2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-16569 | MEDIUM | 4.3 | 0.7% | Dec 17, 2019 | A cross-site request forgery vulnerability in Jenkins Mantis Plugin 0.26 and earlier allows attackers to connect to an a... |
| CVE-2019-16568 | MEDIUM | 5.3 | 0.6% | Dec 17, 2019 | Jenkins SCTMExecutor Plugin 2.2 and earlier transmits previously configured service credentials in plain text as part of... |
| CVE-2019-16567 | MEDIUM | 4.3 | 0.6% | Dec 17, 2019 | A missing permission check in Jenkins Team Concert Plugin 1.3.0 and earlier in form-related methods allowed users with O... |
| CVE-2019-16566 | MEDIUM | 6.5 | 0.8% | Dec 17, 2019 | A missing permission check in Jenkins Team Concert Plugin 1.3.0 and earlier allows attackers with Overall/Read permissio... |
| CVE-2019-16565 | HIGH | 8.8 | 0.6% | Dec 17, 2019 | A cross-site request forgery vulnerability in Jenkins Team Concert Plugin 1.3.0 and earlier allows attackers to connect ... |
| CVE-2019-16564 | MEDIUM | 5.4 | 0.7% | Dec 17, 2019 | Jenkins Pipeline Aggregator View Plugin 1.8 and earlier does not escape information shown on its view, resulting in a st... |
| CVE-2019-16563 | MEDIUM | 5.4 | 0.7% | Dec 17, 2019 | Jenkins Mission Control Plugin 0.9.16 and earlier does not escape job display names and build names shown on its view, r... |
| CVE-2019-16562 | MEDIUM | 5.4 | 0.7% | Dec 17, 2019 | Jenkins buildgraph-view Plugin 1.8 and earlier does not escape the description of builds shown in its view, resulting in... |
| CVE-2019-16561 | HIGH | 7.1 | 0.5% | Dec 17, 2019 | Jenkins WebSphere Deployer Plugin 1.6.1 and earlier allows users with Overall/Read access to disable SSL/TLS certificate... |
| CVE-2019-16560 | HIGH | 8.8 | 0.7% | Dec 17, 2019 | A cross-site request forgery vulnerability in Jenkins WebSphere Deployer Plugin 1.6.1 and earlier allows attackers to pe... |
| CVE-2019-16559 | MEDIUM | 5.4 | 0.7% | Dec 17, 2019 | A missing permission check in Jenkins WebSphere Deployer Plugin 1.6.1 and earlier allows attackers with Overall/Read per... |
| CVE-2019-16558 | HIGH | 8.2 | 0.6% | Dec 17, 2019 | Jenkins Spira Importer Plugin 3.2.3 and earlier disables SSL/TLS certificate validation for the Jenkins master JVM. |
| CVE-2019-16557 | MEDIUM | 6.5 | 0.9% | Dec 17, 2019 | Jenkins Redgate SQL Change Automation Plugin 2.0.3 and earlier stores credentials unencrypted in job config.xml files on... |
| CVE-2019-16556 | MEDIUM | 6.5 | 0.9% | Dec 17, 2019 | Jenkins Rundeck Plugin 3.6.5 and earlier stores credentials unencrypted in its global configuration file and in job conf... |
| CVE-2019-16555 | MEDIUM | 6.5 | 1.1% | Dec 17, 2019 | A user-supplied regular expression in Jenkins Build Failure Analyzer Plugin 1.24.1 and earlier was processed in a way th... |
| CVE-2019-16554 | MEDIUM | 4.3 | 0.8% | Dec 17, 2019 | A missing permission check in Jenkins Build Failure Analyzer Plugin 1.24.1 and earlier allows attackers with Overall/Rea... |
| CVE-2019-16553 | HIGH | 8.8 | 0.7% | Dec 17, 2019 | A cross-site request forgery vulnerability in Jenkins Build Failure Analyzer Plugin 1.24.1 and earlier allows attackers ... |
| CVE-2019-16552 | MEDIUM | 5.4 | 0.6% | Dec 17, 2019 | A missing permission check in Jenkins Gerrit Trigger Plugin 2.30.1 and earlier allows attackers with Overall/Read permis... |
| CVE-2019-16551 | HIGH | 8.8 | 0.7% | Dec 17, 2019 | A cross-site request forgery vulnerability in Jenkins Gerrit Trigger Plugin 2.30.1 and earlier allows attackers to conne... |
| CVE-2019-16550 | HIGH | 8.8 | 0.6% | Dec 17, 2019 | A cross-site request forgery vulnerability in a connection test form method in Jenkins Maven Release Plugin 0.16.1 and e... |
| CVE-2019-16549 | HIGH | 8.1 | 1.0% | Dec 17, 2019 | Jenkins Maven Release Plugin 0.16.1 and earlier does not configure the XML parser to prevent XML external entity (XXE) a... |
| CVE-2019-19712 | MEDIUM | 5.3 | 0.9% | Dec 17, 2019 | Contao 4.0 through 4.8.5 has Insecure Permissions. Back end users can manipulate the details view URL to show pages and ... |
| CVE-2019-19264 | HIGH | 7.5 | 1.7% | Dec 17, 2019 | In Simplifile RecordFusion through 2019-11-25, the logs and hist parameters allow remote attackers to access local files... |
| CVE-2019-18833 | MEDIUM | 5.9 | 0.4% | Dec 17, 2019 | Barco ClickShare Button R9861500D01 devices before 1.9.0 allow Information exposure (issue 2 of 2).. The encryption key ... |
| CVE-2019-18832 | HIGH | 8.1 | 0.4% | Dec 17, 2019 | Barco ClickShare Button R9861500D01 devices before 1.9.0 have incorrect Credentials Management. The ClickShare Button im... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now