2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-9621 | HIGH | 7.5 | 80.9% | Apr 30, 2019 | Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x b... |
| CVE-2019-5624 | HIGH | 7.3 | 2.8% | Apr 30, 2019 | Rapid7 Metasploit Framework suffers from an instance of CWE-22, Improper Limitation of a Pathname to a Restricted Direct... |
| CVE-2019-3399 | HIGH | 7.5 | 2.1% | Apr 30, 2019 | The BrowseProjects.jspa resource in Jira before version 7.13.2, and from version 8.0.0 before version 8.0.2 allows remot... |
| CVE-2019-10318 | HIGH | 8.8 | 1.8% | Apr 30, 2019 | Jenkins Azure AD Plugin 0.3.3 and earlier stored the client secret unencrypted in the global config.xml configuration fi... |
| CVE-2019-10316 | HIGH | 8.8 | 1.8% | Apr 30, 2019 | Jenkins Aqua MicroScanner Plugin 1.0.5 and earlier stored credentials unencrypted in its global configuration file on th... |
| CVE-2019-10313 | HIGH | 8.8 | 1.8% | Apr 30, 2019 | Jenkins Twitter Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they ... |
| CVE-2019-10311 | HIGH | 8.8 | 1.8% | Apr 30, 2019 | A missing permission check in Jenkins Ansible Tower Plugin 0.9.1 and earlier in the TowerInstallation.TowerInstallationD... |
| CVE-2019-11599 | HIGH | 7 | 1.0% | Apr 29, 2019 | The coredump implementation in the Linux kernel before 5.0.10 does not use locking or other mechanisms to prevent vma la... |
| CVE-2019-8454 | HIGH | 7 | 0.3% | Apr 29, 2019 | A local attacker can create a hard-link between a file to which the Check Point Endpoint Security client for Windows bef... |
| CVE-2019-3560 | HIGH | 7.5 | 2.4% | Apr 29, 2019 | An improperly performed length calculation on a buffer in PlaintextRecordLayer could lead to an infinite loop and denial... |
| CVE-2019-5429 | HIGH | 7.8 | 2.5% | Apr 29, 2019 | Untrusted search path in FileZilla before 3.41.0-rc1 allows an attacker to gain privileges via a malicious 'fzsftp' bina... |
| CVE-2019-11591 | HIGH | 8.8 | 1.1% | Apr 29, 2019 | The WebDorado Contact Form plugin before 1.13.5 for WordPress allows CSRF via the wp-admin/admin-ajax.php action paramet... |
| CVE-2019-11557 | HIGH | 8.8 | 1.1% | Apr 26, 2019 | The WebDorado Contact Form Builder plugin before 1.0.69 for WordPress allows CSRF via the wp-admin/admin-ajax.php action... |
| CVE-2019-7476 | HIGH | 8.1 | 1.4% | Apr 26, 2019 | A vulnerability in SonicWall Global Management System (GMS), allow a remote user to gain access to the appliance using e... |
| CVE-2019-3844 | HIGH | 7.8 | 0.9% | Apr 26, 2019 | It was discovered that a systemd service that uses DynamicUser property can get new privileges through the execution of ... |
| CVE-2019-3843 | HIGH | 7.8 | 0.9% | Apr 26, 2019 | It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allo... |
| CVE-2019-3707 | HIGH | 8.6 | 3.3% | Apr 26, 2019 | Dell EMC iDRAC9 versions prior to 3.30.30.30 contain an authentication bypass vulnerability. A remote attacker may poten... |
| CVE-2019-3706 | HIGH | 8.6 | 3.3% | Apr 26, 2019 | Dell EMC iDRAC9 versions prior to 3.24.24.24, 3.21.26.22, 3.22.22.22 and 3.21.25.22 contain an authentication bypass vul... |
| CVE-2019-9810 | HIGH | 8.8 | 29.5% | Apr 26, 2019 | Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to missing bounds check ... |
| CVE-2019-11542 | HIGH | 7.2 | 66.6% | Apr 26, 2019 | In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1R... |
| CVE-2019-11541 | HIGH | 7.5 | 4.0% | Apr 26, 2019 | In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, and 8.2RX before 8.2R12.1, user... |
| CVE-2019-11539 | HIGH | 7.2 | 98.6% | Apr 26, 2019 | In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1R... |
| CVE-2019-11538 | HIGH | 7.7 | 7.4% | Apr 26, 2019 | In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1R... |
| CVE-2019-3788 | HIGH | 8.7 | 0.8% | Apr 25, 2019 | Cloud Foundry UAA Release, versions prior to 71.0, allows clients to be configured with an insecure redirect uri. Given ... |
| CVE-2019-3721 | HIGH | 7.5 | 2.6% | Apr 25, 2019 | Dell EMC Open Manage System Administrator (OMSA) versions prior to 9.3.0 contain an Improper Range Header Processing Vul... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now