2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-12537 | MEDIUM | 6.1 | 2.2% | Jul 11, 2019 | An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via the SearchN.do search field. |
| CVE-2019-10349 | MEDIUM | 5.4 | 3.9% | Jul 11, 2019 | A stored cross site scripting vulnerability in Jenkins Dependency Graph Viewer Plugin 0.13 and earlier allowed attackers... |
| CVE-2019-10346 | MEDIUM | 6.1 | 1.7% | Jul 11, 2019 | A reflected cross site scripting vulnerability in Jenkins Embeddable Build Status Plugin 2.0.1 and earlier allowed attac... |
| CVE-2019-10342 | MEDIUM | 4.3 | 1.4% | Jul 11, 2019 | A missing permission check in Jenkins Docker Plugin 1.1.6 and earlier in various 'fillCredentialsIdItems' methods allowe... |
| CVE-2019-10341 | MEDIUM | 6.5 | 1.7% | Jul 11, 2019 | A missing permission check in Jenkins Docker Plugin 1.1.6 and earlier in DockerAPI.DescriptorImpl#doTestConnection allow... |
| CVE-2019-13505 | MEDIUM | 6.1 | 1.4% | Jul 11, 2019 | The Appointment Hour Booking plugin 1.1.44 for WordPress allows XSS via the E-mail field, as demonstrated by email_1. |
| CVE-2019-13504 | MEDIUM | 6.5 | 2.4% | Jul 11, 2019 | There is an out-of-bounds read in Exiv2::MrwImage::readMetadata in mrwimage.cpp in Exiv2 through 0.27.2. |
| CVE-2019-5445 | MEDIUM | 4.9 | 1.3% | Jul 10, 2019 | DoS in EdgeMAX EdgeSwitch prior to 1.8.2 allow an Admin user to Crash the SSH CLI interface by using crafted commands. |
| CVE-2019-5444 | MEDIUM | 5.3 | 1.5% | Jul 10, 2019 | Path traversal vulnerability in version up to v1.1.3 in serve-here.js npm module allows attackers to list any file in ar... |
| CVE-2019-12804 | MEDIUM | 5.5 | 0.4% | Jul 10, 2019 | In Hunesion i-oneNet version 3.0.7 ~ 3.0.53 and 4.0.4 ~ 4.0.16, due to the lack of update file integrity checking in the... |
| CVE-2019-11650 | MEDIUM | 5.9 | 0.8% | Jul 10, 2019 | A potential Man in the Middle attack (MITM) was found in NetIQ Advanced Authentication Framework versions prior to 6.0. |
| CVE-2019-10966 | MEDIUM | 5.3 | 1.3% | Jul 10, 2019 | In GE Aestiva and Aespire versions 7100 and 7900, a vulnerability exists where serial devices are connected via an added... |
| CVE-2019-13225 | MEDIUM | 6.5 | 2.1% | Jul 10, 2019 | A NULL Pointer Dereference in match_at() in regexec.c in Oniguruma 6.9.2 allows attackers to potentially cause denial of... |
| CVE-2019-12724 | MEDIUM | 6.1 | 1.2% | Jul 10, 2019 | An issue was discovered in the Teclib News plugin through 1.5.2 for GLPI. It allows a stored XSS attack via the $_POST['... |
| CVE-2019-9149 | MEDIUM | 6.5 | 0.9% | Jul 9, 2019 | Mailvelope prior to 3.3.0 allows private key operations without user interaction via its client-API. By modifying an URL... |
| CVE-2019-9148 | MEDIUM | 4.3 | 1.4% | Jul 9, 2019 | Mailvelope prior to 3.3.0 accepts or operates with invalid PGP public keys: Mailvelope allows importing keys that contai... |
| CVE-2019-13454 | MEDIUM | 6.5 | 4.4% | Jul 9, 2019 | ImageMagick 7.0.1-0 to 7.0.8-54 Q16 allows Division by Zero in RemoveDuplicateLayers in MagickCore/layer.c. |
| CVE-2019-12748 | MEDIUM | 6.1 | 0.7% | Jul 9, 2019 | TYPO3 8.3.0 through 8.7.26 and 9.0.0 through 9.5.7 allows XSS. |
| CVE-2019-13414 | MEDIUM | 6.1 | 1.1% | Jul 8, 2019 | The Rencontre plugin before 3.1.3 for WordPress allows XSS via inc/rencontre_widget.php. |
| CVE-2019-1933 | MEDIUM | 5.8 | 1.2% | Jul 6, 2019 | A vulnerability in the email message scanning of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could a... |
| CVE-2019-1932 | MEDIUM | 6.7 | 0.3% | Jul 6, 2019 | A vulnerability in Cisco Advanced Malware Protection (AMP) for Endpoints for Windows could allow an authenticated, local... |
| CVE-2019-1931 | MEDIUM | 6.1 | 1.1% | Jul 6, 2019 | Multiple vulnerabilities in the RSS dashboard in the web-based management interface of Cisco Firepower Management Center... |
| CVE-2019-1930 | MEDIUM | 6.1 | 1.1% | Jul 6, 2019 | Multiple vulnerabilities in the RSS dashboard in the web-based management interface of Cisco Firepower Management Center... |
| CVE-2019-1922 | MEDIUM | 5.3 | 1.3% | Jul 6, 2019 | A vulnerability in Cisco SIP IP Phone Software for Cisco IP Phone 7800 Series and 8800 Series could allow an unauthentic... |
| CVE-2019-1921 | MEDIUM | 5.8 | 1.4% | Jul 6, 2019 | A vulnerability in the attachment scanning of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allo... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now