2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2019-9621HIGH7.5Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x b...
CVE-2019-5624HIGH7.3Rapid7 Metasploit Framework suffers from an instance of CWE-22, Improper Limitation of a Pathname to a Restricted Direct...
CVE-2019-3399HIGH7.5The BrowseProjects.jspa resource in Jira before version 7.13.2, and from version 8.0.0 before version 8.0.2 allows remot...
CVE-2019-10318HIGH8.8Jenkins Azure AD Plugin 0.3.3 and earlier stored the client secret unencrypted in the global config.xml configuration fi...
CVE-2019-10316HIGH8.8Jenkins Aqua MicroScanner Plugin 1.0.5 and earlier stored credentials unencrypted in its global configuration file on th...
CVE-2019-10313HIGH8.8Jenkins Twitter Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they ...
CVE-2019-10311HIGH8.8A missing permission check in Jenkins Ansible Tower Plugin 0.9.1 and earlier in the TowerInstallation.TowerInstallationD...
CVE-2019-11599HIGH7The coredump implementation in the Linux kernel before 5.0.10 does not use locking or other mechanisms to prevent vma la...
CVE-2019-8454HIGH7A local attacker can create a hard-link between a file to which the Check Point Endpoint Security client for Windows bef...
CVE-2019-3560HIGH7.5An improperly performed length calculation on a buffer in PlaintextRecordLayer could lead to an infinite loop and denial...
CVE-2019-5429HIGH7.8Untrusted search path in FileZilla before 3.41.0-rc1 allows an attacker to gain privileges via a malicious 'fzsftp' bina...
CVE-2019-11591HIGH8.8The WebDorado Contact Form plugin before 1.13.5 for WordPress allows CSRF via the wp-admin/admin-ajax.php action paramet...
CVE-2019-11557HIGH8.8The WebDorado Contact Form Builder plugin before 1.0.69 for WordPress allows CSRF via the wp-admin/admin-ajax.php action...
CVE-2019-7476HIGH8.1A vulnerability in SonicWall Global Management System (GMS), allow a remote user to gain access to the appliance using e...
CVE-2019-3844HIGH7.8It was discovered that a systemd service that uses DynamicUser property can get new privileges through the execution of ...
CVE-2019-3843HIGH7.8It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allo...
CVE-2019-3707HIGH8.6Dell EMC iDRAC9 versions prior to 3.30.30.30 contain an authentication bypass vulnerability. A remote attacker may poten...
CVE-2019-3706HIGH8.6Dell EMC iDRAC9 versions prior to 3.24.24.24, 3.21.26.22, 3.22.22.22 and 3.21.25.22 contain an authentication bypass vul...
CVE-2019-9810HIGH8.8Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to missing bounds check ...
CVE-2019-11542HIGH7.2In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1R...
CVE-2019-11541HIGH7.5In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, and 8.2RX before 8.2R12.1, user...
CVE-2019-11539HIGH7.2In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1R...
CVE-2019-11538HIGH7.7In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1R...
CVE-2019-3788HIGH8.7Cloud Foundry UAA Release, versions prior to 71.0, allows clients to be configured with an insecure redirect uri. Given ...
CVE-2019-3721HIGH7.5Dell EMC Open Manage System Administrator (OMSA) versions prior to 9.3.0 contain an Improper Range Header Processing Vul...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now