2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-14478MEDIUM5.4AdRem NetCrunch 10.6.0.4587 has a stored Cross-Site Scripting (XSS) vulnerability in the NetCrunch web client. The user'...
CVE-2019-14476MEDIUM6.5AdRem NetCrunch 10.6.0.4587 has a Server-Side Request Forgery (SSRF) vulnerability in the NetCrunch server. Every user c...
CVE-2019-14483HIGH8.8AdRem NetCrunch 10.6.0.4587 allows Credentials Disclosure. Every user can read the BSD, Linux, MacOS and Solaris private...
CVE-2019-14482CRITICAL9.8AdRem NetCrunch 10.6.0.4587 has a hardcoded SSL private key vulnerability in the NetCrunch web client. The same hardcode...
CVE-2019-14480CRITICAL9.8AdRem NetCrunch 10.6.0.4587 has an Improper Session Handling vulnerability in the NetCrunch web client, which can lead t...
CVE-2019-14477MEDIUM5.5AdRem NetCrunch 10.6.0.4587 has Improper Credential Storage since the internal user database is readable by low-privileg...
CVE-2019-19289HIGH8.8A vulnerability has been identified in XHQ (All Versions < 6.1). The web interface could allow a Cross-Site Request Forg...
CVE-2019-19288MEDIUM6.1A vulnerability has been identified in XHQ (All Versions < 6.1). The web interface could allow Cross-Site Scripting (XSS...
CVE-2019-19287MEDIUM6.5A vulnerability has been identified in XHQ (All Versions < 6.1). The web interface could allow attackers to traverse thr...
CVE-2019-19286HIGH7.2A vulnerability has been identified in XHQ (All Versions < 6.1). The web interface could allow SQL injection attacks if ...
CVE-2019-19285MEDIUM5.4A vulnerability has been identified in XHQ (All Versions < 6.1). The web interface could allow injections that could lea...
CVE-2019-19284MEDIUM5.4A vulnerability has been identified in XHQ (All Versions < 6.1). The web interface could allow Cross-Site Scripting (XSS...
CVE-2019-19283MEDIUM5.3A vulnerability has been identified in XHQ (All Versions < 6.1). The application's web server could expose non-sensitive...
CVE-2019-4738MEDIUM6.5IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 and 6.0.0.0 through 6.0.3.1 discloses sensitive inf...
CVE-2019-7198CRITICAL9.8This command injection vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP h...
CVE-2019-16958MEDIUM5.4Cross-site Scripting (XSS) vulnerability in SolarWinds Web Help Desk 12.7.0 allows attacker to inject arbitrary web scri...
CVE-2019-20934MEDIUM5.3An issue was discovered in the Linux kernel before 5.2.6. On NUMA systems, the Linux fair scheduler has a use-after-free...
CVE-2019-19878HIGH7.5An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. An attacker can get access to historical d...
CVE-2019-19877MEDIUM5.3An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. An attacker can get access to sensitive in...
CVE-2019-19876CRITICAL9.8An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. An EnMon PHP script was vulnerable to SQL ...
CVE-2019-19875CRITICAL9.8An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. Arbitrary commands could be injected (usin...
CVE-2019-19874CRITICAL9.8An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. Some web scripts in the web interface allo...
CVE-2019-19873HIGH7.5An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. An attacker can get information from the A...
CVE-2019-19872CRITICAL9.8An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. The AprolLoader could be used to inject an...
CVE-2019-19869HIGH7.5An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. PVs could be changed (unencrypted) by usin...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now