2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-14478 | MEDIUM | 5.4 | 0.6% | Dec 16, 2020 | AdRem NetCrunch 10.6.0.4587 has a stored Cross-Site Scripting (XSS) vulnerability in the NetCrunch web client. The user'... |
| CVE-2019-14476 | MEDIUM | 6.5 | 0.8% | Dec 16, 2020 | AdRem NetCrunch 10.6.0.4587 has a Server-Side Request Forgery (SSRF) vulnerability in the NetCrunch server. Every user c... |
| CVE-2019-14483 | HIGH | 8.8 | 1.8% | Dec 16, 2020 | AdRem NetCrunch 10.6.0.4587 allows Credentials Disclosure. Every user can read the BSD, Linux, MacOS and Solaris private... |
| CVE-2019-14482 | CRITICAL | 9.8 | 1.8% | Dec 16, 2020 | AdRem NetCrunch 10.6.0.4587 has a hardcoded SSL private key vulnerability in the NetCrunch web client. The same hardcode... |
| CVE-2019-14480 | CRITICAL | 9.8 | 1.1% | Dec 16, 2020 | AdRem NetCrunch 10.6.0.4587 has an Improper Session Handling vulnerability in the NetCrunch web client, which can lead t... |
| CVE-2019-14477 | MEDIUM | 5.5 | 0.3% | Dec 16, 2020 | AdRem NetCrunch 10.6.0.4587 has Improper Credential Storage since the internal user database is readable by low-privileg... |
| CVE-2019-19289 | HIGH | 8.8 | 0.4% | Dec 14, 2020 | A vulnerability has been identified in XHQ (All Versions < 6.1). The web interface could allow a Cross-Site Request Forg... |
| CVE-2019-19288 | MEDIUM | 6.1 | 0.6% | Dec 14, 2020 | A vulnerability has been identified in XHQ (All Versions < 6.1). The web interface could allow Cross-Site Scripting (XSS... |
| CVE-2019-19287 | MEDIUM | 6.5 | 1.2% | Dec 14, 2020 | A vulnerability has been identified in XHQ (All Versions < 6.1). The web interface could allow attackers to traverse thr... |
| CVE-2019-19286 | HIGH | 7.2 | 0.9% | Dec 14, 2020 | A vulnerability has been identified in XHQ (All Versions < 6.1). The web interface could allow SQL injection attacks if ... |
| CVE-2019-19285 | MEDIUM | 5.4 | 0.5% | Dec 14, 2020 | A vulnerability has been identified in XHQ (All Versions < 6.1). The web interface could allow injections that could lea... |
| CVE-2019-19284 | MEDIUM | 5.4 | 0.5% | Dec 14, 2020 | A vulnerability has been identified in XHQ (All Versions < 6.1). The web interface could allow Cross-Site Scripting (XSS... |
| CVE-2019-19283 | MEDIUM | 5.3 | 0.9% | Dec 14, 2020 | A vulnerability has been identified in XHQ (All Versions < 6.1). The application's web server could expose non-sensitive... |
| CVE-2019-4738 | MEDIUM | 6.5 | 0.5% | Dec 10, 2020 | IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 and 6.0.0.0 through 6.0.3.1 discloses sensitive inf... |
| CVE-2019-7198 | CRITICAL | 9.8 | 2.7% | Dec 10, 2020 | This command injection vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP h... |
| CVE-2019-16958 | MEDIUM | 5.4 | 1.2% | Dec 1, 2020 | Cross-site Scripting (XSS) vulnerability in SolarWinds Web Help Desk 12.7.0 allows attacker to inject arbitrary web scri... |
| CVE-2019-20934 | MEDIUM | 5.3 | 0.3% | Nov 28, 2020 | An issue was discovered in the Linux kernel before 5.2.6. On NUMA systems, the Linux fair scheduler has a use-after-free... |
| CVE-2019-19878 | HIGH | 7.5 | 1.2% | Nov 27, 2020 | An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. An attacker can get access to historical d... |
| CVE-2019-19877 | MEDIUM | 5.3 | 1.3% | Nov 27, 2020 | An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. An attacker can get access to sensitive in... |
| CVE-2019-19876 | CRITICAL | 9.8 | 1.0% | Nov 27, 2020 | An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. An EnMon PHP script was vulnerable to SQL ... |
| CVE-2019-19875 | CRITICAL | 9.8 | 1.5% | Nov 27, 2020 | An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. Arbitrary commands could be injected (usin... |
| CVE-2019-19874 | CRITICAL | 9.8 | 1.8% | Nov 27, 2020 | An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. Some web scripts in the web interface allo... |
| CVE-2019-19873 | HIGH | 7.5 | 1.2% | Nov 27, 2020 | An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. An attacker can get information from the A... |
| CVE-2019-19872 | CRITICAL | 9.8 | 1.2% | Nov 27, 2020 | An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. The AprolLoader could be used to inject an... |
| CVE-2019-19869 | HIGH | 7.5 | 0.9% | Nov 27, 2020 | An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. PVs could be changed (unencrypted) by usin... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now