KEV 2019

118 CISA Known Exploited Vulnerabilities from 2019

Critical 40

February 2026

March 2025

November 2024

September 2024

March 2024

June 2023

June 2022

May 2022

April 2022

March 2022

January 2022

December 2021

November 2021

CVE-2019-11510

Pulse Connect Secure — unauthenticated arbitrary file read exposes VPN credentials, root of a ransomware pandemic

CVSS 10
CVE-2019-0604

SharePoint unauthenticated RCE via malicious application package, widely used to drop China Chopper webshells

CVSS 9.8
CVE-2019-0708

Microsoft RDP 'BlueKeep' — Use-After-Free in Remote Desktop Services Allows Wormable Pre-Auth Remote Code Execution

CVSS 9.8
CVE-2019-11580

Atlassian Crowd — leftover pdkinstall dev plugin lets unauthenticated attackers upload a malicious plugin for RCE

CVSS 9.8
CVE-2019-11634

Citrix Workspace/Receiver — a malicious or compromised server abuses client drive mapping to write files outside the client sandbox

CVSS 9.8
CVE-2019-16256

SIMalliance S@T Browser ("Simjacker") — SIM Card Exploitation via Malicious OTA SMS

CVSS 9.8
CVE-2019-16759

vBulletin widgetConfig[code] Parameter — Unauthenticated Pre-Auth Remote Code Execution (0-Day)

CVSS 9.8
CVE-2019-18935

Telerik UI for ASP.NET AJAX — RadAsyncUpload Deserialization RCE Used to Breach a US Federal Agency

CVSS 9.8
CVE-2019-19781

Citrix ADC/NetScaler — Path Traversal Enables Unauthenticated Remote Code Execution; 6-Week Unpatched Window Drives Mass Exploitation

CVSS 9.8
CVE-2019-3396

Atlassian Confluence — Widget Connector Velocity Template Injection Enables RCE via Path Traversal

CVSS 9.8
CVE-2019-4716

IBM Planning Analytics — Configuration Overwrite Grants Admin Login and TM1 Script RCE

CVSS 9.8
CVE-2019-5544

VMware ESXi — OpenSLP Heap Overflow Reachable Over the Network on Port 427

CVSS 9.8

High 70

July 2025

March 2025

December 2024

June 2023

April 2023

June 2022

May 2022

March 2022

CVE-2019-0903

GDI memory-handling flaw enabling code execution via a crafted document or font

CVSS 8.8
CVE-2019-12991

Citrix SD-WAN / NetScaler SD-WAN — low-privileged command injection in the appliance management interface

CVSS 8.8
CVE-2019-1297

Microsoft Excel — a malicious spreadsheet triggers memory corruption for code execution in the context of the victim

CVSS 8.8
CVE-2019-11043

PHP-FPM — Nginx path_info underflow leads to unauthenticated remote code execution

CVSS 8.7
CVE-2019-6340

Drupal Core — REST Module Deserialization Flaw Enables PHP Code Execution

CVSS 8.1
CVE-2019-0543

Windows authentication flaw letting a local attacker run code in an elevated context

CVSS 7.8
CVE-2019-0841

AppXSVC hard-link race condition letting a local attacker overwrite protected files as SYSTEM

CVSS 7.8
CVE-2019-1064

Follow-up fix for the AppXSVC hard-link EoP after the initial April 2019 patch was bypassed

CVSS 7.8
CVE-2019-1069

Task Scheduler file-validation flaw letting a local attacker elevate to SYSTEM

CVSS 7.8
CVE-2019-1129

Windows AppXSVC — hard-link abuse lets a low-privileged process overwrite arbitrary files as SYSTEM

CVSS 7.8
CVE-2019-1132

Windows Win32k — kernel callback memory-handling flaw exploited as an in-the-wild zero-day

CVSS 7.8
CVE-2019-1253

Windows AppX Deployment Server — junction-following flaw grants SYSTEM-level file access to a local user

CVSS 7.8
CVE-2019-1315

Windows Error Reporting — hard-link abuse in the crash-reporting service escalates a local user to SYSTEM

CVSS 7.8
CVE-2019-1322

Windows — improper handling of authentication requests lets a local low-privileged user reach SYSTEM

CVSS 7.8
CVE-2019-1405

Windows UPnP Service — Local Privilege Escalation via Insecure COM Object Instantiation

CVSS 7.8
CVE-2019-7483

SonicWall SMA100 — Unauthenticated Directory Traversal via handleWAFRedirect CGI

CVSS 7.5
CVE-2019-2616

Oracle BI Publisher — Unauthenticated Access Bypass in a Widely Deployed Reporting Engine

CVSS 7.2
CVE-2019-1652

Cisco RV320/RV325 Routers — Authenticated Command Injection via Web Management Interface

CVSS 7.2

February 2022

January 2022

December 2021

November 2021

CVE-2019-0541

MSHTML memory-corruption flaw allowing code execution via malicious content rendering

CVSS 8.8
CVE-2019-15949

Nagios XI — Authenticated Root Command Execution via check_plugin Executable Tampering

CVSS 8.8
CVE-2019-17026

Firefox/Thunderbird IonMonkey JIT — Type Confusion Zero-Day Exploited in Targeted Attacks

CVSS 8.8
CVE-2019-3398

Atlassian Confluence — Authenticated downloadallattachments Path Traversal Enables File Write / RCE

CVSS 8.8
CVE-2019-9082

ThinkPHP 5.x — Unauthenticated RCE via Method-Invocation Abuse, Mass-Exploited for Years

CVSS 8.8
CVE-2019-0211

Apache httpd MPM — Worker Process Scoreboard Manipulation Enables Root Privilege Escalation

CVSS 7.8
CVE-2019-0797

Win32k kernel memory-handling flaw exploited as a zero-day for local privilege escalation

CVSS 7.8
CVE-2019-0803

Win32k kernel object-handling flaw enabling local privilege escalation to SYSTEM

CVSS 7.8
CVE-2019-0808

Win32k zero-day chained with a Chrome renderer bug to escape the browser sandbox

CVSS 7.8
CVE-2019-0859

Win32k use-after-free exploited in the wild as a kernel privilege-escalation zero-day

CVSS 7.8
CVE-2019-0863

WER file-handling flaw letting a local attacker corrupt protected files to gain SYSTEM

CVSS 7.8
CVE-2019-1214

Windows CLFS driver — kernel memory-handling flaw in the log-file-system driver escalates a local user to SYSTEM

CVSS 7.8
CVE-2019-1215

Windows ws2ifsl.sys (Winsock) — a publicly-dropped local privilege escalation zero-day dubbed AngryPolarBearBug2

CVSS 7.8
CVE-2019-15752

Docker Desktop Community Edition — Local Privilege Escalation via Trojanized Credential Helper Binary

CVSS 7.8
CVE-2019-2215

Android Kernel — Binder Use-After-Free 0-Day Exploited by NSO Group

CVSS 7.8
CVE-2019-13608

Citrix StoreFront — unauthenticated XXE processing exposes sensitive server-side files and data

CVSS 7.5
CVE-2019-1367

Internet Explorer scripting engine — actively-exploited zero-day patched via emergency out-of-band update

CVSS 7.5
CVE-2019-1429

Internet Explorer Scripting Engine — Use-After-Free Remote Code Execution via Malicious Web Content

CVSS 7.5
CVE-2019-1653

Cisco RV320/RV325 Routers — Unauthenticated Configuration and Diagnostic Data Disclosure

CVSS 7.5
CVE-2019-17558

Apache Solr VelocityResponseWriter — Server-Side Template Injection Leading to Remote Code Execution

CVSS 7.5
CVE-2019-18187

Trend Micro OfficeScan — Unauthenticated Path Traversal via Zip Extraction Exposes Server Credentials and Configuration Files

CVSS 7.5
CVE-2019-19356

Netis WF2419 Router — Web Management Interface Command Injection Grants Root

CVSS 7.5
CVE-2019-20085

TVT NVMS-1000 — Unauthenticated Directory Traversal in White-Labeled DVR/NVR Firmware

CVSS 7.5
CVE-2019-6223

Apple Group FaceTime — Caller Can Force Callee's Device to Answer and Transmit Audio/Video

CVSS 7.5
CVE-2019-7481

SonicWall SMA100 — Pre-Auth SQL Injection Enabling Unauthorized Data Access, Tied to Ransomware Intrusions

CVSS 7.5
CVE-2019-11539

Pulse Connect/Policy Secure — authenticated admin console command injection, often chained after credential theft via CVE-2019-11510

CVSS 7.2
CVE-2019-18988

TeamViewer Desktop — Shared AES Key Across Installations Exposes Unattended Access Credentials

CVSS 7

Medium 8

June 2025

June 2022

May 2022

November 2021