2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-10382MEDIUM6.5Jenkins VMware Lab Manager Slaves Plugin 0.2.8 and earlier disables SSL/TLS and hostname verification globally for the J...
CVE-2019-10379MEDIUM6.5Jenkins Google Cloud Messaging Notification Plugin 1.0 and earlier stores credentials unencrypted in its global configur...
CVE-2019-10378MEDIUM5.3Jenkins TestLink Plugin 3.16 and earlier stores credentials unencrypted in its global configuration file on the Jenkins ...
CVE-2019-10377MEDIUM4.3A missing permission check in Jenkins Avatar Plugin 1.2 and earlier allows attackers with Overall/Read access to change ...
CVE-2019-10376MEDIUM6.1A reflected cross-site scripting vulnerability in Jenkins Wall Display Plugin 0.6.34 and earlier allows attackers to inj...
CVE-2019-10375MEDIUM6.5An arbitrary file read vulnerability in Jenkins File System SCM Plugin 2.1 and earlier allows attackers able to configur...
CVE-2019-10374MEDIUM5.4A stored cross-site scripting vulnerability in Jenkins PegDown Formatter Plugin 1.3 and earlier allows attackers able to...
CVE-2019-10373MEDIUM5.4A stored cross-site scripting vulnerability in Jenkins Build Pipeline Plugin 1.5.8 and earlier allows attackers able to ...
CVE-2019-10372MEDIUM6.1An open redirect vulnerability in Jenkins Gitlab Authentication Plugin 1.4 and earlier in GitLabSecurityRealm.java allow...
CVE-2019-10370MEDIUM6.5Jenkins Mask Passwords Plugin 2.12.0 and earlier transmits globally configured passwords in plain text as part of the co...
CVE-2019-10369MEDIUM6.5A missing permission check in Jenkins JClouds Plugin 2.14 and earlier in BlobStoreProfile.DescriptorImpl#doTestConnectio...
CVE-2019-10367MEDIUM5.5Due to an incomplete fix of CVE-2019-10343, Jenkins Configuration as Code Plugin 1.26 and earlier did not properly apply...
CVE-2019-14664MEDIUM6.5In Enigmail below 2.1, an attacker in possession of PGP encrypted emails can wrap them as sub-parts within a crafted mul...
CVE-2019-3800MEDIUM6.3CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when th...
CVE-2019-3717MEDIUM6.8Select Dell Client Commercial and Consumer platforms contain an Improper Access Vulnerability. An unauthenticated attack...
CVE-2019-4284MEDIUM4.4IBM Cloud Private 2.1.0 , 3.1.0, 3.1.1, and 3.1.2 could allow a local privileged user to obtain sensitive OIDC token tha...
CVE-2019-4261MEDIUM6.5IBM WebSphere MQ V7.1, 7.5, IBM MQ V8, IBM MQ V9.0LTS, IBM MQ V9.1 LTS, and IBM MQ V9.1 CD are vulnerable to a denial of...
CVE-2019-6968MEDIUM6.1The web interface of the D-Link DVA-5592 20180823 is vulnerable to XSS because HTML form parameters are directly reflect...
CVE-2019-10176MEDIUM4.2A flaw was found in OpenShift Container Platform, versions 3.11 and later, in which the CSRF tokens used in the cluster ...
CVE-2019-4275MEDIUM5.5IBM Jazz for Service Management 1.1.3, 1.1.3.1, and 1.1.3.2 could allow an unauthorized local user to create unique cata...
CVE-2019-3884MEDIUM5.4A vulnerability exists in the garbage collection mechanism of atomic-openshift. An attacker able spoof the UUID of a val...
CVE-2019-14338MEDIUM6.1An issue was discovered on D-Link 6600-AP and DWL-3600AP Ax 4.2.0.14 21/03/2019 devices. There is a post-authentication ...
CVE-2019-14337MEDIUM5.5An issue was discovered on D-Link 6600-AP and DWL-3600AP Ax 4.2.0.14 21/03/2019 devices. There is an ability to escape t...
CVE-2019-14336MEDIUM5.5An issue was discovered on D-Link 6600-AP and DWL-3600AP Ax 4.2.0.14 21/03/2019 devices. There is post-authenticated dum...
CVE-2019-14334MEDIUM5.5An issue was discovered on D-Link 6600-AP, DWL-3600AP, and DWL-8610AP Ax 4.2.0.14 21/03/2019 devices. There is post-auth...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now