2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-16975MEDIUM6.1In FusionPBX up to 4.5.7, the file app\contacts\contact_notes.php uses an unsanitized "id" variable coming from the URL,...
CVE-2019-11282MEDIUM4.3Cloud Foundry UAA, versions prior to v74.3.0, contains an endpoint that is vulnerable to SCIM injection attack. A remote...
CVE-2019-18281MEDIUM4.3An out-of-bounds memory access in the generateDirectionalRuns() function in qtextengine.cpp in Qt qtbase 5.11.x and 5.12...
CVE-2019-16976MEDIUM6.1In FusionPBX up to 4.5.7, the file app\destinations\destination_imports.php uses an unsanitized "query_string" variable ...
CVE-2019-18219MEDIUM6.1Sitemagic CMS 4.4.1 is affected by a Cross-Site-Scripting (XSS) vulnerability, as it fails to validate user input. The a...
CVE-2019-10475MEDIUM6.1A reflected cross-site scripting vulnerability in Jenkins build-metrics Plugin allows attackers to inject arbitrary HTML...
CVE-2019-10474MEDIUM4.3A missing permission check in Jenkins Global Post Script Plugin in allowed users with Overall/Read access to list the sc...
CVE-2019-10473MEDIUM4.3A missing permission check in Jenkins Libvirt Slaves Plugin in form-related methods allowed users with Overall/Read acce...
CVE-2019-10472MEDIUM6.5A missing permission check in Jenkins Libvirt Slaves Plugin allows attackers with Overall/Read permission to connect to ...
CVE-2019-10470MEDIUM6.5A missing permission check in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin in form-related methods allowed users w...
CVE-2019-10469MEDIUM6.5A missing permission check in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin allows attackers with Overall/Read perm...
CVE-2019-10467MEDIUM6.5Jenkins Sonar Gerrit Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can ...
CVE-2019-10465MEDIUM4.3A missing permission check in Jenkins Deploy WebLogic Plugin allows attackers with Overall/Read permission to connect to...
CVE-2019-10463MEDIUM6.5A missing permission check in Jenkins Dynatrace Application Monitoring Plugin allows attackers with Overall/Read permiss...
CVE-2019-10459MEDIUM6.5Jenkins Mattermost Notification Plugin 2.7.0 and earlier stored webhook URLs containing a secret token unencrypted in it...
CVE-2019-14276MEDIUM6.5WUSTL XNAT 1.7.5.3 allows XXE attacks via a POST request body.
CVE-2019-16973MEDIUM6.1In FusionPBX up to 4.5.7, the file app\contacts\contact_edit.php uses an unsanitized "query_string" variable coming from...
CVE-2019-16972MEDIUM6.1In FusionPBX up to 4.5.7, the file app\contacts\contact_addresses.php uses an unsanitized "id" variable coming from the ...
CVE-2019-16971MEDIUM6.1In FusionPBX up to 4.5.7, the file app\messages\messages_thread.php uses an unsanitized "contact_uuid" variable coming f...
CVE-2019-8089MEDIUM6.1Adobe Experience Manager Forms versions 6.3-6.5 have a reflected cross-site scripting vulnerability. Successful exploita...
CVE-2019-15587MEDIUM5.4In the Loofah gem for Ruby through v2.3.0 unsanitized JavaScript may occur in sanitized output when a crafted SVG elemen...
CVE-2019-17189MEDIUM5.4totemodata 3.0.0_b936 has XSS via a folder name.
CVE-2019-12967MEDIUM6.5Stephan Mooltipass Moolticute through 0.42.1 (and possibly earlier versions) has Incorrect Access Control.
CVE-2019-11674MEDIUM5.9Man-in-the-middle vulnerability in Micro Focus Self Service Password Reset, affecting all versions prior to 4.4.0.4. The...
CVE-2019-17220MEDIUM6.1Rocket.Chat before 2.1.0 allows XSS via a URL on a ![title] line.

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now