2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-10473 | MEDIUM | 4.3 | 0.7% | Oct 23, 2019 | A missing permission check in Jenkins Libvirt Slaves Plugin in form-related methods allowed users with Overall/Read acce... |
| CVE-2019-10472 | MEDIUM | 6.5 | 0.8% | Oct 23, 2019 | A missing permission check in Jenkins Libvirt Slaves Plugin allows attackers with Overall/Read permission to connect to ... |
| CVE-2019-10471 | HIGH | 8.8 | 0.7% | Oct 23, 2019 | A cross-site request forgery vulnerability in Jenkins Libvirt Slaves Plugin allows attackers to connect to an attacker-s... |
| CVE-2019-10470 | MEDIUM | 6.5 | 0.8% | Oct 23, 2019 | A missing permission check in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin in form-related methods allowed users w... |
| CVE-2019-10469 | MEDIUM | 6.5 | 0.8% | Oct 23, 2019 | A missing permission check in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin allows attackers with Overall/Read perm... |
| CVE-2019-10468 | HIGH | 8.8 | 0.7% | Oct 23, 2019 | A cross-site request forgery vulnerability in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin allows attackers to con... |
| CVE-2019-10467 | MEDIUM | 6.5 | 0.9% | Oct 23, 2019 | Jenkins Sonar Gerrit Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can ... |
| CVE-2019-10466 | HIGH | 8.1 | 1.0% | Oct 23, 2019 | An XML external entities (XXE) vulnerability in Jenkins 360 FireLine Plugin allows attackers with Overall/Read access to... |
| CVE-2019-10465 | MEDIUM | 4.3 | 0.8% | Oct 23, 2019 | A missing permission check in Jenkins Deploy WebLogic Plugin allows attackers with Overall/Read permission to connect to... |
| CVE-2019-10464 | HIGH | 8.8 | 0.8% | Oct 23, 2019 | A cross-site request forgery vulnerability in Jenkins Deploy WebLogic Plugin allows attackers to connect to an attacker-... |
| CVE-2019-10463 | MEDIUM | 6.5 | 0.8% | Oct 23, 2019 | A missing permission check in Jenkins Dynatrace Application Monitoring Plugin allows attackers with Overall/Read permiss... |
| CVE-2019-10462 | HIGH | 8.1 | 0.7% | Oct 23, 2019 | A cross-site request forgery vulnerability in Jenkins Dynatrace Application Monitoring Plugin 2.1.3 and earlier allowed ... |
| CVE-2019-10461 | HIGH | 7.8 | 0.3% | Oct 23, 2019 | Jenkins Dynatrace Application Monitoring Plugin 2.1.3 and earlier stored credentials unencrypted in its global configura... |
| CVE-2019-10460 | HIGH | 7.8 | 0.3% | Oct 23, 2019 | Jenkins Bitbucket OAuth Plugin 0.9 and earlier stored credentials unencrypted in the global config.xml configuration fil... |
| CVE-2019-10459 | MEDIUM | 6.5 | 0.9% | Oct 23, 2019 | Jenkins Mattermost Notification Plugin 2.7.0 and earlier stored webhook URLs containing a secret token unencrypted in it... |
| CVE-2019-14276 | MEDIUM | 6.5 | 1.0% | Oct 23, 2019 | WUSTL XNAT 1.7.5.3 allows XXE attacks via a POST request body. |
| CVE-2019-16973 | MEDIUM | 6.1 | 0.8% | Oct 22, 2019 | In FusionPBX up to 4.5.7, the file app\contacts\contact_edit.php uses an unsanitized "query_string" variable coming from... |
| CVE-2019-16972 | MEDIUM | 6.1 | 0.8% | Oct 22, 2019 | In FusionPBX up to 4.5.7, the file app\contacts\contact_addresses.php uses an unsanitized "id" variable coming from the ... |
| CVE-2019-16971 | MEDIUM | 6.1 | 0.8% | Oct 22, 2019 | In FusionPBX up to 4.5.7, the file app\messages\messages_thread.php uses an unsanitized "contact_uuid" variable coming f... |
| CVE-2019-8089 | MEDIUM | 6.1 | 1.5% | Oct 22, 2019 | Adobe Experience Manager Forms versions 6.3-6.5 have a reflected cross-site scripting vulnerability. Successful exploita... |
| CVE-2019-15587 | MEDIUM | 5.4 | 1.4% | Oct 22, 2019 | In the Loofah gem for Ruby through v2.3.0 unsanitized JavaScript may occur in sanitized output when a crafted SVG elemen... |
| CVE-2019-12290 | HIGH | 7.5 | 2.8% | Oct 22, 2019 | GNU libidn2 before 2.2.0 fails to perform the roundtrip checks specified in RFC3490 Section 4.2 when converting A-labels... |
| CVE-2019-12148 | CRITICAL | 9.8 | 3.5% | Oct 22, 2019 | The Sangoma Session Border Controller (SBC) 2.3.23-119 GA web interface is vulnerable to an authentication bypass via an... |
| CVE-2019-12147 | CRITICAL | 9.8 | 2.6% | Oct 22, 2019 | The Sangoma Session Border Controller (SBC) 2.3.23-119 GA web interface is vulnerable to Argument Injection via special ... |
| CVE-2019-10079 | HIGH | 7.5 | 4.6% | Oct 22, 2019 | Apache Traffic Server is vulnerable to HTTP/2 setting flood attacks. Earlier versions of Apache Traffic Server didn't li... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now