2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-18870MEDIUM6.5A path traversal via the iniFile parameter in excel.php in Blaauw Remote Kiln Control through v3.00r4 allows an authenti...
CVE-2019-18869CRITICAL9.8Leftover Debug Code in Blaauw Remote Kiln Control through v3.00r4 allows a user to execute arbitrary php code via /defau...
CVE-2019-18866HIGH7.5Unauthenticated SQL injection via the username in the login mechanism in Blaauw Remote Kiln Control through v3.00r4 allo...
CVE-2019-18864HIGH7.5/server-info and /server-status in Blaauw Remote Kiln Control through v3.00r4 allow an unauthenticated attacker to gain ...
CVE-2019-18868CRITICAL9.8Blaauw Remote Kiln Control through v3.00r4 allows an unauthenticated attacker to access MySQL credentials in cleartext i...
CVE-2019-18867HIGH7.5Browsable directories in Blaauw Remote Kiln Control through v3.00r4 allow an attacker to enumerate sensitive filenames a...
CVE-2019-18865MEDIUM5.3Information disclosure via error message discrepancies in authentication functions in Blaauw Remote Kiln Control through...
CVE-2019-4266LOW2.4IBM Maximo Anywhere 7.6.2.0, 7.6.2.1, 7.6.3.0, and 7.6.3.1 does not have device jailbreak detection which could result i...
CVE-2019-19169CRITICAL9.8Dext5.ocx ActiveX 5.0.0.116 and eariler versions contain a vulnerability, which could allow remote attacker to download ...
CVE-2019-19168CRITICAL9.8Dext5.ocx ActiveX 5.0.0.116 and eariler versions contain a vulnerability, which could allow remote attacker to download ...
CVE-2019-19167CRITICAL9.8Tobesoft Nexacro v2019.9.25.1 and earlier version have an arbitrary code execution vulnerability by using method support...
CVE-2019-19166HIGH7.8Tobesoft XPlatform v9.1, 9.2.0, 9.2.1 and 9.2.2 have a vulnerability that can load unauthorized DLL files. It allows att...
CVE-2019-20768MEDIUM5.4ServiceNow IT Service Management Kingston through Patch 14-1, London through Patch 7, and Madrid before patch 4 allow st...
CVE-2019-19517HIGH8.8Intelbras RF1200 1.1.3 devices allow CSRF to bypass the login.html form, as demonstrated by launching a scrapy process.
CVE-2019-19515MEDIUM6.1Ayision Ays-WR01 v28K.RPT.20161224 devices allow stored XSS in wireless settings.
CVE-2019-19514MEDIUM5.4Ayision Ays-WR01 v28K.RPT.20161224 devices allow stored XSS in basic repeater settings via an SSID.
CVE-2019-13285HIGH7.5CoSoSys Endpoint Protector 5.1.0.2 allows Host Header Injection.
CVE-2019-12864MEDIUM5.5SolarWinds Orion Platform 2018.4 HF3 (NPM 12.4, NetPath 1.1.4) is vulnerable to Information Leakage, because of improper...
CVE-2019-17557MEDIUM5.4It was found that the Apache Syncope EndUser UI login page prio to 2.0.15 and 2.1.6 reflects the successMessage paramete...
CVE-2019-11823HIGH7.5CRLF injection vulnerability in Network Center in Synology Router Manager (SRM) before 1.2.3-8017-2 allows remote attack...
CVE-2019-4209MEDIUM6.1HCL Connections v5.5, v6.0, and v6.5 contains an open redirect vulnerability which could be exploited by an attacker to ...
CVE-2019-12425HIGH7.5Apache OFBiz 17.12.01 is vulnerable to Host header injection by accepting arbitrary host
CVE-2019-0235HIGH8.8Apache OFBiz 17.12.01 is vulnerable to some CSRF attacks.
CVE-2019-19220HIGH8.8BMC Control-M/Agent 7.0.00.000 allows OS Command Injection (issue 2 of 2).
CVE-2019-19219HIGH7.5BMC Control-M/Agent 7.0.00.000 allows Arbitrary File Download.

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now