Known Exploited Vulnerabilities (KEV)

ID Title Severity CVSS EPSS Source Updated
cve-2019-6693 Fortinet FortiOS Use of Hard-Coded Credentials Vulnerability CRITICAL N/A 5.83% cvelistv5 2025-06-25
cve-2019-6340 drupal: does not sanitize data from non-form sources leads to arbitrary PHP code execution CRITICAL 9.8 92.02% cvelistv5 2025-11-21
cve-2019-6223 Apple iOS and macOS Group Facetime Vulnerability HIGH 7.5 2.63% cvelistv5 2021-11-03
cve-2019-5825 chromium-browser: Out-of-bounds write in V8 HIGH 8.8 55.93% cvelistv5 2026-06-28
cve-2019-5786 chromium-browser: Use-after-free in FileReader HIGH 8.8 62.24% cvelistv5 2026-06-28
cve-2019-5591 Fortinet FortiOS Default Configuration Vulnerability MEDIUM 6.5 18.42% cvelistv5 2021-11-03
cve-2019-5544 openslp: Heap-based buffer overflow in ProcessSrvRqst() in slpd_process.c leading to remote code execution CRITICAL 9.8 97.26% cvelistv5 2025-11-21
cve-2019-5434 An attacker could send a specifically crafted payload to the XML-RPC invocation script and trigger the unserialize() call on the "what" parameter in the "openads.spc" RPC method. Such vulnerability could be used to perform various types of attacks, e.g. exploit serialize-related PHP vulnerabilities or PHP object injection. It is possible, although unconfirmed, that the vulnerability has been used by some attackers in order to gain access to some Revive Adserver instances and deliver malware through them to third party websites. This vulnerability was addressed in version 4.2.0. CRITICAL 9.8 57.02% cvelistv5 2026-06-17
cve-2019-5418 rubygem-actionpack: render file directory traversal in Action View HIGH 8.1 98.51% cvelistv5 2026-06-28
cve-2019-5129 CVE-2019-5129 CRITICAL 10.0 38.53% cvelistv5
cve-2019-5128 CVE-2019-5128 CRITICAL 10.0 30.17% cvelistv5
cve-2019-5127 CVE-2019-5127 CRITICAL 10.0 45.30% cvelistv5
cve-2019-4716 IBM Planning Analytics Remote Code Execution Vulnerability CRITICAL 10.0 86.44% cvelistv5 2021-11-03
cve-2019-4061 CVE-2019-4061 MEDIUM 5.3 22.55% cvelistv5
cve-2019-3929 Crestron Multiple Products Command Injection Vulnerability CRITICAL 9.8 98.95% cvelistv5 2022-04-15
cve-2019-3914 Remote command injection vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05 allows a remote, authenticated attacker to execute arbitrary commands on the target device by adding an access control rule for a network object with a crafted hostname. HIGH 7.2 29.89% cvelistv5 2026-06-17
cve-2019-3568 WhatsApp VOIP Stack Buffer Overflow Vulnerability HIGH N/A 30.08% cvelistv5 2022-04-19
cve-2019-3495 CVE-2019-3495 HIGH N/A 4.95% cvelistv5
cve-2019-3398 Atlassian Confluence Server and Data Center Path Traversal Vulnerability HIGH 8.8 96.84% cvelistv5 2021-11-03
cve-2019-3396 Atlassian Confluence Server and Data Center Server-Side Template Injection Vulnerability CRITICAL 9.8 99.91% cvelistv5 2021-11-03
cve-2019-3010 Oracle Solaris Privilege Escalation Vulnerability HIGH 8.8 13.40% cvelistv5 2022-05-25
cve-2019-2768 Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). The supported version that is affected is 11.1.1.9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise BI Publisher (formerly XML Publisher). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all BI Publisher (formerly XML Publisher) accessible data. CVSS 3.0 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). HIGH 7.5 1.71% cvelistv5 2026-06-17
cve-2019-2725 Oracle WebLogic Server, Injection CRITICAL 9.8 99.96% cvelistv5 2022-01-10
cve-2019-2618 Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data as well as unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data. CVSS 3.0 Base Score 5.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N). MEDIUM 5.5 32.88% cvelistv5 2026-06-17
cve-2019-2616 Oracle BI Publisher Unauthorized Access Vulnerability HIGH 7.2 92.18% cvelistv5 2022-03-25
cve-2019-2588 Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise BI Publisher (formerly XML Publisher). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all BI Publisher (formerly XML Publisher) accessible data. CVSS 3.0 Base Score 4.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N). MEDIUM 4.9 36.79% cvelistv5 2026-06-17
cve-2019-25765 ASP-CMS SQL Injection via commentList.asp id Parameter HIGH 7.5 0.59% cvelistv5 2026-09-10
cve-2019-25141 CVE-2019-25141 CRITICAL 9.8 4.50% cvelistv5
cve-2019-25065 CVE-2019-25065 MEDIUM 6.3 6.51% cvelistv5
cve-2019-2215 SUSE CVE CVE-2019-2215 UNKNOWN N/A 72.10% cvelistv5 2025-10-07