2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-10391MEDIUM6.5Jenkins IBM Application Security on Cloud Plugin 1.2.4 and earlier transmitted configured passwords in plain text as par...
CVE-2019-10383MEDIUM4.8A stored cross-site scripting vulnerability in Jenkins 2.191 and earlier, LTS 2.176.2 and earlier allowed attackers with...
CVE-2019-13237MEDIUM4.3In Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple resources vulnerable to Local File Inclusion that allow an atta...
CVE-2019-15666MEDIUM4.4An issue was discovered in the Linux kernel before 5.0.19. There is an out-of-bounds array access in __xfrm_policy_unlin...
CVE-2019-12400MEDIUM5.5In version 2.0.3 Apache Santuario XML Security for Java, a caching mechanism was introduced to speed up creating new XML...
CVE-2019-5592MEDIUM5.9Multiple padding oracle vulnerabilities (Zombie POODLE, GOLDENDOODLE, OpenSSL 0-length) in the CBC padding implementatio...
CVE-2019-15531MEDIUM6.5GNU Libextractor through 1.9 has a heap-based buffer over-read in the function EXTRACTOR_dvi_extract_method in plugins/d...
CVE-2019-13014MEDIUM5.5Little Snitch versions 4.4.0 fixes a vulnerability in a privileged helper tool. However, the operating system may have m...
CVE-2019-13013MEDIUM5.5Little Snitch versions 4.3.0 to 4.3.2 have a local privilege escalation vulnerability in their privileged helper tool. T...
CVE-2019-8446MEDIUM5.3The /rest/issueNav/1/issueTable resource in Jira before version 8.3.2 allows remote attackers to enumerate usernames via...
CVE-2019-8445MEDIUM5.3Several worklog rest resources in Jira before version 7.13.7, and from version 8.0.0 before version 8.3.2 allow remote a...
CVE-2019-8444MEDIUM5.4The wikirenderer component in Jira before version 7.13.6, and from version 8.0.0 before version 8.3.2 allows remote atta...
CVE-2019-15499MEDIUM6.1CodiMD 1.3.1, when Safari is used, allows XSS via an IFRAME element with allow-top-navigation in the sandbox attribute, ...
CVE-2019-5634MEDIUM6.5An inclusion of sensitive information in log files vulnerability is present in Hickory Smart for Android mobile devices ...
CVE-2019-5633MEDIUM5.5An insecure storage of sensitive information vulnerability is present in Hickory Smart for iOS mobile devices from Belwi...
CVE-2019-5632MEDIUM5.5An insecure storage of sensitive information vulnerability is present in Hickory Smart for Android mobile devices from B...
CVE-2019-11602MEDIUM5.3Leakage of stack traces in remote access to backup & restore in earlier versions than ProSyst mBS SDK 8.2.6 and Bosch Io...
CVE-2019-1984MEDIUM6.5A vulnerability in Cisco Enterprise Network Functions Virtualization Infrastructure Software (NFVIS) could allow an auth...
CVE-2019-1948MEDIUM5.9A vulnerability in Cisco Webex Meetings Mobile (iOS) could allow an unauthenticated, remote attacker to gain unauthorize...
CVE-2019-1839MEDIUM6.7A vulnerability in Cisco Remote PHY Device Software could allow an authenticated, local attacker to execute commands on ...
CVE-2019-14246MEDIUM6.5In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to discover...
CVE-2019-14245MEDIUM6.5In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to delete d...
CVE-2019-13599MEDIUM5.3In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.848, the Login process allows attackers to check whether a usern...
CVE-2019-12626MEDIUM4.8A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow ...
CVE-2019-12623MEDIUM4.3A vulnerability in the web server functionality of Cisco Enterprise Network Functions Virtualization Infrastructure Soft...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now