Known Exploited Vulnerabilities (KEV)

ID Title Severity CVSS EPSS Source Updated
cve-2019-12991 Citrix SD-WAN and NetScaler Command Injection Vulnerability HIGH 8.8 74.05% cvelistv5 2022-03-25
cve-2019-12990 Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow Directory Traversal. CRITICAL 9.8 39.34% cvelistv5 2026-06-17
cve-2019-12989 Citrix SD-WAN and NetScaler SQL Injection Vulnerability CRITICAL 9.8 94.13% cvelistv5 2022-03-25
cve-2019-12988 Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 4 of 6). CRITICAL 9.8 42.55% cvelistv5 2026-06-17
cve-2019-12987 Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 3 of 6). CRITICAL 9.8 42.55% cvelistv5 2026-06-17
cve-2019-12986 Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 2 of 6). CRITICAL 9.8 39.54% cvelistv5 2026-06-17
cve-2019-12985 Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 1 of 6). CRITICAL 9.8 39.54% cvelistv5 2026-06-17
cve-2019-1297 Microsoft Excel Remote Code Execution Vulnerability HIGH 8.8 21.80% cvelistv5 2022-03-03
cve-2019-12780 The Belkin Wemo Enabled Crock-Pot allows command injection in the Wemo UPnP API via the SmartDevURL argument to the SetSmartDevInfo action. A simple POST request to /upnp/control/basicevent1 can allow an attacker to execute commands without authentication. CRITICAL 9.8 72.44% cvelistv5 2026-06-17
cve-2019-12725 Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web application mishandles a few HTTP parameters. An unauthenticated attacker can exploit this issue by injecting OS commands inside the vulnerable parameters. CRITICAL 9.8 89.85% cvelistv5 2026-06-17
cve-2019-12593 IceWarp Mail Server through 10.4.4 is prone to a local file inclusion vulnerability via webmail/calendar/minimizer/index.php?style=..%5c directory traversal. HIGH 7.5 40.97% cvelistv5 2026-06-17
cve-2019-1253 Microsoft Windows AppX Deployment Server Privilege Escalation Vulnerability HIGH 7.8 11.62% cvelistv5 2022-03-15
cve-2019-12314 Deltek Maconomy 2.2.5 is prone to local file inclusion via absolute path traversal in the WS.macx1.W_MCS/ PATH_INFO, as demonstrated by a cgi-bin/Maconomy/MaconomyWS.macx1.W_MCS/etc/passwd URI. CRITICAL 9.8 84.22% cvelistv5 2026-06-17
cve-2019-12276 A Path Traversal vulnerability in Controllers/LetsEncryptController.cs in LetsEncryptController in GrandNode 4.40 allows remote, unauthenticated attackers to retrieve arbitrary files on the web server via specially crafted LetsEncrypt/Index?fileName= HTTP requests. A patch for this issue was made on 2019-05-30 in GrandNode 4.40. HIGH 7.5 57.10% cvelistv5 2026-06-17
cve-2019-1215 Microsoft Windows Privilege Escalation Vulnerability HIGH 7.8 19.25% cvelistv5 2021-11-03
cve-2019-1214 Microsoft Windows Privilege Common Log File System (CLFS) Escalation Vulnerability HIGH 7.8 1.42% cvelistv5 2021-11-03
cve-2019-11708 Mozilla Firefox and Thunderbird Sandbox Escape Vulnerability HIGH N/A 55.87% cvelistv5 2022-05-23
cve-2019-11707 Mozilla Firefox and Thunderbird Type Confusion Vulnerability HIGH N/A 37.70% cvelistv5 2022-05-23
cve-2019-11634 Citrix Workspace Application and Receiver for Windows Remote Code Execution Vulnerability CRITICAL 9.8 8.03% cvelistv5 2021-11-03
cve-2019-11581 Atlassian Jira Server and Data Center Server-Side Template Injection Vulnerability CRITICAL 9.8 84.62% cvelistv5 2022-03-07
cve-2019-11580 Atlassian Crowd and Crowd Data Center Remote Code Execution Vulnerability CRITICAL 9.8 95.36% cvelistv5 2021-11-03
cve-2019-11539 Ivanti Pulse Connect Secure and Policy Secure Command Injection Vulnerability HIGH 8.0 98.54% cvelistv5 2021-11-03
cve-2019-11510 Ivanti Pulse Connect Secure Arbitrary File Read Vulnerability CRITICAL 9.9 100.00% cvelistv5 2021-11-03
cve-2019-11370 Stored XSS was discovered in Carel pCOWeb prior to B1.2.4, as demonstrated by the config/pw_snmp.html "System contact" field. MEDIUM 5.4 5.03% cvelistv5 2026-06-17
cve-2019-1132 Microsoft Win32k Privilege Escalation Vulnerability HIGH 7.8 9.79% cvelistv5 2022-03-15
cve-2019-1130 Microsoft Windows AppX Deployment Service Privilege Escalation Vulnerability HIGH 7.8 2.28% cvelistv5 2022-05-23
cve-2019-1129 Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability HIGH 7.8 1.78% cvelistv5 2022-03-15
cve-2019-11248 SUSE CVE CVE-2019-11248 UNKNOWN N/A 75.06% cvelistv5 2026-09-02
cve-2019-11043 PHP FastCGI Process Manager (FPM) Buffer Overflow Vulnerability CRITICAL N/A 99.78% cvelistv5 2022-03-25
cve-2019-11001 Reolink Multiple IP Cameras OS Command Injection Vulnerability HIGH 7.2 37.54% cvelistv5 2024-12-18