2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-16523 | MEDIUM | 5.4 | 1.1% | Oct 16, 2019 | The events-manager plugin through 5.9.5 for WordPress (aka Events Manager) is susceptible to Stored XSS due to improper ... |
| CVE-2019-16522 | MEDIUM | 4.8 | 1.0% | Oct 16, 2019 | The eu-cookie-law plugin through 3.0.6 for WordPress (aka EU Cookie Law (GDPR)) is susceptible to Stored XSS due to impr... |
| CVE-2019-16521 | MEDIUM | 6.1 | 1.4% | Oct 16, 2019 | The broken-link-checker plugin through 1.11.8 for WordPress (aka Broken Link Checker) is susceptible to Reflected XSS du... |
| CVE-2019-17630 | MEDIUM | 4.8 | 0.5% | Oct 16, 2019 | CMS Made Simple (CMSMS) 2.2.11 allows stored XSS by an admin via a crafted image filename on the "News > Add Article" sc... |
| CVE-2019-17629 | MEDIUM | 4.8 | 0.5% | Oct 16, 2019 | CMS Made Simple (CMSMS) 2.2.11 allows stored XSS by an admin via a crafted image filename on the "file manager > upload ... |
| CVE-2019-16520 | MEDIUM | 5.4 | 1.5% | Oct 16, 2019 | The all-in-one-seo-pack plugin before 3.2.7 for WordPress (aka All in One SEO Pack) is susceptible to Stored XSS due to ... |
| CVE-2019-15893 | HIGH | 7.2 | 2.1% | Oct 16, 2019 | Sonatype Nexus Repository Manager 2.x before 2.14.15 allows Remote Code Execution. |
| CVE-2019-10458 | CRITICAL | 9.9 | 1.9% | Oct 16, 2019 | Jenkins Puppet Enterprise Pipeline 1.3.1 and earlier specifies unsafe values in its custom Script Security whitelist, al... |
| CVE-2019-10457 | MEDIUM | 4.3 | 0.6% | Oct 16, 2019 | A missing permission check in Jenkins Oracle Cloud Infrastructure Compute Classic Plugin allows attackers with Overall/R... |
| CVE-2019-10456 | MEDIUM | 4.3 | 0.6% | Oct 16, 2019 | A cross-site request forgery vulnerability in Jenkins Oracle Cloud Infrastructure Compute Classic Plugin allows attacker... |
| CVE-2019-10455 | MEDIUM | 4.3 | 0.6% | Oct 16, 2019 | A missing permission check in Jenkins Rundeck Plugin allows attackers with Overall/Read permission to connect to an atta... |
| CVE-2019-10454 | MEDIUM | 4.3 | 0.7% | Oct 16, 2019 | A cross-site request forgery vulnerability in Jenkins Rundeck Plugin allows attackers to connect to an attacker-specifie... |
| CVE-2019-10453 | HIGH | 7.8 | 0.3% | Oct 16, 2019 | Jenkins Delphix Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they ... |
| CVE-2019-10452 | MEDIUM | 4.3 | 0.5% | Oct 16, 2019 | Jenkins View26 Test-Reporting Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where ... |
| CVE-2019-10451 | MEDIUM | 4.3 | 0.5% | Oct 16, 2019 | Jenkins SOASTA CloudTest Plugin stores credentials unencrypted in its global configuration file on the Jenkins master wh... |
| CVE-2019-10450 | LOW | 3.3 | 0.2% | Oct 16, 2019 | Jenkins ElasticBox CI Plugin stores credentials unencrypted in the global config.xml configuration file on the Jenkins m... |
| CVE-2019-10449 | HIGH | 8.8 | 0.7% | Oct 16, 2019 | Jenkins Fortify on Demand Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they... |
| CVE-2019-10448 | HIGH | 8.8 | 0.9% | Oct 16, 2019 | Jenkins Extensive Testing Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they... |
| CVE-2019-10447 | MEDIUM | 4.3 | 0.5% | Oct 16, 2019 | Jenkins Sofy.AI Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be vi... |
| CVE-2019-10446 | HIGH | 8.2 | 1.0% | Oct 16, 2019 | Jenkins Cadence vManager Plugin 2.7.0 and earlier disabled SSL/TLS and hostname verification globally for the Jenkins ma... |
| CVE-2019-10445 | MEDIUM | 4.3 | 0.7% | Oct 16, 2019 | A missing permission check in Jenkins Google Kubernetes Engine Plugin 0.7.0 and earlier allowed attackers with Overall/R... |
| CVE-2019-10444 | MEDIUM | 6.5 | 0.8% | Oct 16, 2019 | Jenkins Bumblebee HP ALM Plugin 4.1.3 and earlier unconditionally disabled SSL/TLS and hostname verification for connect... |
| CVE-2019-10443 | HIGH | 8.8 | 1.6% | Oct 16, 2019 | Jenkins iceScrum Plugin 1.1.4 and earlier stored credentials unencrypted in job config.xml files on the Jenkins master w... |
| CVE-2019-10442 | MEDIUM | 4.3 | 0.7% | Oct 16, 2019 | A missing permission check in Jenkins iceScrum Plugin 1.1.5 and earlier allowed attackers with Overall/Read permission t... |
| CVE-2019-10441 | MEDIUM | 4.3 | 0.7% | Oct 16, 2019 | A cross-site request forgery vulnerability in Jenkins iceScrum Plugin 1.1.5 and earlier allowed attackers to connect to ... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now