2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-16520 | MEDIUM | 5.4 | 1.5% | Oct 16, 2019 | The all-in-one-seo-pack plugin before 3.2.7 for WordPress (aka All in One SEO Pack) is susceptible to Stored XSS due to ... |
| CVE-2019-10457 | MEDIUM | 4.3 | 0.6% | Oct 16, 2019 | A missing permission check in Jenkins Oracle Cloud Infrastructure Compute Classic Plugin allows attackers with Overall/R... |
| CVE-2019-10456 | MEDIUM | 4.3 | 0.6% | Oct 16, 2019 | A cross-site request forgery vulnerability in Jenkins Oracle Cloud Infrastructure Compute Classic Plugin allows attacker... |
| CVE-2019-10455 | MEDIUM | 4.3 | 0.6% | Oct 16, 2019 | A missing permission check in Jenkins Rundeck Plugin allows attackers with Overall/Read permission to connect to an atta... |
| CVE-2019-10454 | MEDIUM | 4.3 | 0.7% | Oct 16, 2019 | A cross-site request forgery vulnerability in Jenkins Rundeck Plugin allows attackers to connect to an attacker-specifie... |
| CVE-2019-10452 | MEDIUM | 4.3 | 0.5% | Oct 16, 2019 | Jenkins View26 Test-Reporting Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where ... |
| CVE-2019-10451 | MEDIUM | 4.3 | 0.5% | Oct 16, 2019 | Jenkins SOASTA CloudTest Plugin stores credentials unencrypted in its global configuration file on the Jenkins master wh... |
| CVE-2019-10447 | MEDIUM | 4.3 | 0.5% | Oct 16, 2019 | Jenkins Sofy.AI Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be vi... |
| CVE-2019-10445 | MEDIUM | 4.3 | 0.7% | Oct 16, 2019 | A missing permission check in Jenkins Google Kubernetes Engine Plugin 0.7.0 and earlier allowed attackers with Overall/R... |
| CVE-2019-10444 | MEDIUM | 6.5 | 0.8% | Oct 16, 2019 | Jenkins Bumblebee HP ALM Plugin 4.1.3 and earlier unconditionally disabled SSL/TLS and hostname verification for connect... |
| CVE-2019-10442 | MEDIUM | 4.3 | 0.7% | Oct 16, 2019 | A missing permission check in Jenkins iceScrum Plugin 1.1.5 and earlier allowed attackers with Overall/Read permission t... |
| CVE-2019-10441 | MEDIUM | 4.3 | 0.7% | Oct 16, 2019 | A cross-site request forgery vulnerability in Jenkins iceScrum Plugin 1.1.5 and earlier allowed attackers to connect to ... |
| CVE-2019-10439 | MEDIUM | 4.3 | 0.7% | Oct 16, 2019 | A missing permission check in Jenkins CRX Content Package Deployer Plugin 1.8.1 and earlier in various 'doFillCredential... |
| CVE-2019-10438 | MEDIUM | 6.5 | 1.0% | Oct 16, 2019 | A missing permission check in Jenkins CRX Content Package Deployer Plugin 1.8.1 and earlier allowed attackers with Overa... |
| CVE-2019-10436 | MEDIUM | 6.5 | 1.0% | Oct 16, 2019 | An arbitrary file read vulnerability in Jenkins Google OAuth Credentials Plugin 0.9 and earlier allowed attackers able t... |
| CVE-2019-17627 | MEDIUM | 6.5 | 0.7% | Oct 16, 2019 | The Yale Bluetooth Key application for mobile devices allows unauthorized unlock actions by sniffing Bluetooth Low Energ... |
| CVE-2019-13392 | MEDIUM | 6.1 | 3.9% | Oct 16, 2019 | A reflected Cross-Site Scripting (XSS) vulnerability in MindPalette NateMail 3.0.15 allows an attacker to execute remote... |
| CVE-2019-17356 | MEDIUM | 6.5 | 0.4% | Oct 15, 2019 | The Infinite Design application 3.4.12 for Android sends a username and password via TCP without any encryption during l... |
| CVE-2019-17223 | MEDIUM | 6.1 | 1.1% | Oct 15, 2019 | There is HTML Injection in the Note field in Dolibarr ERP/CRM 10.0.2 via user/note.php. |
| CVE-2019-17595 | MEDIUM | 5.4 | 2.0% | Oct 14, 2019 | There is a heap-based buffer over-read in the fmt_entry function in tinfo/comp_hash.c in the terminfo library in ncurses... |
| CVE-2019-17594 | MEDIUM | 5.3 | 0.5% | Oct 14, 2019 | There is a heap-based buffer over-read in the _nc_find_entry function in tinfo/comp_hash.c in the terminfo library in nc... |
| CVE-2019-16282 | MEDIUM | 5.4 | 0.6% | Oct 14, 2019 | In NCH Express Invoice v7.12, persistent cross site scripting (XSS) exists via the Invoices/Items/Customers/Quotes input... |
| CVE-2019-14227 | MEDIUM | 6.1 | 1.0% | Oct 14, 2019 | OX App Suite 7.10.1 and 7.10.2 allows XSS. |
| CVE-2019-14225 | MEDIUM | 5.4 | 0.7% | Oct 14, 2019 | OX App Suite 7.10.1 and 7.10.2 allows SSRF. |
| CVE-2019-17579 | MEDIUM | 6.1 | 0.7% | Oct 14, 2019 | SonarSource SonarQube before 7.8 has XSS in project links on account/projects. |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now