2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-16520MEDIUM5.4The all-in-one-seo-pack plugin before 3.2.7 for WordPress (aka All in One SEO Pack) is susceptible to Stored XSS due to ...
CVE-2019-10457MEDIUM4.3A missing permission check in Jenkins Oracle Cloud Infrastructure Compute Classic Plugin allows attackers with Overall/R...
CVE-2019-10456MEDIUM4.3A cross-site request forgery vulnerability in Jenkins Oracle Cloud Infrastructure Compute Classic Plugin allows attacker...
CVE-2019-10455MEDIUM4.3A missing permission check in Jenkins Rundeck Plugin allows attackers with Overall/Read permission to connect to an atta...
CVE-2019-10454MEDIUM4.3A cross-site request forgery vulnerability in Jenkins Rundeck Plugin allows attackers to connect to an attacker-specifie...
CVE-2019-10452MEDIUM4.3Jenkins View26 Test-Reporting Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where ...
CVE-2019-10451MEDIUM4.3Jenkins SOASTA CloudTest Plugin stores credentials unencrypted in its global configuration file on the Jenkins master wh...
CVE-2019-10447MEDIUM4.3Jenkins Sofy.AI Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be vi...
CVE-2019-10445MEDIUM4.3A missing permission check in Jenkins Google Kubernetes Engine Plugin 0.7.0 and earlier allowed attackers with Overall/R...
CVE-2019-10444MEDIUM6.5Jenkins Bumblebee HP ALM Plugin 4.1.3 and earlier unconditionally disabled SSL/TLS and hostname verification for connect...
CVE-2019-10442MEDIUM4.3A missing permission check in Jenkins iceScrum Plugin 1.1.5 and earlier allowed attackers with Overall/Read permission t...
CVE-2019-10441MEDIUM4.3A cross-site request forgery vulnerability in Jenkins iceScrum Plugin 1.1.5 and earlier allowed attackers to connect to ...
CVE-2019-10439MEDIUM4.3A missing permission check in Jenkins CRX Content Package Deployer Plugin 1.8.1 and earlier in various 'doFillCredential...
CVE-2019-10438MEDIUM6.5A missing permission check in Jenkins CRX Content Package Deployer Plugin 1.8.1 and earlier allowed attackers with Overa...
CVE-2019-10436MEDIUM6.5An arbitrary file read vulnerability in Jenkins Google OAuth Credentials Plugin 0.9 and earlier allowed attackers able t...
CVE-2019-17627MEDIUM6.5The Yale Bluetooth Key application for mobile devices allows unauthorized unlock actions by sniffing Bluetooth Low Energ...
CVE-2019-13392MEDIUM6.1A reflected Cross-Site Scripting (XSS) vulnerability in MindPalette NateMail 3.0.15 allows an attacker to execute remote...
CVE-2019-17356MEDIUM6.5The Infinite Design application 3.4.12 for Android sends a username and password via TCP without any encryption during l...
CVE-2019-17223MEDIUM6.1There is HTML Injection in the Note field in Dolibarr ERP/CRM 10.0.2 via user/note.php.
CVE-2019-17595MEDIUM5.4There is a heap-based buffer over-read in the fmt_entry function in tinfo/comp_hash.c in the terminfo library in ncurses...
CVE-2019-17594MEDIUM5.3There is a heap-based buffer over-read in the _nc_find_entry function in tinfo/comp_hash.c in the terminfo library in nc...
CVE-2019-16282MEDIUM5.4In NCH Express Invoice v7.12, persistent cross site scripting (XSS) exists via the Invoices/Items/Customers/Quotes input...
CVE-2019-14227MEDIUM6.1OX App Suite 7.10.1 and 7.10.2 allows XSS.
CVE-2019-14225MEDIUM5.4OX App Suite 7.10.1 and 7.10.2 allows SSRF.
CVE-2019-17579MEDIUM6.1SonarSource SonarQube before 7.8 has XSS in project links on account/projects.

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now