2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-1003093MEDIUM6.5A missing permission check in Jenkins Nomad Plugin in the NomadCloud.DescriptorImpl#doTestConnection form validation met...
CVE-2019-1003091MEDIUM6.5A missing permission check in Jenkins SOASTA CloudTest Plugin in the CloudTestServer.DescriptorImpl#doValidate form vali...
CVE-2019-1003089MEDIUM6.5Jenkins Upload to pgyer Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they c...
CVE-2019-1003088MEDIUM6.5Jenkins Fabric Beta Publisher Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where ...
CVE-2019-1003087MEDIUM6.5A missing permission check in Jenkins Chef Sinatra Plugin in the ChefBuilderConfiguration.DescriptorImpl#doTestConnectio...
CVE-2019-1003085MEDIUM6.5A missing permission check in Jenkins Zephyr Enterprise Test Management Plugin in the ZeeDescriptor#doTestConnection for...
CVE-2019-1003083MEDIUM6.5A missing permission check in Jenkins Gearman Plugin in the GearmanPluginConfig#doTestConnection form validation method ...
CVE-2019-1003081MEDIUM6.5A missing permission check in Jenkins OpenShift Deployer Plugin in the DeployApplication.DeployApplicationDescriptor#doC...
CVE-2019-1003079MEDIUM6.5A missing permission check in Jenkins VMware Lab Manager Slaves Plugin in the LabManager.DescriptorImpl#doTestConnection...
CVE-2019-1003077MEDIUM6.5A missing permission check in Jenkins Audit to Database Plugin in the DbAuditPublisherDescriptorImpl#doTestJdbcConnectio...
CVE-2019-1003059MEDIUM6.5A missing permission check in Jenkins FTP publisher Plugin in the FTPPublisher.DescriptorImpl#doLoginCheck method allows...
CVE-2019-10714MEDIUM6.5LocaleLowercase in MagickCore/locale.c in ImageMagick before 7.0.8-32 allows out-of-bounds access, leading to a SIGSEGV.
CVE-2019-7474MEDIUM6.5A vulnerability in SonicWall SonicOS and SonicOSv, allow authenticated read-only admin to leave the firewall in an unsta...
CVE-2019-4093MEDIUM4.4IBM Tivoli Storage Manager (IBM Spectrum Protect 8.1.7) could allow a user to restore files and directories using IBM Sp...
CVE-2019-4080MEDIUM6.5IBM WebSphere Application Server Admin Console 7.5, 8.0, 8.5, and 9.0 is vulnerable to a potential denial of service, ca...
CVE-2019-3792MEDIUM6.8Pivotal Concourse version 5.0.0, contains an API that is vulnerable to SQL injection. An Concourse resource can craft a ...
CVE-2019-5888MEDIUM6.1Multiple XSS vulnerabilities were discovered in OverIT Geocall 6.3 before build 2:346977.
CVE-2019-3876MEDIUM6.3A flaw was found in the /oauth/token/request custom endpoint of the OpenShift OAuth server allowing for XSS generation o...
CVE-2019-3836MEDIUM5.9It was discovered in gnutls before version 3.6.7 upstream that there is an uninitialized pointer access in gnutls versio...
CVE-2019-1002101MEDIUM6.4The kubectl cp command allows copying files between containers and the user machine. To copy files from a container, Kub...
CVE-2019-1002100MEDIUM6.5In all Kubernetes versions prior to v1.11.8, v1.12.6, and v1.13.4, users that are authorized to make patch requests to t...
CVE-2019-10657MEDIUM6.5Grandstream GWN7000 before 1.0.6.32 and GWN7610 before 1.0.8.18 devices allow remote authenticated users to discover pas...
CVE-2019-10649MEDIUM5.5In ImageMagick 7.0.8-36 Q16, there is a memory leak in the function SVGKeyValuePairs of coders/svg.c, which allows an at...
CVE-2019-9921MEDIUM6.5An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. It is possible to read information that ...
CVE-2019-9919MEDIUM5.4An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. It is possible to craft messages in a wa...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now