2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-10350 | HIGH | 8.8 | 1.7% | Jul 11, 2019 | Jenkins Port Allocator Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they ca... |
| CVE-2019-10348 | HIGH | 8.8 | 1.7% | Jul 11, 2019 | Jenkins Gogs Plugin stored credentials unencrypted in job config.xml files on the Jenkins master where they can be viewe... |
| CVE-2019-10347 | HIGH | 8.8 | 1.8% | Jul 11, 2019 | Jenkins Mashup Portlets Plugin stored credentials unencrypted on the Jenkins master where they can be viewed by users wi... |
| CVE-2019-10340 | HIGH | 8.8 | 1.4% | Jul 11, 2019 | A cross-site request forgery vulnerability in Jenkins Docker Plugin 1.1.6 and earlier in DockerAPI.DescriptorImpl#doTest... |
| CVE-2019-13503 | HIGH | 7.5 | 1.4% | Jul 11, 2019 | mq_parse_http in mongoose.c in Mongoose 6.15 has a heap-based buffer over-read. |
| CVE-2019-5446 | HIGH | 7.2 | 2.7% | Jul 10, 2019 | Command Injection in EdgeMAX EdgeSwitch prior to 1.8.2 allow an Admin user to execute commands as root. |
| CVE-2019-13482 | HIGH | 8.8 | 8.1% | Jul 10, 2019 | An issue was discovered on D-Link DIR-818LW devices with firmware 2.06betab01. There is a command injection in HNAP1 (ex... |
| CVE-2019-13481 | HIGH | 8.8 | 8.2% | Jul 10, 2019 | An issue was discovered on D-Link DIR-818LW devices with firmware 2.06betab01. There is a command injection in HNAP1 (ex... |
| CVE-2019-1873 | HIGH | 8.6 | 2.5% | Jul 10, 2019 | A vulnerability in the cryptographic driver for Cisco Adaptive Security Appliance Software (ASA) and Firepower Threat De... |
| CVE-2019-13071 | HIGH | 8.8 | 0.7% | Jul 10, 2019 | CSRF in the Agent/Center component of CyberPower PowerPanel Business Edition 3.4.0 allows an attacker to submit POST req... |
| CVE-2019-11020 | HIGH | 7.5 | 1.5% | Jul 9, 2019 | Lack of authentication in file-viewing components in DDRT Dashcom Live 2019-05-09 allows anyone to remotely access all c... |
| CVE-2019-11019 | HIGH | 7.5 | 1.5% | Jul 9, 2019 | Lack of authentication in case-exporting components in DDRT Dashcom Live through 2019-05-08 allows anyone to remotely ac... |
| CVE-2019-12747 | HIGH | 8.8 | 1.5% | Jul 9, 2019 | TYPO3 8.x through 8.7.26 and 9.x through 9.5.7 allows Deserialization of Untrusted Data. |
| CVE-2019-13370 | HIGH | 8.8 | 0.6% | Jul 6, 2019 | index.php/admin/permissions in Ignited CMS through 2017-02-19 allows CSRF to add an administrator. |
| CVE-2019-1894 | HIGH | 7.2 | 3.5% | Jul 6, 2019 | A vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker wi... |
| CVE-2019-1893 | HIGH | 7.8 | 0.6% | Jul 6, 2019 | A vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to ... |
| CVE-2019-1892 | HIGH | 7.5 | 1.8% | Jul 6, 2019 | A vulnerability in the Secure Sockets Layer (SSL) input packet processor of Cisco Small Business 200, 300, and 500 Serie... |
| CVE-2019-1891 | HIGH | 7.5 | 1.8% | Jul 6, 2019 | A vulnerability in the web interface of Cisco Small Business 200, 300, and 500 Series Managed Switches could allow an un... |
| CVE-2019-1887 | HIGH | 8.6 | 1.8% | Jul 6, 2019 | A vulnerability in the Session Initiation Protocol (SIP) protocol implementation of Cisco Unified Communications Manager... |
| CVE-2019-13358 | HIGH | 7.5 | 23.8% | Jul 5, 2019 | lib/DocumentToText.php in OpenCats before 0.9.4-3 has XXE that allows remote users to read files on the underlying opera... |
| CVE-2019-5984 | HIGH | 8.8 | 1.0% | Jul 5, 2019 | Cross-site request forgery (CSRF) vulnerability in Custom CSS Pro 1.0.3 and earlier allows remote attackers to hijack th... |
| CVE-2019-5983 | HIGH | 8.8 | 1.0% | Jul 5, 2019 | Cross-site request forgery (CSRF) vulnerability in HTML5 Maps 1.6.5.6 and earlier allows remote attackers to hijack the ... |
| CVE-2019-5980 | HIGH | 8.8 | 1.0% | Jul 5, 2019 | Cross-site request forgery (CSRF) vulnerability in Related YouTube Videos versions prior to 1.9.9 allows remote attacker... |
| CVE-2019-5979 | HIGH | 8.8 | 1.0% | Jul 5, 2019 | Cross-site request forgery (CSRF) vulnerability in Personalized WooCommerce Cart Page 2.4 and earlier allows remote atta... |
| CVE-2019-5973 | HIGH | 8.8 | 1.1% | Jul 5, 2019 | Cross-site request forgery (CSRF) vulnerability in Online Lesson Booking 0.8.6 and earlier allows remote attackers to hi... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now