2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-1010241 | MEDIUM | 6.5 | 1.5% | Jul 19, 2019 | Jenkins Credentials Binding Plugin Jenkins 1.17 is affected by: CWE-257: Storing Passwords in a Recoverable Format. The ... |
| CVE-2019-1010065 | MEDIUM | 6.5 | 1.4% | Jul 18, 2019 | The Sleuth Kit 4.6.0 and earlier is affected by: Integer Overflow. The impact is: Opening crafted disk image triggers cr... |
| CVE-2019-3794 | MEDIUM | 5.4 | 1.1% | Jul 18, 2019 | Cloud Foundry UAA, versions prior to v73.4.0, does not set an X-FRAME-OPTIONS header on various endpoints. A remote user... |
| CVE-2019-3734 | MEDIUM | 5.4 | 1.1% | Jul 18, 2019 | Dell EMC Unity and UnityVSA versions prior to 5.0.0.0.5.116 contain an improper authorization vulnerability in NAS Serve... |
| CVE-2019-1010069 | MEDIUM | 5.5 | 0.9% | Jul 18, 2019 | moinejf abcm2ps 8.13.20 is affected by: Incorrect Access Control. The impact is: Allows attackers to cause a denial of s... |
| CVE-2019-13644 | MEDIUM | 5.4 | 0.8% | Jul 18, 2019 | Firefly III before 4.7.17.1 is vulnerable to stored XSS due to lack of filtration of user-supplied data in a budget name... |
| CVE-2019-1943 | MEDIUM | 4.7 | 10.5% | Jul 17, 2019 | A vulnerability in the web interface of Cisco Small Business 200, 300, and 500 Series Switches software could allow an u... |
| CVE-2019-1942 | MEDIUM | 4.3 | 1.2% | Jul 17, 2019 | A vulnerability in the sponsor portal web interface for Cisco Identity Services Engine (ISE) could allow an authenticate... |
| CVE-2019-1941 | MEDIUM | 6.1 | 1.3% | Jul 17, 2019 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthentic... |
| CVE-2019-1940 | MEDIUM | 5.9 | 1.0% | Jul 17, 2019 | A vulnerability in the Web Services Management Agent (WSMA) feature of Cisco Industrial Network Director (IND) could all... |
| CVE-2019-1923 | MEDIUM | 6.6 | 0.5% | Jul 17, 2019 | A vulnerability in Cisco Small Business SPA500 Series IP Phones could allow a physically proximate attacker to execute a... |
| CVE-2019-1010266 | MEDIUM | 6.5 | 3.1% | Jul 17, 2019 | lodash prior to 4.17.11 is affected by: CWE-400: Uncontrolled Resource Consumption. The impact is: Denial of service. Th... |
| CVE-2019-1010091 | MEDIUM | 6.1 | 1.9% | Jul 17, 2019 | tinymce 4.7.11, 4.7.12 is affected by: CWE-79: Improper Neutralization of Input During Web Page Generation. The impact i... |
| CVE-2019-13626 | MEDIUM | 6.5 | 1.8% | Jul 17, 2019 | SDL (Simple DirectMedia Layer) 2.x through 2.0.9 has a heap-based buffer over-read in Fill_IMA_ADPCM_block, caused by an... |
| CVE-2019-10354 | MEDIUM | 4.3 | 1.6% | Jul 17, 2019 | A vulnerability in the Stapler web framework used in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier allowed attacker... |
| CVE-2019-4211 | MEDIUM | 5.4 | 0.7% | Jul 17, 2019 | IBM QRadar SIEM 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Ja... |
| CVE-2019-4194 | MEDIUM | 4.3 | 1.3% | Jul 17, 2019 | IBM Jazz for Service Management 1.1.3, 1.1.3.1, and 1.1.3.2 is missing function level access control that could allow a ... |
| CVE-2019-9849 | MEDIUM | 4.3 | 3.1% | Jul 17, 2019 | LibreOffice has a 'stealth mode' in which only documents from locations deemed 'trusted' are allowed to retrieve remote ... |
| CVE-2019-13603 | MEDIUM | 5.9 | 1.1% | Jul 16, 2019 | An issue was discovered in the HID Global DigitalPersona (formerly Crossmatch) U.are.U 4500 Fingerprint Reader Windows B... |
| CVE-2019-13383 | MEDIUM | 5.3 | 14.2% | Jul 16, 2019 | In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.846, the Login process allows attackers to check whether a usern... |
| CVE-2019-0234 | MEDIUM | 6.1 | 3.4% | Jul 15, 2019 | A Reflected Cross-site Scripting (XSS) vulnerability exists in Apache Roller. Roller's Math Comment Authenticator did no... |
| CVE-2019-1137 | MEDIUM | 5.4 | 1.6% | Jul 15, 2019 | A cross-site-scripting (XSS) vulnerability exists when Microsoft Exchange Server does not properly sanitize a specially ... |
| CVE-2019-1134 | MEDIUM | 5.4 | 1.6% | Jul 15, 2019 | A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a speciall... |
| CVE-2019-5447 | MEDIUM | 5.3 | 1.5% | Jul 15, 2019 | A path traversal vulnerability in <= v0.2.6 of http-file-server npm module allows attackers to list files in arbitrary f... |
| CVE-2019-1010302 | MEDIUM | 5.5 | 1.0% | Jul 15, 2019 | jhead 3.03 is affected by: Incorrect Access Control. The impact is: Denial of service. The component is: iptc.c Line 122... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now