2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-10391 | MEDIUM | 6.5 | 0.8% | Aug 28, 2019 | Jenkins IBM Application Security on Cloud Plugin 1.2.4 and earlier transmitted configured passwords in plain text as par... |
| CVE-2019-10383 | MEDIUM | 4.8 | 1.4% | Aug 28, 2019 | A stored cross-site scripting vulnerability in Jenkins 2.191 and earlier, LTS 2.176.2 and earlier allowed attackers with... |
| CVE-2019-13237 | MEDIUM | 4.3 | 7.3% | Aug 27, 2019 | In Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple resources vulnerable to Local File Inclusion that allow an atta... |
| CVE-2019-15666 | MEDIUM | 4.4 | 1.7% | Aug 27, 2019 | An issue was discovered in the Linux kernel before 5.0.19. There is an out-of-bounds array access in __xfrm_policy_unlin... |
| CVE-2019-12400 | MEDIUM | 5.5 | 0.8% | Aug 23, 2019 | In version 2.0.3 Apache Santuario XML Security for Java, a caching mechanism was introduced to speed up creating new XML... |
| CVE-2019-5592 | MEDIUM | 5.9 | 0.7% | Aug 23, 2019 | Multiple padding oracle vulnerabilities (Zombie POODLE, GOLDENDOODLE, OpenSSL 0-length) in the CBC padding implementatio... |
| CVE-2019-15531 | MEDIUM | 6.5 | 1.7% | Aug 23, 2019 | GNU Libextractor through 1.9 has a heap-based buffer over-read in the function EXTRACTOR_dvi_extract_method in plugins/d... |
| CVE-2019-13014 | MEDIUM | 5.5 | 0.4% | Aug 23, 2019 | Little Snitch versions 4.4.0 fixes a vulnerability in a privileged helper tool. However, the operating system may have m... |
| CVE-2019-13013 | MEDIUM | 5.5 | 0.3% | Aug 23, 2019 | Little Snitch versions 4.3.0 to 4.3.2 have a local privilege escalation vulnerability in their privileged helper tool. T... |
| CVE-2019-8446 | MEDIUM | 5.3 | 17.5% | Aug 23, 2019 | The /rest/issueNav/1/issueTable resource in Jira before version 8.3.2 allows remote attackers to enumerate usernames via... |
| CVE-2019-8445 | MEDIUM | 5.3 | 2.7% | Aug 23, 2019 | Several worklog rest resources in Jira before version 7.13.7, and from version 8.0.0 before version 8.3.2 allow remote a... |
| CVE-2019-8444 | MEDIUM | 5.4 | 0.9% | Aug 23, 2019 | The wikirenderer component in Jira before version 7.13.6, and from version 8.0.0 before version 8.3.2 allows remote atta... |
| CVE-2019-15499 | MEDIUM | 6.1 | 0.9% | Aug 23, 2019 | CodiMD 1.3.1, when Safari is used, allows XSS via an IFRAME element with allow-top-navigation in the sandbox attribute, ... |
| CVE-2019-5634 | MEDIUM | 6.5 | 0.4% | Aug 22, 2019 | An inclusion of sensitive information in log files vulnerability is present in Hickory Smart for Android mobile devices ... |
| CVE-2019-5633 | MEDIUM | 5.5 | 0.4% | Aug 22, 2019 | An insecure storage of sensitive information vulnerability is present in Hickory Smart for iOS mobile devices from Belwi... |
| CVE-2019-5632 | MEDIUM | 5.5 | 0.4% | Aug 22, 2019 | An insecure storage of sensitive information vulnerability is present in Hickory Smart for Android mobile devices from B... |
| CVE-2019-11602 | MEDIUM | 5.3 | 1.1% | Aug 21, 2019 | Leakage of stack traces in remote access to backup & restore in earlier versions than ProSyst mBS SDK 8.2.6 and Bosch Io... |
| CVE-2019-1984 | MEDIUM | 6.5 | 1.6% | Aug 21, 2019 | A vulnerability in Cisco Enterprise Network Functions Virtualization Infrastructure Software (NFVIS) could allow an auth... |
| CVE-2019-1948 | MEDIUM | 5.9 | 0.9% | Aug 21, 2019 | A vulnerability in Cisco Webex Meetings Mobile (iOS) could allow an unauthenticated, remote attacker to gain unauthorize... |
| CVE-2019-1839 | MEDIUM | 6.7 | 0.4% | Aug 21, 2019 | A vulnerability in Cisco Remote PHY Device Software could allow an authenticated, local attacker to execute commands on ... |
| CVE-2019-14246 | MEDIUM | 6.5 | 2.2% | Aug 21, 2019 | In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to discover... |
| CVE-2019-14245 | MEDIUM | 6.5 | 1.9% | Aug 21, 2019 | In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to delete d... |
| CVE-2019-13599 | MEDIUM | 5.3 | 4.0% | Aug 21, 2019 | In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.848, the Login process allows attackers to check whether a usern... |
| CVE-2019-12626 | MEDIUM | 4.8 | 0.8% | Aug 21, 2019 | A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow ... |
| CVE-2019-12623 | MEDIUM | 4.3 | 1.2% | Aug 21, 2019 | A vulnerability in the web server functionality of Cisco Enterprise Network Functions Virtualization Infrastructure Soft... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now