2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2019-10350HIGH8.8Jenkins Port Allocator Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they ca...
CVE-2019-10348HIGH8.8Jenkins Gogs Plugin stored credentials unencrypted in job config.xml files on the Jenkins master where they can be viewe...
CVE-2019-10347HIGH8.8Jenkins Mashup Portlets Plugin stored credentials unencrypted on the Jenkins master where they can be viewed by users wi...
CVE-2019-10340HIGH8.8A cross-site request forgery vulnerability in Jenkins Docker Plugin 1.1.6 and earlier in DockerAPI.DescriptorImpl#doTest...
CVE-2019-13503HIGH7.5mq_parse_http in mongoose.c in Mongoose 6.15 has a heap-based buffer over-read.
CVE-2019-5446HIGH7.2Command Injection in EdgeMAX EdgeSwitch prior to 1.8.2 allow an Admin user to execute commands as root.
CVE-2019-13482HIGH8.8An issue was discovered on D-Link DIR-818LW devices with firmware 2.06betab01. There is a command injection in HNAP1 (ex...
CVE-2019-13481HIGH8.8An issue was discovered on D-Link DIR-818LW devices with firmware 2.06betab01. There is a command injection in HNAP1 (ex...
CVE-2019-1873HIGH8.6A vulnerability in the cryptographic driver for Cisco Adaptive Security Appliance Software (ASA) and Firepower Threat De...
CVE-2019-13071HIGH8.8CSRF in the Agent/Center component of CyberPower PowerPanel Business Edition 3.4.0 allows an attacker to submit POST req...
CVE-2019-11020HIGH7.5Lack of authentication in file-viewing components in DDRT Dashcom Live 2019-05-09 allows anyone to remotely access all c...
CVE-2019-11019HIGH7.5Lack of authentication in case-exporting components in DDRT Dashcom Live through 2019-05-08 allows anyone to remotely ac...
CVE-2019-12747HIGH8.8TYPO3 8.x through 8.7.26 and 9.x through 9.5.7 allows Deserialization of Untrusted Data.
CVE-2019-13370HIGH8.8index.php/admin/permissions in Ignited CMS through 2017-02-19 allows CSRF to add an administrator.
CVE-2019-1894HIGH7.2A vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker wi...
CVE-2019-1893HIGH7.8A vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to ...
CVE-2019-1892HIGH7.5A vulnerability in the Secure Sockets Layer (SSL) input packet processor of Cisco Small Business 200, 300, and 500 Serie...
CVE-2019-1891HIGH7.5A vulnerability in the web interface of Cisco Small Business 200, 300, and 500 Series Managed Switches could allow an un...
CVE-2019-1887HIGH8.6A vulnerability in the Session Initiation Protocol (SIP) protocol implementation of Cisco Unified Communications Manager...
CVE-2019-13358HIGH7.5lib/DocumentToText.php in OpenCats before 0.9.4-3 has XXE that allows remote users to read files on the underlying opera...
CVE-2019-5984HIGH8.8Cross-site request forgery (CSRF) vulnerability in Custom CSS Pro 1.0.3 and earlier allows remote attackers to hijack th...
CVE-2019-5983HIGH8.8Cross-site request forgery (CSRF) vulnerability in HTML5 Maps 1.6.5.6 and earlier allows remote attackers to hijack the ...
CVE-2019-5980HIGH8.8Cross-site request forgery (CSRF) vulnerability in Related YouTube Videos versions prior to 1.9.9 allows remote attacker...
CVE-2019-5979HIGH8.8Cross-site request forgery (CSRF) vulnerability in Personalized WooCommerce Cart Page 2.4 and earlier allows remote atta...
CVE-2019-5973HIGH8.8Cross-site request forgery (CSRF) vulnerability in Online Lesson Booking 0.8.6 and earlier allows remote attackers to hi...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now