2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-10473MEDIUM4.3A missing permission check in Jenkins Libvirt Slaves Plugin in form-related methods allowed users with Overall/Read acce...
CVE-2019-10472MEDIUM6.5A missing permission check in Jenkins Libvirt Slaves Plugin allows attackers with Overall/Read permission to connect to ...
CVE-2019-10471HIGH8.8A cross-site request forgery vulnerability in Jenkins Libvirt Slaves Plugin allows attackers to connect to an attacker-s...
CVE-2019-10470MEDIUM6.5A missing permission check in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin in form-related methods allowed users w...
CVE-2019-10469MEDIUM6.5A missing permission check in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin allows attackers with Overall/Read perm...
CVE-2019-10468HIGH8.8A cross-site request forgery vulnerability in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin allows attackers to con...
CVE-2019-10467MEDIUM6.5Jenkins Sonar Gerrit Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can ...
CVE-2019-10466HIGH8.1An XML external entities (XXE) vulnerability in Jenkins 360 FireLine Plugin allows attackers with Overall/Read access to...
CVE-2019-10465MEDIUM4.3A missing permission check in Jenkins Deploy WebLogic Plugin allows attackers with Overall/Read permission to connect to...
CVE-2019-10464HIGH8.8A cross-site request forgery vulnerability in Jenkins Deploy WebLogic Plugin allows attackers to connect to an attacker-...
CVE-2019-10463MEDIUM6.5A missing permission check in Jenkins Dynatrace Application Monitoring Plugin allows attackers with Overall/Read permiss...
CVE-2019-10462HIGH8.1A cross-site request forgery vulnerability in Jenkins Dynatrace Application Monitoring Plugin 2.1.3 and earlier allowed ...
CVE-2019-10461HIGH7.8Jenkins Dynatrace Application Monitoring Plugin 2.1.3 and earlier stored credentials unencrypted in its global configura...
CVE-2019-10460HIGH7.8Jenkins Bitbucket OAuth Plugin 0.9 and earlier stored credentials unencrypted in the global config.xml configuration fil...
CVE-2019-10459MEDIUM6.5Jenkins Mattermost Notification Plugin 2.7.0 and earlier stored webhook URLs containing a secret token unencrypted in it...
CVE-2019-14276MEDIUM6.5WUSTL XNAT 1.7.5.3 allows XXE attacks via a POST request body.
CVE-2019-16973MEDIUM6.1In FusionPBX up to 4.5.7, the file app\contacts\contact_edit.php uses an unsanitized "query_string" variable coming from...
CVE-2019-16972MEDIUM6.1In FusionPBX up to 4.5.7, the file app\contacts\contact_addresses.php uses an unsanitized "id" variable coming from the ...
CVE-2019-16971MEDIUM6.1In FusionPBX up to 4.5.7, the file app\messages\messages_thread.php uses an unsanitized "contact_uuid" variable coming f...
CVE-2019-8089MEDIUM6.1Adobe Experience Manager Forms versions 6.3-6.5 have a reflected cross-site scripting vulnerability. Successful exploita...
CVE-2019-15587MEDIUM5.4In the Loofah gem for Ruby through v2.3.0 unsanitized JavaScript may occur in sanitized output when a crafted SVG elemen...
CVE-2019-12290HIGH7.5GNU libidn2 before 2.2.0 fails to perform the roundtrip checks specified in RFC3490 Section 4.2 when converting A-labels...
CVE-2019-12148CRITICAL9.8The Sangoma Session Border Controller (SBC) 2.3.23-119 GA web interface is vulnerable to an authentication bypass via an...
CVE-2019-12147CRITICAL9.8The Sangoma Session Border Controller (SBC) 2.3.23-119 GA web interface is vulnerable to Argument Injection via special ...
CVE-2019-10079HIGH7.5Apache Traffic Server is vulnerable to HTTP/2 setting flood attacks. Earlier versions of Apache Traffic Server didn't li...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now