2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-16523MEDIUM5.4The events-manager plugin through 5.9.5 for WordPress (aka Events Manager) is susceptible to Stored XSS due to improper ...
CVE-2019-16522MEDIUM4.8The eu-cookie-law plugin through 3.0.6 for WordPress (aka EU Cookie Law (GDPR)) is susceptible to Stored XSS due to impr...
CVE-2019-16521MEDIUM6.1The broken-link-checker plugin through 1.11.8 for WordPress (aka Broken Link Checker) is susceptible to Reflected XSS du...
CVE-2019-17630MEDIUM4.8CMS Made Simple (CMSMS) 2.2.11 allows stored XSS by an admin via a crafted image filename on the "News > Add Article" sc...
CVE-2019-17629MEDIUM4.8CMS Made Simple (CMSMS) 2.2.11 allows stored XSS by an admin via a crafted image filename on the "file manager > upload ...
CVE-2019-16520MEDIUM5.4The all-in-one-seo-pack plugin before 3.2.7 for WordPress (aka All in One SEO Pack) is susceptible to Stored XSS due to ...
CVE-2019-15893HIGH7.2Sonatype Nexus Repository Manager 2.x before 2.14.15 allows Remote Code Execution.
CVE-2019-10458CRITICAL9.9Jenkins Puppet Enterprise Pipeline 1.3.1 and earlier specifies unsafe values in its custom Script Security whitelist, al...
CVE-2019-10457MEDIUM4.3A missing permission check in Jenkins Oracle Cloud Infrastructure Compute Classic Plugin allows attackers with Overall/R...
CVE-2019-10456MEDIUM4.3A cross-site request forgery vulnerability in Jenkins Oracle Cloud Infrastructure Compute Classic Plugin allows attacker...
CVE-2019-10455MEDIUM4.3A missing permission check in Jenkins Rundeck Plugin allows attackers with Overall/Read permission to connect to an atta...
CVE-2019-10454MEDIUM4.3A cross-site request forgery vulnerability in Jenkins Rundeck Plugin allows attackers to connect to an attacker-specifie...
CVE-2019-10453HIGH7.8Jenkins Delphix Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they ...
CVE-2019-10452MEDIUM4.3Jenkins View26 Test-Reporting Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where ...
CVE-2019-10451MEDIUM4.3Jenkins SOASTA CloudTest Plugin stores credentials unencrypted in its global configuration file on the Jenkins master wh...
CVE-2019-10450LOW3.3Jenkins ElasticBox CI Plugin stores credentials unencrypted in the global config.xml configuration file on the Jenkins m...
CVE-2019-10449HIGH8.8Jenkins Fortify on Demand Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they...
CVE-2019-10448HIGH8.8Jenkins Extensive Testing Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they...
CVE-2019-10447MEDIUM4.3Jenkins Sofy.AI Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be vi...
CVE-2019-10446HIGH8.2Jenkins Cadence vManager Plugin 2.7.0 and earlier disabled SSL/TLS and hostname verification globally for the Jenkins ma...
CVE-2019-10445MEDIUM4.3A missing permission check in Jenkins Google Kubernetes Engine Plugin 0.7.0 and earlier allowed attackers with Overall/R...
CVE-2019-10444MEDIUM6.5Jenkins Bumblebee HP ALM Plugin 4.1.3 and earlier unconditionally disabled SSL/TLS and hostname verification for connect...
CVE-2019-10443HIGH8.8Jenkins iceScrum Plugin 1.1.4 and earlier stored credentials unencrypted in job config.xml files on the Jenkins master w...
CVE-2019-10442MEDIUM4.3A missing permission check in Jenkins iceScrum Plugin 1.1.5 and earlier allowed attackers with Overall/Read permission t...
CVE-2019-10441MEDIUM4.3A cross-site request forgery vulnerability in Jenkins iceScrum Plugin 1.1.5 and earlier allowed attackers to connect to ...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now