Known Exploited Vulnerabilities (KEV)

ID Title Severity CVSS EPSS Source Updated
cve-2019-9874 Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability CRITICAL 9.8 83.74% cvelistv5 2025-03-26
cve-2019-9762 A SQL Injection was discovered in PHPSHE 1.7 in include/plugin/payment/alipay/pay.php with the parameter id. The vulnerability does not need any authentication. CRITICAL 9.8 6.04% cvelistv5 2026-06-17
cve-2019-9733 An issue was discovered in JFrog Artifactory 6.7.3. By default, the access-admin account is used to reset the password of the admin account in case an administrator gets locked out from the Artifactory console. This is only allowable from a connection directly from localhost, but providing a X-Forwarded-For HTTP header to the request allows an unauthenticated user to login with the default credentials of the access-admin account while bypassing the whitelist of allowed IP addresses. The access-admin account can use Artifactory's API to request authentication tokens for all users including the admin account and, in turn, assume full control of all artifacts and repositories managed by Artifactory. CRITICAL 9.8 52.95% cvelistv5 2026-06-17
cve-2019-9670 Synacor Zimbra Collaboration Suite (ZCS) Improper Restriction of XML External Entity Reference CRITICAL 9.8 99.99% cvelistv5 2022-01-10
cve-2019-9621 Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery (SSRF) Vulnerability HIGH 7.5 81.04% cvelistv5 2025-07-07
cve-2019-9082 ThinkPHP Remote Code Execution Vulnerability HIGH 8.8 97.42% cvelistv5 2021-11-03
cve-2019-8942 SUSE CVE CVE-2019-8942 UNKNOWN N/A 82.74% cvelistv5 2025-02-17
cve-2019-8720 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution HIGH 8.8 1.56% cvelistv5 2026-01-05
cve-2019-8605 A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, watchOS 5.2.1. A malicious application may be able to execute arbitrary code with system privileges. HIGH 7.8 17.51% cvelistv5 2026-06-17
cve-2019-8526 Apple macOS Use-After-Free Vulnerability HIGH 7.8 0.70% cvelistv5 2023-04-17
cve-2019-8506 A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12.2, watchOS 5.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. Processing maliciously crafted web content may lead to arbitrary code execution. HIGH 8.8 18.11% cvelistv5 2026-06-17
cve-2019-8451 CVE-2019-8451 HIGH N/A 94.45% cvelistv5
cve-2019-8446 CVE-2019-8446 HIGH N/A 17.55% cvelistv5
cve-2019-8442 CVE-2019-8442 HIGH N/A 59.83% cvelistv5
cve-2019-8394 Zoho ManageEngine ServiceDesk Plus (SDP) File Upload Vulnerability HIGH 7.5 63.34% cvelistv5 2021-11-03
cve-2019-8387 MASTER IPCAMERA01 3.3.4.2103 devices allow Remote Command Execution, related to the thttpd component. CRITICAL 9.8 55.72% cvelistv5 2026-06-17
cve-2019-7609 kibana: Arbitrary code execution flaw in the Timelion visualizer HIGH 7.5 95.34% cvelistv5 2026-02-23
cve-2019-7483 SonicWall SMA100 Directory Traversal Vulnerability HIGH N/A 4.01% cvelistv5 2022-03-28
cve-2019-7481 SonicWall SMA100 SQL Injection Vulnerability HIGH 7.5 99.91% cvelistv5 2021-11-03
cve-2019-7287 Apple iOS Memory Corruption Vulnerability HIGH N/A 4.58% cvelistv5 2022-05-23
cve-2019-7286 A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.4, macOS Mojave 10.14.3 Supplemental Update. An application may be able to gain elevated privileges. HIGH 7.8 15.58% cvelistv5 2026-06-17
cve-2019-7256 Nice Linear eMerge E3-Series OS Command Injection Vulnerability HIGH N/A 97.08% cvelistv5 2024-03-25
cve-2019-7254 CVE-2019-7254 HIGH N/A 82.29% cvelistv5
cve-2019-7238 Sonatype Nexus Repository Manager Incorrect Access Control Vulnerability CRITICAL 9.8 77.15% cvelistv5 2021-12-10
cve-2019-7195 QNAP Photo Station Path Traversal Vulnerability CRITICAL 9.8 89.68% cvelistv5 2022-06-08
cve-2019-7194 QNAP Photo Station Path Traversal Vulnerability CRITICAL 9.8 83.12% cvelistv5 2022-06-08
cve-2019-7193 QNAP QTS Improper Input Validation Vulnerability CRITICAL 9.8 14.37% cvelistv5 2022-06-08
cve-2019-7192 QNAP Photo Station Improper Access Control Vulnerability CRITICAL N/A 88.10% cvelistv5 2022-06-08
cve-2019-6814 CVE-2019-6814 HIGH N/A 36.65% cvelistv5
cve-2019-6703 Incorrect access control in migla_ajax_functions.php in the Calmar Webmedia Total Donations plugin through 2.0.5 for WordPress allows unauthenticated attackers to update arbitrary WordPress option values, leading to site takeover. These attackers can send requests to wp-admin/admin-ajax.php to call the miglaA_update_me action to change arbitrary options on affected sites. This can be used to enable new user registration and set the default role for new users to Administrator. CRITICAL 9.8 26.08% cvelistv5 2026-06-17