2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-14333MEDIUM5.5An issue was discovered on D-Link 6600-AP and DWL-3600AP Ax 4.2.0.14 21/03/2019 devices. There is a pre-authenticated de...
CVE-2019-14464MEDIUM5.5XMFile::read in XMFile.cpp in milkyplay in MilkyTracker 1.02.00 has a heap-based buffer overflow.
CVE-2019-7000MEDIUM6.1A Cross-Site Scripting (XSS) vulnerability in the Web UI of Avaya Aura Conferencing may allow code execution and potenti...
CVE-2019-10198MEDIUM6.5An authentication bypass vulnerability was discovered in foreman-tasks before 0.15.7. Previously, commit tasks were sear...
CVE-2019-10189MEDIUM4.3A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Teachers in an assignment group could modify group overr...
CVE-2019-10188MEDIUM4.3A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Teachers in a quiz group could modify group overrides fo...
CVE-2019-10187MEDIUM4.3A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Users with permission to delete entries from a glossary ...
CVE-2019-5020MEDIUM5.5An exploitable denial of service vulnerability exists in the object lookup functionality of Yara 3.8.1. A specially craf...
CVE-2019-4163MEDIUM4.3IBM StoreIQ 7.6.0.0. through 7.6.0.18 could allow an authenticated user to obtain sensitive information that a privilege...
CVE-2019-10366MEDIUM6.5Jenkins Skytap Cloud CI Plugin 2.06 and earlier stored credentials unencrypted in job config.xml files on the Jenkins ma...
CVE-2019-10365MEDIUM4.3Jenkins Google Kubernetes Engine Plugin 0.6.2 and earlier created a temporary file containing a temporary access token i...
CVE-2019-10364MEDIUM5.5Jenkins Amazon EC2 Plugin 1.43 and earlier wrote the beginning of private keys to the Jenkins system log.
CVE-2019-10363MEDIUM4.9Jenkins Configuration as Code Plugin 1.24 and earlier did not reliably identify sensitive values expected to be exported...
CVE-2019-10362MEDIUM5.4Jenkins Configuration as Code Plugin 1.24 and earlier did not escape values resulting in variable interpolation during c...
CVE-2019-10361MEDIUM5.5Jenkins Maven Release Plugin 0.14.0 and earlier stored credentials unencrypted on the Jenkins master where they could be...
CVE-2019-10360MEDIUM5.4A stored cross site scripting vulnerability in Jenkins Maven Release Plugin 0.14.0 and earlier allowed attackers to inje...
CVE-2019-10359MEDIUM6.3A cross-site request forgery vulnerability in Jenkins Maven Release Plugin 0.14.0 and earlier in the M2ReleaseAction#doS...
CVE-2019-10358MEDIUM6.5Jenkins Maven Integration Plugin 3.3 and earlier did not apply build log decorators to module builds, potentially reveal...
CVE-2019-10357MEDIUM4.3A missing permission check in Jenkins Pipeline: Shared Groovy Libraries Plugin 2.14 and earlier allowed users with Overa...
CVE-2019-10345MEDIUM5.5Jenkins Configuration as Code Plugin 1.20 and earlier did not treat the proxy password as a secret to be masked when log...
CVE-2019-10344MEDIUM4.3Missing permission checks in Jenkins Configuration as Code Plugin 1.24 and earlier in various HTTP endpoints allowed use...
CVE-2019-10163MEDIUM4.3A Vulnerability has been found in PowerDNS Authoritative Server before versions 4.1.9, 4.0.8 allowing a remote, authoriz...
CVE-2019-10156MEDIUM5.4A flaw was discovered in the way Ansible templating was implemented in versions before 2.6.18, 2.7.12 and 2.8.2, causing...
CVE-2019-10153MEDIUM5A flaw was discovered in fence-agents, prior to version 4.3.4, where using non-ASCII characters in a guest VM's comment ...
CVE-2019-7616MEDIUM4.9Kibana versions before 6.8.2 and 7.2.1 contain a server side request forgery (SSRF) flaw in the graphite integration for...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now