Known Exploited Vulnerabilities (KEV)
| ID | Title | Severity | CVSS | EPSS | Source | Updated |
|---|---|---|---|---|---|---|
| cve-2019-20933 | influxdb: authentication bypass because a JWT token may have an empty SharedSecret | HIGH | 8.6 | 30.92% | cvelistv5 | 2026-08-21 |
| cve-2019-20504 | CVE-2019-20504 | HIGH | N/A | 9.55% | cvelistv5 | |
| cve-2019-20500 | D-Link DWL-2600AP Access Point Command Injection Vulnerability | HIGH | 7.8 | 97.11% | cvelistv5 | 2023-06-29 |
| cve-2019-20085 | TVT NVMS-1000 Directory Traversal Vulnerability | HIGH | 7.5 | 96.07% | cvelistv5 | 2021-11-03 |
| cve-2019-20074 | On Netis DL4323 devices, any user role can view sensitive information, such as a user password or the FTP password, via the form2saveConf.cgi page. | HIGH | 8.8 | 1.40% | cvelistv5 | 2026-06-17 |
| cve-2019-19915 | CVE-2019-19915 | CRITICAL | 9.0 | 0.86% | cvelistv5 | |
| cve-2019-19825 | CVE-2019-19825 | HIGH | N/A | 29.56% | cvelistv5 | |
| cve-2019-19824 | CVE-2019-19824 | HIGH | N/A | 25.14% | cvelistv5 | |
| cve-2019-19781 | Citrix ADC, Gateway, and SD-WAN WANOP Appliance Code Execution Vulnerability | CRITICAL | 9.8 | 100.00% | cvelistv5 | 2021-11-03 |
| cve-2019-19356 | Netis WF2419 Devices Remote Code Execution Vulnerability | HIGH | 7.5 | 28.17% | cvelistv5 | 2021-11-03 |
| cve-2019-19006 | Sangoma FreePBX 115.0.16.26 and below, 14.0.13.11 and below, 13.0.197.13 and below have Incorrect Access Control. | CRITICAL | 9.8 | 36.61% | cvelistv5 | 2026-06-17 |
| cve-2019-18988 | TeamViewer Desktop Bypass Remote Login Vulnerability | HIGH | 7.0 | 4.71% | cvelistv5 | 2021-11-03 |
| cve-2019-18952 | CVE-2019-18952 | HIGH | N/A | 45.36% | cvelistv5 | |
| cve-2019-18935 | Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability | CRITICAL | 9.8 | 99.74% | cvelistv5 | 2021-11-03 |
| cve-2019-18818 | CVE-2019-18818 | HIGH | N/A | 97.64% | cvelistv5 | |
| cve-2019-18426 | WhatsApp Cross-Site Scripting Vulnerability | HIGH | 8.2 | 67.86% | cvelistv5 | 2022-05-23 |
| cve-2019-18394 | CVE-2019-18394 | HIGH | N/A | 32.30% | cvelistv5 | |
| cve-2019-18393 | CVE-2019-18393 | HIGH | N/A | 13.94% | cvelistv5 | |
| cve-2019-18371 | CVE-2019-18371 | HIGH | N/A | 55.87% | cvelistv5 | |
| cve-2019-1821 | Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerabilities | HIGH | 8.8 | 98.05% | cvelistv5 | 2026-06-17 |
| cve-2019-18187 | Trend Micro OfficeScan Directory Traversal Vulnerability | HIGH | 8.8 | 25.12% | cvelistv5 | 2021-11-03 |
| cve-2019-17621 | D-Link DIR-859 Router Command Execution Vulnerability | CRITICAL | 9.8 | 89.62% | cvelistv5 | 2023-06-29 |
| cve-2019-17558 | solr: Remote Code Execution through the VelocityResponseWriter | HIGH | 7.5 | 98.57% | cvelistv5 | 2026-08-04 |
| cve-2019-17506 | CVE-2019-17506 | HIGH | N/A | 56.39% | cvelistv5 | |
| cve-2019-17503 | CVE-2019-17503 | HIGH | N/A | 48.30% | cvelistv5 | |
| cve-2019-17270 | CVE-2019-17270 | HIGH | N/A | 58.88% | cvelistv5 | |
| cve-2019-17026 | Mozilla: IonMonkey type confusion with StoreElementHole and FallibleStoreElement | HIGH | 8.8 | 46.31% | cvelistv5 | 2025-11-21 |
| cve-2019-16932 | CVE-2019-16932 | HIGH | N/A | 39.14% | cvelistv5 | |
| cve-2019-16928 | exim: remotely triggerable buffer overflow in string_vformat() | CRITICAL | 9.8 | 41.64% | cvelistv5 | 2026-02-20 |
| cve-2019-16920 | D-Link Multiple Routers Command Injection Vulnerability | CRITICAL | 9.8 | 100.00% | cvelistv5 | 2022-03-25 |