2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-10382 | MEDIUM | 6.5 | 0.8% | Aug 7, 2019 | Jenkins VMware Lab Manager Slaves Plugin 0.2.8 and earlier disables SSL/TLS and hostname verification globally for the J... |
| CVE-2019-10379 | MEDIUM | 6.5 | 0.4% | Aug 7, 2019 | Jenkins Google Cloud Messaging Notification Plugin 1.0 and earlier stores credentials unencrypted in its global configur... |
| CVE-2019-10378 | MEDIUM | 5.3 | 0.5% | Aug 7, 2019 | Jenkins TestLink Plugin 3.16 and earlier stores credentials unencrypted in its global configuration file on the Jenkins ... |
| CVE-2019-10377 | MEDIUM | 4.3 | 0.7% | Aug 7, 2019 | A missing permission check in Jenkins Avatar Plugin 1.2 and earlier allows attackers with Overall/Read access to change ... |
| CVE-2019-10376 | MEDIUM | 6.1 | 0.8% | Aug 7, 2019 | A reflected cross-site scripting vulnerability in Jenkins Wall Display Plugin 0.6.34 and earlier allows attackers to inj... |
| CVE-2019-10375 | MEDIUM | 6.5 | 1.0% | Aug 7, 2019 | An arbitrary file read vulnerability in Jenkins File System SCM Plugin 2.1 and earlier allows attackers able to configur... |
| CVE-2019-10374 | MEDIUM | 5.4 | 0.7% | Aug 7, 2019 | A stored cross-site scripting vulnerability in Jenkins PegDown Formatter Plugin 1.3 and earlier allows attackers able to... |
| CVE-2019-10373 | MEDIUM | 5.4 | 0.7% | Aug 7, 2019 | A stored cross-site scripting vulnerability in Jenkins Build Pipeline Plugin 1.5.8 and earlier allows attackers able to ... |
| CVE-2019-10372 | MEDIUM | 6.1 | 1.0% | Aug 7, 2019 | An open redirect vulnerability in Jenkins Gitlab Authentication Plugin 1.4 and earlier in GitLabSecurityRealm.java allow... |
| CVE-2019-10370 | MEDIUM | 6.5 | 1.3% | Aug 7, 2019 | Jenkins Mask Passwords Plugin 2.12.0 and earlier transmits globally configured passwords in plain text as part of the co... |
| CVE-2019-10369 | MEDIUM | 6.5 | 1.0% | Aug 7, 2019 | A missing permission check in Jenkins JClouds Plugin 2.14 and earlier in BlobStoreProfile.DescriptorImpl#doTestConnectio... |
| CVE-2019-10367 | MEDIUM | 5.5 | 0.4% | Aug 7, 2019 | Due to an incomplete fix of CVE-2019-10343, Jenkins Configuration as Code Plugin 1.26 and earlier did not properly apply... |
| CVE-2019-14664 | MEDIUM | 6.5 | 1.0% | Aug 5, 2019 | In Enigmail below 2.1, an attacker in possession of PGP encrypted emails can wrap them as sub-parts within a crafted mul... |
| CVE-2019-3800 | MEDIUM | 6.3 | 2.1% | Aug 5, 2019 | CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when th... |
| CVE-2019-3717 | MEDIUM | 6.8 | 0.4% | Aug 5, 2019 | Select Dell Client Commercial and Consumer platforms contain an Improper Access Vulnerability. An unauthenticated attack... |
| CVE-2019-4284 | MEDIUM | 4.4 | 0.4% | Aug 5, 2019 | IBM Cloud Private 2.1.0 , 3.1.0, 3.1.1, and 3.1.2 could allow a local privileged user to obtain sensitive OIDC token tha... |
| CVE-2019-4261 | MEDIUM | 6.5 | 2.6% | Aug 5, 2019 | IBM WebSphere MQ V7.1, 7.5, IBM MQ V8, IBM MQ V9.0LTS, IBM MQ V9.1 LTS, and IBM MQ V9.1 CD are vulnerable to a denial of... |
| CVE-2019-6968 | MEDIUM | 6.1 | 1.1% | Aug 2, 2019 | The web interface of the D-Link DVA-5592 20180823 is vulnerable to XSS because HTML form parameters are directly reflect... |
| CVE-2019-10176 | MEDIUM | 4.2 | 0.5% | Aug 2, 2019 | A flaw was found in OpenShift Container Platform, versions 3.11 and later, in which the CSRF tokens used in the cluster ... |
| CVE-2019-4275 | MEDIUM | 5.5 | 0.3% | Aug 2, 2019 | IBM Jazz for Service Management 1.1.3, 1.1.3.1, and 1.1.3.2 could allow an unauthorized local user to create unique cata... |
| CVE-2019-3884 | MEDIUM | 5.4 | 0.6% | Aug 1, 2019 | A vulnerability exists in the garbage collection mechanism of atomic-openshift. An attacker able spoof the UUID of a val... |
| CVE-2019-14338 | MEDIUM | 6.1 | 2.0% | Aug 1, 2019 | An issue was discovered on D-Link 6600-AP and DWL-3600AP Ax 4.2.0.14 21/03/2019 devices. There is a post-authentication ... |
| CVE-2019-14337 | MEDIUM | 5.5 | 0.8% | Aug 1, 2019 | An issue was discovered on D-Link 6600-AP and DWL-3600AP Ax 4.2.0.14 21/03/2019 devices. There is an ability to escape t... |
| CVE-2019-14336 | MEDIUM | 5.5 | 1.3% | Aug 1, 2019 | An issue was discovered on D-Link 6600-AP and DWL-3600AP Ax 4.2.0.14 21/03/2019 devices. There is post-authenticated dum... |
| CVE-2019-14334 | MEDIUM | 5.5 | 0.4% | Aug 1, 2019 | An issue was discovered on D-Link 6600-AP, DWL-3600AP, and DWL-8610AP Ax 4.2.0.14 21/03/2019 devices. There is post-auth... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now