2019 CVE Vulnerabilities

17,624 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-10169HIGH7.2A flaw was found in Keycloak’s user-managed access interface, where it would permit a script to be set in the UMA policy...
CVE-2019-19164HIGH8.8dext5.ocx ActiveX Control in Dext5 Upload 5.0.0.112 and earlier versions contains a vulnerability that could allow remot...
CVE-2019-18872HIGH7.5Weak password requirements in Blaauw Remote Kiln Control through v3.00r4 allow a user to set short or guessable password...
CVE-2019-18871HIGH8.8A path traversal in debug.php accessed via default.php in Blaauw Remote Kiln Control through v3.00r4 allows an authentic...
CVE-2019-18870MEDIUM6.5A path traversal via the iniFile parameter in excel.php in Blaauw Remote Kiln Control through v3.00r4 allows an authenti...
CVE-2019-18869CRITICAL9.8Leftover Debug Code in Blaauw Remote Kiln Control through v3.00r4 allows a user to execute arbitrary php code via /defau...
CVE-2019-18866HIGH7.5Unauthenticated SQL injection via the username in the login mechanism in Blaauw Remote Kiln Control through v3.00r4 allo...
CVE-2019-18864HIGH7.5/server-info and /server-status in Blaauw Remote Kiln Control through v3.00r4 allow an unauthenticated attacker to gain ...
CVE-2019-18868CRITICAL9.8Blaauw Remote Kiln Control through v3.00r4 allows an unauthenticated attacker to access MySQL credentials in cleartext i...
CVE-2019-18867HIGH7.5Browsable directories in Blaauw Remote Kiln Control through v3.00r4 allow an attacker to enumerate sensitive filenames a...
CVE-2019-18865MEDIUM5.3Information disclosure via error message discrepancies in authentication functions in Blaauw Remote Kiln Control through...
CVE-2019-4266LOW2.4IBM Maximo Anywhere 7.6.2.0, 7.6.2.1, 7.6.3.0, and 7.6.3.1 does not have device jailbreak detection which could result i...
CVE-2019-19169CRITICAL9.8Dext5.ocx ActiveX 5.0.0.116 and eariler versions contain a vulnerability, which could allow remote attacker to download ...
CVE-2019-19168CRITICAL9.8Dext5.ocx ActiveX 5.0.0.116 and eariler versions contain a vulnerability, which could allow remote attacker to download ...
CVE-2019-19167CRITICAL9.8Tobesoft Nexacro v2019.9.25.1 and earlier version have an arbitrary code execution vulnerability by using method support...
CVE-2019-19166HIGH7.8Tobesoft XPlatform v9.1, 9.2.0, 9.2.1 and 9.2.2 have a vulnerability that can load unauthorized DLL files. It allows att...
CVE-2019-20768MEDIUM5.4ServiceNow IT Service Management Kingston through Patch 14-1, London through Patch 7, and Madrid before patch 4 allow st...
CVE-2019-19517HIGH8.8Intelbras RF1200 1.1.3 devices allow CSRF to bypass the login.html form, as demonstrated by launching a scrapy process.
CVE-2019-19515MEDIUM6.1Ayision Ays-WR01 v28K.RPT.20161224 devices allow stored XSS in wireless settings.
CVE-2019-19514MEDIUM5.4Ayision Ays-WR01 v28K.RPT.20161224 devices allow stored XSS in basic repeater settings via an SSID.
CVE-2019-13285HIGH7.5CoSoSys Endpoint Protector 5.1.0.2 allows Host Header Injection.
CVE-2019-12864MEDIUM5.5SolarWinds Orion Platform 2018.4 HF3 (NPM 12.4, NetPath 1.1.4) is vulnerable to Information Leakage, because of improper...
CVE-2019-17557MEDIUM5.4It was found that the Apache Syncope EndUser UI login page prio to 2.0.15 and 2.1.6 reflects the successMessage paramete...
CVE-2019-11823HIGH7.5CRLF injection vulnerability in Network Center in Synology Router Manager (SRM) before 1.2.3-8017-2 allows remote attack...
CVE-2019-4209MEDIUM6.1HCL Connections v5.5, v6.0, and v6.5 contains an open redirect vulnerability which could be exploited by an attacker to ...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now