2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-10440 | HIGH | 8.8 | 1.5% | Oct 16, 2019 | Jenkins NeoLoad Plugin 2.2.5 and earlier stored credentials unencrypted in its global configuration file and in job conf... |
| CVE-2019-10439 | MEDIUM | 4.3 | 0.7% | Oct 16, 2019 | A missing permission check in Jenkins CRX Content Package Deployer Plugin 1.8.1 and earlier in various 'doFillCredential... |
| CVE-2019-10438 | MEDIUM | 6.5 | 1.0% | Oct 16, 2019 | A missing permission check in Jenkins CRX Content Package Deployer Plugin 1.8.1 and earlier allowed attackers with Overa... |
| CVE-2019-10437 | HIGH | 8.8 | 0.8% | Oct 16, 2019 | A cross-site request forgery vulnerability in Jenkins CRX Content Package Deployer Plugin 1.8.1 and earlier allowed atta... |
| CVE-2019-10436 | MEDIUM | 6.5 | 1.0% | Oct 16, 2019 | An arbitrary file read vulnerability in Jenkins Google OAuth Credentials Plugin 0.9 and earlier allowed attackers able t... |
| CVE-2019-4031 | HIGH | 7.8 | 0.3% | Oct 16, 2019 | IBM Workload Scheduler Distributed 9.2, 9.3, 9.4, and 9.5 contains a vulnerability that could allow a local user to writ... |
| CVE-2019-17627 | MEDIUM | 6.5 | 0.7% | Oct 16, 2019 | The Yale Bluetooth Key application for mobile devices allows unauthorized unlock actions by sniffing Bluetooth Low Energ... |
| CVE-2019-17626 | CRITICAL | 9.8 | 10.2% | Oct 16, 2019 | ReportLab through 3.5.26 allows remote code execution because of toColor(eval(arg)) in colors.py, as demonstrated by a c... |
| CVE-2019-17625 | CRITICAL | 9 | 3.0% | Oct 16, 2019 | There is a stored XSS in Rambox 0.6.9 that can lead to code execution. The XSS is in the name field while adding/editing... |
| CVE-2019-17624 | HIGH | 7.8 | 3.7% | Oct 16, 2019 | "" In X.Org X Server 1.20.4, there is a stack-based buffer overflow in the function XQueryKeymap. For example, by sendin... |
| CVE-2019-13392 | MEDIUM | 6.1 | 3.9% | Oct 16, 2019 | A reflected Cross-Site Scripting (XSS) vulnerability in MindPalette NateMail 3.0.15 allows an attacker to execute remote... |
| CVE-2019-17613 | CRITICAL | 9.8 | 2.9% | Oct 15, 2019 | qibosoft 7 allows remote code execution because do/jf.php makes eval calls. The attacker can use the Point Introduction ... |
| CVE-2019-17612 | HIGH | 7.2 | 1.0% | Oct 15, 2019 | An issue was discovered in 74CMS v5.2.8. There is a SQL Injection generated by the _list method in the Common/Controller... |
| CVE-2019-17395 | CRITICAL | 9.8 | 1.3% | Oct 15, 2019 | In the Rapid Gator application 0.7.1 for Android, the username and password are stored in the log during authentication,... |
| CVE-2019-17602 | CRITICAL | 9.8 | 81.5% | Oct 15, 2019 | An issue was discovered in Zoho ManageEngine OpManager before 12.4 build 124089. The OPMDeviceDetailsServlet servlet is ... |
| CVE-2019-17601 | CRITICAL | 9.8 | 2.8% | Oct 15, 2019 | In MiniShare 1.4.1, there is a stack-based buffer overflow via an HTTP CONNECT request, which allows an attacker to achi... |
| CVE-2019-17398 | CRITICAL | 9.8 | 1.3% | Oct 15, 2019 | In the Dark Horse Comics application 1.3.21 for Android, token information (equivalent to the username and password) is ... |
| CVE-2019-17396 | CRITICAL | 9.8 | 1.2% | Oct 15, 2019 | In the PowerSchool Mobile application 1.1.8 for Android, the username and password are stored in the log during authenti... |
| CVE-2019-17394 | CRITICAL | 9.8 | 1.3% | Oct 15, 2019 | In the Seesaw Parent and Family application 6.2.5 for Android, the username and password are stored in the log during au... |
| CVE-2019-17356 | MEDIUM | 6.5 | 0.4% | Oct 15, 2019 | The Infinite Design application 3.4.12 for Android sends a username and password via TCP without any encryption during l... |
| CVE-2019-17355 | CRITICAL | 9.8 | 1.3% | Oct 15, 2019 | In the Orbitz application 19.31.1 for Android, the username and password are stored in the log during authentication, an... |
| CVE-2019-14832 | HIGH | 7.5 | 0.5% | Oct 15, 2019 | A flaw was found in the Keycloak REST API before version 8.0.0 where it would permit user access from a realm the user w... |
| CVE-2019-17397 | CRITICAL | 9.8 | 1.3% | Oct 15, 2019 | In the DoorDash application through 11.5.2 for Android, the username and password are stored in the log during authentic... |
| CVE-2019-10760 | CRITICAL | 9.9 | 2.9% | Oct 15, 2019 | safer-eval before 1.3.2 are vulnerable to Arbitrary Code Execution. A payload using constructor properties can escape th... |
| CVE-2019-10759 | CRITICAL | 9.9 | 1.8% | Oct 15, 2019 | safer-eval before 1.3.4 are vulnerable to Arbitrary Code Execution. A payload using constructor properties can escape th... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now