2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-18870 | MEDIUM | 6.5 | 1.1% | May 7, 2020 | A path traversal via the iniFile parameter in excel.php in Blaauw Remote Kiln Control through v3.00r4 allows an authenti... |
| CVE-2019-18869 | CRITICAL | 9.8 | 1.3% | May 7, 2020 | Leftover Debug Code in Blaauw Remote Kiln Control through v3.00r4 allows a user to execute arbitrary php code via /defau... |
| CVE-2019-18866 | HIGH | 7.5 | 1.2% | May 7, 2020 | Unauthenticated SQL injection via the username in the login mechanism in Blaauw Remote Kiln Control through v3.00r4 allo... |
| CVE-2019-18864 | HIGH | 7.5 | 1.3% | May 7, 2020 | /server-info and /server-status in Blaauw Remote Kiln Control through v3.00r4 allow an unauthenticated attacker to gain ... |
| CVE-2019-18868 | CRITICAL | 9.8 | 0.8% | May 7, 2020 | Blaauw Remote Kiln Control through v3.00r4 allows an unauthenticated attacker to access MySQL credentials in cleartext i... |
| CVE-2019-18867 | HIGH | 7.5 | 1.2% | May 7, 2020 | Browsable directories in Blaauw Remote Kiln Control through v3.00r4 allow an attacker to enumerate sensitive filenames a... |
| CVE-2019-18865 | MEDIUM | 5.3 | 1.1% | May 7, 2020 | Information disclosure via error message discrepancies in authentication functions in Blaauw Remote Kiln Control through... |
| CVE-2019-4266 | LOW | 2.4 | 0.3% | May 6, 2020 | IBM Maximo Anywhere 7.6.2.0, 7.6.2.1, 7.6.3.0, and 7.6.3.1 does not have device jailbreak detection which could result i... |
| CVE-2019-19169 | CRITICAL | 9.8 | 1.6% | May 6, 2020 | Dext5.ocx ActiveX 5.0.0.116 and eariler versions contain a vulnerability, which could allow remote attacker to download ... |
| CVE-2019-19168 | CRITICAL | 9.8 | 1.6% | May 6, 2020 | Dext5.ocx ActiveX 5.0.0.116 and eariler versions contain a vulnerability, which could allow remote attacker to download ... |
| CVE-2019-19167 | CRITICAL | 9.8 | 0.7% | May 6, 2020 | Tobesoft Nexacro v2019.9.25.1 and earlier version have an arbitrary code execution vulnerability by using method support... |
| CVE-2019-19166 | HIGH | 7.8 | 0.4% | May 6, 2020 | Tobesoft XPlatform v9.1, 9.2.0, 9.2.1 and 9.2.2 have a vulnerability that can load unauthorized DLL files. It allows att... |
| CVE-2019-20768 | MEDIUM | 5.4 | 0.7% | May 5, 2020 | ServiceNow IT Service Management Kingston through Patch 14-1, London through Patch 7, and Madrid before patch 4 allow st... |
| CVE-2019-19517 | HIGH | 8.8 | 0.5% | May 5, 2020 | Intelbras RF1200 1.1.3 devices allow CSRF to bypass the login.html form, as demonstrated by launching a scrapy process. |
| CVE-2019-19515 | MEDIUM | 6.1 | 0.8% | May 5, 2020 | Ayision Ays-WR01 v28K.RPT.20161224 devices allow stored XSS in wireless settings. |
| CVE-2019-19514 | MEDIUM | 5.4 | 0.6% | May 5, 2020 | Ayision Ays-WR01 v28K.RPT.20161224 devices allow stored XSS in basic repeater settings via an SSID. |
| CVE-2019-13285 | HIGH | 7.5 | 1.0% | May 4, 2020 | CoSoSys Endpoint Protector 5.1.0.2 allows Host Header Injection. |
| CVE-2019-12864 | MEDIUM | 5.5 | 0.5% | May 4, 2020 | SolarWinds Orion Platform 2018.4 HF3 (NPM 12.4, NetPath 1.1.4) is vulnerable to Information Leakage, because of improper... |
| CVE-2019-17557 | MEDIUM | 5.4 | 1.2% | May 4, 2020 | It was found that the Apache Syncope EndUser UI login page prio to 2.0.15 and 2.1.6 reflects the successMessage paramete... |
| CVE-2019-11823 | HIGH | 7.5 | 2.4% | May 4, 2020 | CRLF injection vulnerability in Network Center in Synology Router Manager (SRM) before 1.2.3-8017-2 allows remote attack... |
| CVE-2019-4209 | MEDIUM | 6.1 | 0.6% | May 1, 2020 | HCL Connections v5.5, v6.0, and v6.5 contains an open redirect vulnerability which could be exploited by an attacker to ... |
| CVE-2019-12425 | HIGH | 7.5 | 4.7% | Apr 30, 2020 | Apache OFBiz 17.12.01 is vulnerable to Host header injection by accepting arbitrary host |
| CVE-2019-0235 | HIGH | 8.8 | 32.7% | Apr 30, 2020 | Apache OFBiz 17.12.01 is vulnerable to some CSRF attacks. |
| CVE-2019-19220 | HIGH | 8.8 | 1.8% | Apr 30, 2020 | BMC Control-M/Agent 7.0.00.000 allows OS Command Injection (issue 2 of 2). |
| CVE-2019-19219 | HIGH | 7.5 | 1.1% | Apr 30, 2020 | BMC Control-M/Agent 7.0.00.000 allows Arbitrary File Download. |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now