 | 0.3% | Feb 26, 2021 | Micro Focus Solutions Business Manager versions prior to 11.7.1 are vulnerable to XML External Entity Processing (XXE) o... |
| CVE-2019-18942 | MEDIUM | 4.8 | 0.3% | Feb 26, 2021 | Micro Focus Solutions Business Manager versions prior to 11.7.1 are vulnerable to stored XSS. The application reflects p... |
| CVE-2019-25024 | CRITICAL | 9.8 | 27.6% | Feb 19, 2021 | OpenRepeater (ORP) before 2.2 allows unauthenticated command injection via shell metacharacters in the functions/ajax_sy... |
| CVE-2019-18243 | MEDIUM | 5.5 | 0.2% | Feb 18, 2021 | HMI/SCADA iFIX (Versions 6.1 and prior) allows a local authenticated user to modify system-wide iFIX configurations thro... |
| CVE-2019-18255 | MEDIUM | 5.5 | 0.2% | Feb 18, 2021 | HMI/SCADA iFIX (Versions 6.1 and prior) allows a local authenticated user to modify system-wide iFIX configurations thro... |
| CVE-2019-25019 | CRITICAL | 9.8 | 1.3% | Feb 14, 2021 | LimeSurvey before 4.0.0-RC4 allows SQL injection via the participant model. |
| CVE-2019-19005 | HIGH | 7.8 | 1.0% | Feb 11, 2021 | A bitmap double free in main.c in autotrace 0.31.1 allows attackers to cause an unspecified impact via a malformed bitma... |
| CVE-2019-19004 | LOW | 3.3 | 1.0% | Feb 11, 2021 | A biWidth*biBitCnt integer overflow in input-bmp.c in autotrace 0.31.1 allows attackers to provide an unexpected input v... |
| CVE-2019-17582 | CRITICAL | 9.8 | 2.5% | Feb 9, 2021 | A use-after-free in the _zip_dirent_read function of zip_dirent.c in libzip 1.2.0 allows attackers to have an unspecifie... |
| CVE-2019-16268 | MEDIUM | 4.8 | 1.8% | Feb 3, 2021 | Zoho ManageEngine Remote Access Plus 10.0.259 allows HTML injection via the Description field on the Admin - User Admini... |
| CVE-2019-25018 | HIGH | 7.5 | 1.6% | Feb 2, 2021 | In the rcp client in MIT krb5-appl through 1.0.3, malicious servers could bypass intended access restrictions via the fi... |
| CVE-2019-25017 | MEDIUM | 5.9 | 1.4% | Feb 2, 2021 | An issue was discovered in rcp in MIT krb5-appl through 1.0.3. Due to the rcp implementation being derived from 1983 rcp... |
| CVE-2019-20473 | MEDIUM | 6.8 | 0.4% | Feb 1, 2021 | An issue was discovered on TK-Star Q90 Junior GPS horloge 3.1042.9.8656 devices. Any SIM card used with the device canno... |
| CVE-2019-20471 | HIGH | 7.8 | 0.4% | Feb 1, 2021 | An issue was discovered on TK-Star Q90 Junior GPS horloge 3.1042.9.8656 devices. When using the device at initial setup,... |
| CVE-2019-20470 | HIGH | 7.5 | 1.9% | Feb 1, 2021 | An issue was discovered on TK-Star Q90 Junior GPS horloge 3.1042.9.8656 devices. It performs actions based on certain SM... |
| CVE-2019-20468 | CRITICAL | 9.8 | 2.3% | Feb 1, 2021 | An issue was discovered in SeTracker2 for TK-Star Q90 Junior GPS horloge 3.1042.9.8656 devices. It has unnecessary permi... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now