2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-14333 | MEDIUM | 5.5 | 1.1% | Aug 1, 2019 | An issue was discovered on D-Link 6600-AP and DWL-3600AP Ax 4.2.0.14 21/03/2019 devices. There is a pre-authenticated de... |
| CVE-2019-14464 | MEDIUM | 5.5 | 1.3% | Jul 31, 2019 | XMFile::read in XMFile.cpp in milkyplay in MilkyTracker 1.02.00 has a heap-based buffer overflow. |
| CVE-2019-7000 | MEDIUM | 6.1 | 1.1% | Jul 31, 2019 | A Cross-Site Scripting (XSS) vulnerability in the Web UI of Avaya Aura Conferencing may allow code execution and potenti... |
| CVE-2019-10198 | MEDIUM | 6.5 | 1.6% | Jul 31, 2019 | An authentication bypass vulnerability was discovered in foreman-tasks before 0.15.7. Previously, commit tasks were sear... |
| CVE-2019-10189 | MEDIUM | 4.3 | 0.9% | Jul 31, 2019 | A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Teachers in an assignment group could modify group overr... |
| CVE-2019-10188 | MEDIUM | 4.3 | 0.9% | Jul 31, 2019 | A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Teachers in a quiz group could modify group overrides fo... |
| CVE-2019-10187 | MEDIUM | 4.3 | 0.9% | Jul 31, 2019 | A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Users with permission to delete entries from a glossary ... |
| CVE-2019-5020 | MEDIUM | 5.5 | 1.1% | Jul 31, 2019 | An exploitable denial of service vulnerability exists in the object lookup functionality of Yara 3.8.1. A specially craf... |
| CVE-2019-4163 | MEDIUM | 4.3 | 1.0% | Jul 31, 2019 | IBM StoreIQ 7.6.0.0. through 7.6.0.18 could allow an authenticated user to obtain sensitive information that a privilege... |
| CVE-2019-10366 | MEDIUM | 6.5 | 1.5% | Jul 31, 2019 | Jenkins Skytap Cloud CI Plugin 2.06 and earlier stored credentials unencrypted in job config.xml files on the Jenkins ma... |
| CVE-2019-10365 | MEDIUM | 4.3 | 0.3% | Jul 31, 2019 | Jenkins Google Kubernetes Engine Plugin 0.6.2 and earlier created a temporary file containing a temporary access token i... |
| CVE-2019-10364 | MEDIUM | 5.5 | 0.3% | Jul 31, 2019 | Jenkins Amazon EC2 Plugin 1.43 and earlier wrote the beginning of private keys to the Jenkins system log. |
| CVE-2019-10363 | MEDIUM | 4.9 | 0.6% | Jul 31, 2019 | Jenkins Configuration as Code Plugin 1.24 and earlier did not reliably identify sensitive values expected to be exported... |
| CVE-2019-10362 | MEDIUM | 5.4 | 0.7% | Jul 31, 2019 | Jenkins Configuration as Code Plugin 1.24 and earlier did not escape values resulting in variable interpolation during c... |
| CVE-2019-10361 | MEDIUM | 5.5 | 0.5% | Jul 31, 2019 | Jenkins Maven Release Plugin 0.14.0 and earlier stored credentials unencrypted on the Jenkins master where they could be... |
| CVE-2019-10360 | MEDIUM | 5.4 | 0.7% | Jul 31, 2019 | A stored cross site scripting vulnerability in Jenkins Maven Release Plugin 0.14.0 and earlier allowed attackers to inje... |
| CVE-2019-10359 | MEDIUM | 6.3 | 0.6% | Jul 31, 2019 | A cross-site request forgery vulnerability in Jenkins Maven Release Plugin 0.14.0 and earlier in the M2ReleaseAction#doS... |
| CVE-2019-10358 | MEDIUM | 6.5 | 1.0% | Jul 31, 2019 | Jenkins Maven Integration Plugin 3.3 and earlier did not apply build log decorators to module builds, potentially reveal... |
| CVE-2019-10357 | MEDIUM | 4.3 | 1.2% | Jul 31, 2019 | A missing permission check in Jenkins Pipeline: Shared Groovy Libraries Plugin 2.14 and earlier allowed users with Overa... |
| CVE-2019-10345 | MEDIUM | 5.5 | 0.3% | Jul 31, 2019 | Jenkins Configuration as Code Plugin 1.20 and earlier did not treat the proxy password as a secret to be masked when log... |
| CVE-2019-10344 | MEDIUM | 4.3 | 0.7% | Jul 31, 2019 | Missing permission checks in Jenkins Configuration as Code Plugin 1.24 and earlier in various HTTP endpoints allowed use... |
| CVE-2019-10163 | MEDIUM | 4.3 | 1.0% | Jul 30, 2019 | A Vulnerability has been found in PowerDNS Authoritative Server before versions 4.1.9, 4.0.8 allowing a remote, authoriz... |
| CVE-2019-10156 | MEDIUM | 5.4 | 1.8% | Jul 30, 2019 | A flaw was discovered in the way Ansible templating was implemented in versions before 2.6.18, 2.7.12 and 2.8.2, causing... |
| CVE-2019-10153 | MEDIUM | 5 | 2.2% | Jul 30, 2019 | A flaw was discovered in fence-agents, prior to version 4.3.4, where using non-ASCII characters in a guest VM's comment ... |
| CVE-2019-7616 | MEDIUM | 4.9 | 2.1% | Jul 30, 2019 | Kibana versions before 6.8.2 and 7.2.1 contain a server side request forgery (SSRF) flaw in the graphite integration for... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now