2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-11025 | MEDIUM | 5.4 | 1.3% | Apr 8, 2019 | In clearFilter() in utilities.php in Cacti before 1.2.3, no escaping occurs before printing out the value of the SNMP co... |
| CVE-2019-1798 | MEDIUM | 5.5 | 1.1% | Apr 8, 2019 | A vulnerability in the Portable Executable (PE) file scanning functionality of Clam AntiVirus (ClamAV) Software versions... |
| CVE-2019-1788 | MEDIUM | 5.5 | 1.8% | Apr 8, 2019 | A vulnerability in the Object Linking & Embedding (OLE2) file scanning functionality of Clam AntiVirus (ClamAV) Software... |
| CVE-2019-1787 | MEDIUM | 5.5 | 1.7% | Apr 8, 2019 | A vulnerability in the Portable Document Format (PDF) scanning functionality of Clam AntiVirus (ClamAV) Software version... |
| CVE-2019-1786 | MEDIUM | 5.5 | 1.5% | Apr 8, 2019 | A vulnerability in the Portable Document Format (PDF) scanning functionality of Clam AntiVirus (ClamAV) Software version... |
| CVE-2019-4143 | MEDIUM | 5.5 | 0.4% | Apr 8, 2019 | The IBM Cloud Private Key Management Service (IBM Cloud Private 3.1.1 and 3.1.2) could allow a local user to obtain sens... |
| CVE-2019-4051 | MEDIUM | 5.3 | 1.7% | Apr 8, 2019 | Some URIs in IBM API Connect 2018.1 and 2018.4.1.3 disclose system specification information like the machine id, system... |
| CVE-2019-4045 | MEDIUM | 4.3 | 0.9% | Apr 8, 2019 | IBM Business Automation Workflow and IBM Business Process Manager 18.0.0.0, 18.0.0.1, and 18.0.0.2 provide embedded docu... |
| CVE-2019-10741 | MEDIUM | 4.3 | 0.9% | Apr 7, 2019 | K-9 Mail v5.600 can include the original quoted HTML code of a specially crafted, benign looking, email within (digitall... |
| CVE-2019-10740 | MEDIUM | 4.3 | 0.8% | Apr 7, 2019 | In Roundcube Webmail before 1.3.10, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-par... |
| CVE-2019-10732 | MEDIUM | 4.3 | 0.6% | Apr 7, 2019 | In KDE KMail 5.2.3, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a craf... |
| CVE-2019-10887 | MEDIUM | 6.1 | 5.8% | Apr 5, 2019 | A reflected HTML injection vulnerability on Salicru SLC-20-cube3(5) devices running firmware version cs121-SNMP v4.54.82... |
| CVE-2019-10875 | MEDIUM | 6.5 | 2.2% | Apr 5, 2019 | A URL spoofing vulnerability was found in all international versions of Xiaomi Mi browser 10.5.6-g (aka the MIUI native ... |
| CVE-2019-10868 | MEDIUM | 6.5 | 1.3% | Apr 5, 2019 | In trytond/model/modelstorage.py in Tryton 4.2 before 4.2.21, 4.4 before 4.4.19, 4.6 before 4.6.14, 4.8 before 4.8.10, a... |
| CVE-2019-3886 | MEDIUM | 5.4 | 1.1% | Apr 4, 2019 | An incorrect permissions check was discovered in libvirt 4.8.0 and above. The readonly permission was allowed to invoke ... |
| CVE-2019-1828 | MEDIUM | 5.9 | 0.7% | Apr 4, 2019 | A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Route... |
| CVE-2019-1827 | MEDIUM | 6.1 | 1.3% | Apr 4, 2019 | A vulnerability in the Online Help web service of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers coul... |
| CVE-2019-10293 | MEDIUM | 6.5 | 1.5% | Apr 4, 2019 | A missing permission check in Jenkins Kmap Plugin in KmapJenkinsBuilder.DescriptorImpl form validation methods allows at... |
| CVE-2019-10290 | MEDIUM | 6.5 | 1.5% | Apr 4, 2019 | A missing permission check in Jenkins Netsparker Cloud Scan Plugin 1.1.5 and older in the NCScanBuilder.DescriptorImpl#d... |
| CVE-2019-10279 | MEDIUM | 6.5 | 1.5% | Apr 4, 2019 | A missing permission check in Jenkins jenkins-reviewbot Plugin in the ReviewboardDescriptor#doTestConnection form valida... |
| CVE-2019-1003099 | MEDIUM | 6.5 | 1.5% | Apr 4, 2019 | A missing permission check in Jenkins openid Plugin in the OpenIdSsoSecurityRealm.DescriptorImpl#doValidate form validat... |
| CVE-2019-1003097 | MEDIUM | 6.5 | 1.6% | Apr 4, 2019 | Jenkins Crowd Integration Plugin stores credentials unencrypted in the global config.xml configuration file on the Jenki... |
| CVE-2019-1003096 | MEDIUM | 6.5 | 1.7% | Apr 4, 2019 | Jenkins TestFairy Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be ... |
| CVE-2019-1003095 | MEDIUM | 6.5 | 1.2% | Apr 4, 2019 | Jenkins Perfecto Mobile Plugin stores credentials unencrypted in its global configuration file on the Jenkins master whe... |
| CVE-2019-1003094 | MEDIUM | 6.5 | 1.2% | Apr 4, 2019 | Jenkins Open STF Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now