2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-16975 | MEDIUM | 6.1 | 0.7% | Oct 23, 2019 | In FusionPBX up to 4.5.7, the file app\contacts\contact_notes.php uses an unsanitized "id" variable coming from the URL,... |
| CVE-2019-11282 | MEDIUM | 4.3 | 1.1% | Oct 23, 2019 | Cloud Foundry UAA, versions prior to v74.3.0, contains an endpoint that is vulnerable to SCIM injection attack. A remote... |
| CVE-2019-18281 | MEDIUM | 4.3 | 2.1% | Oct 23, 2019 | An out-of-bounds memory access in the generateDirectionalRuns() function in qtextengine.cpp in Qt qtbase 5.11.x and 5.12... |
| CVE-2019-16976 | MEDIUM | 6.1 | 0.7% | Oct 23, 2019 | In FusionPBX up to 4.5.7, the file app\destinations\destination_imports.php uses an unsanitized "query_string" variable ... |
| CVE-2019-18219 | MEDIUM | 6.1 | 0.9% | Oct 23, 2019 | Sitemagic CMS 4.4.1 is affected by a Cross-Site-Scripting (XSS) vulnerability, as it fails to validate user input. The a... |
| CVE-2019-10475 | MEDIUM | 6.1 | 57.7% | Oct 23, 2019 | A reflected cross-site scripting vulnerability in Jenkins build-metrics Plugin allows attackers to inject arbitrary HTML... |
| CVE-2019-10474 | MEDIUM | 4.3 | 0.7% | Oct 23, 2019 | A missing permission check in Jenkins Global Post Script Plugin in allowed users with Overall/Read access to list the sc... |
| CVE-2019-10473 | MEDIUM | 4.3 | 0.7% | Oct 23, 2019 | A missing permission check in Jenkins Libvirt Slaves Plugin in form-related methods allowed users with Overall/Read acce... |
| CVE-2019-10472 | MEDIUM | 6.5 | 0.8% | Oct 23, 2019 | A missing permission check in Jenkins Libvirt Slaves Plugin allows attackers with Overall/Read permission to connect to ... |
| CVE-2019-10470 | MEDIUM | 6.5 | 0.8% | Oct 23, 2019 | A missing permission check in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin in form-related methods allowed users w... |
| CVE-2019-10469 | MEDIUM | 6.5 | 0.8% | Oct 23, 2019 | A missing permission check in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin allows attackers with Overall/Read perm... |
| CVE-2019-10467 | MEDIUM | 6.5 | 0.9% | Oct 23, 2019 | Jenkins Sonar Gerrit Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can ... |
| CVE-2019-10465 | MEDIUM | 4.3 | 0.8% | Oct 23, 2019 | A missing permission check in Jenkins Deploy WebLogic Plugin allows attackers with Overall/Read permission to connect to... |
| CVE-2019-10463 | MEDIUM | 6.5 | 0.8% | Oct 23, 2019 | A missing permission check in Jenkins Dynatrace Application Monitoring Plugin allows attackers with Overall/Read permiss... |
| CVE-2019-10459 | MEDIUM | 6.5 | 0.9% | Oct 23, 2019 | Jenkins Mattermost Notification Plugin 2.7.0 and earlier stored webhook URLs containing a secret token unencrypted in it... |
| CVE-2019-14276 | MEDIUM | 6.5 | 1.0% | Oct 23, 2019 | WUSTL XNAT 1.7.5.3 allows XXE attacks via a POST request body. |
| CVE-2019-16973 | MEDIUM | 6.1 | 0.8% | Oct 22, 2019 | In FusionPBX up to 4.5.7, the file app\contacts\contact_edit.php uses an unsanitized "query_string" variable coming from... |
| CVE-2019-16972 | MEDIUM | 6.1 | 0.8% | Oct 22, 2019 | In FusionPBX up to 4.5.7, the file app\contacts\contact_addresses.php uses an unsanitized "id" variable coming from the ... |
| CVE-2019-16971 | MEDIUM | 6.1 | 0.8% | Oct 22, 2019 | In FusionPBX up to 4.5.7, the file app\messages\messages_thread.php uses an unsanitized "contact_uuid" variable coming f... |
| CVE-2019-8089 | MEDIUM | 6.1 | 1.5% | Oct 22, 2019 | Adobe Experience Manager Forms versions 6.3-6.5 have a reflected cross-site scripting vulnerability. Successful exploita... |
| CVE-2019-15587 | MEDIUM | 5.4 | 1.4% | Oct 22, 2019 | In the Loofah gem for Ruby through v2.3.0 unsanitized JavaScript may occur in sanitized output when a crafted SVG elemen... |
| CVE-2019-17189 | MEDIUM | 5.4 | 0.8% | Oct 22, 2019 | totemodata 3.0.0_b936 has XSS via a folder name. |
| CVE-2019-12967 | MEDIUM | 6.5 | 1.0% | Oct 22, 2019 | Stephan Mooltipass Moolticute through 0.42.1 (and possibly earlier versions) has Incorrect Access Control. |
| CVE-2019-11674 | MEDIUM | 5.9 | 0.4% | Oct 22, 2019 | Man-in-the-middle vulnerability in Micro Focus Self Service Password Reset, affecting all versions prior to 4.4.0.4. The... |
| CVE-2019-17220 | MEDIUM | 6.1 | 4.0% | Oct 21, 2019 | Rocket.Chat before 2.1.0 allows XSS via a URL on a ![title] line. |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now