2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-12537MEDIUM6.1An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via the SearchN.do search field.
CVE-2019-10349MEDIUM5.4A stored cross site scripting vulnerability in Jenkins Dependency Graph Viewer Plugin 0.13 and earlier allowed attackers...
CVE-2019-10346MEDIUM6.1A reflected cross site scripting vulnerability in Jenkins Embeddable Build Status Plugin 2.0.1 and earlier allowed attac...
CVE-2019-10342MEDIUM4.3A missing permission check in Jenkins Docker Plugin 1.1.6 and earlier in various 'fillCredentialsIdItems' methods allowe...
CVE-2019-10341MEDIUM6.5A missing permission check in Jenkins Docker Plugin 1.1.6 and earlier in DockerAPI.DescriptorImpl#doTestConnection allow...
CVE-2019-13505MEDIUM6.1The Appointment Hour Booking plugin 1.1.44 for WordPress allows XSS via the E-mail field, as demonstrated by email_1.
CVE-2019-13504MEDIUM6.5There is an out-of-bounds read in Exiv2::MrwImage::readMetadata in mrwimage.cpp in Exiv2 through 0.27.2.
CVE-2019-5445MEDIUM4.9DoS in EdgeMAX EdgeSwitch prior to 1.8.2 allow an Admin user to Crash the SSH CLI interface by using crafted commands.
CVE-2019-5444MEDIUM5.3Path traversal vulnerability in version up to v1.1.3 in serve-here.js npm module allows attackers to list any file in ar...
CVE-2019-12804MEDIUM5.5In Hunesion i-oneNet version 3.0.7 ~ 3.0.53 and 4.0.4 ~ 4.0.16, due to the lack of update file integrity checking in the...
CVE-2019-11650MEDIUM5.9A potential Man in the Middle attack (MITM) was found in NetIQ Advanced Authentication Framework versions prior to 6.0.
CVE-2019-10966MEDIUM5.3In GE Aestiva and Aespire versions 7100 and 7900, a vulnerability exists where serial devices are connected via an added...
CVE-2019-13225MEDIUM6.5A NULL Pointer Dereference in match_at() in regexec.c in Oniguruma 6.9.2 allows attackers to potentially cause denial of...
CVE-2019-12724MEDIUM6.1An issue was discovered in the Teclib News plugin through 1.5.2 for GLPI. It allows a stored XSS attack via the $_POST['...
CVE-2019-9149MEDIUM6.5Mailvelope prior to 3.3.0 allows private key operations without user interaction via its client-API. By modifying an URL...
CVE-2019-9148MEDIUM4.3Mailvelope prior to 3.3.0 accepts or operates with invalid PGP public keys: Mailvelope allows importing keys that contai...
CVE-2019-13454MEDIUM6.5ImageMagick 7.0.1-0 to 7.0.8-54 Q16 allows Division by Zero in RemoveDuplicateLayers in MagickCore/layer.c.
CVE-2019-12748MEDIUM6.1TYPO3 8.3.0 through 8.7.26 and 9.0.0 through 9.5.7 allows XSS.
CVE-2019-13414MEDIUM6.1The Rencontre plugin before 3.1.3 for WordPress allows XSS via inc/rencontre_widget.php.
CVE-2019-1933MEDIUM5.8A vulnerability in the email message scanning of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could a...
CVE-2019-1932MEDIUM6.7A vulnerability in Cisco Advanced Malware Protection (AMP) for Endpoints for Windows could allow an authenticated, local...
CVE-2019-1931MEDIUM6.1Multiple vulnerabilities in the RSS dashboard in the web-based management interface of Cisco Firepower Management Center...
CVE-2019-1930MEDIUM6.1Multiple vulnerabilities in the RSS dashboard in the web-based management interface of Cisco Firepower Management Center...
CVE-2019-1922MEDIUM5.3A vulnerability in Cisco SIP IP Phone Software for Cisco IP Phone 7800 Series and 8800 Series could allow an unauthentic...
CVE-2019-1921MEDIUM5.8A vulnerability in the attachment scanning of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allo...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now