2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-15067CRITICAL9.8An authentication bypass vulnerability discovered in Smart Battery A2-25DE, a multifunctional portable charger, firmware...
CVE-2019-12245MEDIUM5.3SilverStripe through 4.3.3 has incorrect access control for protected files uploaded via Upload::loadIntoFile(). An atta...
CVE-2019-12205MEDIUM6.1SilverStripe through 4.3.3 has Flash Clipboard Reflected XSS.
CVE-2019-12204CRITICAL9.8In SilverStripe through 4.3.3, a missing warning about leaving install.php in a public webroot can lead to unauthenticat...
CVE-2019-12203MEDIUM6.3SilverStripe through 4.3.3 allows session fixation in the "change password" form.
CVE-2019-6653MEDIUM5.4There is a Stored Cross Site Scripting vulnerability in the undisclosed page of a BIG-IQ 6.0.0-6.1.0 or 5.2.0-5.4.0 syst...
CVE-2019-6652MEDIUM6.5In BIG-IQ 6.0.0-6.1.0, services for stats do not require authentication nor do they implement any form of Transport Laye...
CVE-2019-6651MEDIUM5.3In BIG-IP 15.0.0, 14.1.0-14.1.0.6, 14.0.0-14.0.0.5, 13.0.0-13.1.1.5, 12.1.0-12.1.4.1, 11.5.1-11.6.4, BIG-IQ 7.0.0, 6.0.0...
CVE-2019-16887HIGH7.8In IrfanView 4.53, Data from a Faulting Address controls a subsequent Write Address starting at image00400000+0x00000000...
CVE-2019-16884HIGH7.5runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass beca...
CVE-2019-16882HIGH7.5An issue was discovered in the string-interner crate before 0.7.1 for Rust. It allows attackers to read from memory loca...
CVE-2019-16881CRITICAL9.8An issue was discovered in the portaudio-rs crate through 0.3.1 for Rust. There is a use-after-free with resultant arbit...
CVE-2019-16880CRITICAL9.8An issue was discovered in the linea crate through 0.9.4 for Rust. There is double free in the Matrix::zip_elements meth...
CVE-2019-16188HIGH7.1HCL AppScan Source before 9.03.13 is susceptible to XML External Entity (XXE) attacks in multiple locations. In particul...
CVE-2019-10098MEDIUM6.1In Apache HTTP server 2.4.0 to 2.4.39, Redirects configured with mod_rewrite that were intended to be self-referential m...
CVE-2019-16701HIGH8.8pfSense through 2.3.4 through 2.4.4-p3 allows Remote Code Injection via a methodCall XML document with a pfsense.exec_ph...
CVE-2019-16194CRITICAL9.8SQL injection vulnerabilities in Centreon through 19.04 allow attacks via the svc_id parameter in include/monitoring/sta...
CVE-2019-10430MEDIUM5.5Jenkins NeuVector Vulnerability Scanner Plugin 1.5 and earlier stored credentials unencrypted in its global configuratio...
CVE-2019-10429MEDIUM5.5Jenkins GitLab Logo Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where t...
CVE-2019-10428HIGH7.5Jenkins Aqua Security Scanner Plugin 3.0.17 and earlier transmitted configured credentials in plain text as part of the ...
CVE-2019-10427MEDIUM5.3Jenkins Aqua MicroScanner Plugin 1.0.7 and earlier transmitted configured credentials in plain text as part of the globa...
CVE-2019-10426MEDIUM5.5Jenkins Gem Publisher Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where...
CVE-2019-10425MEDIUM6.5Jenkins Google Calendar Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they c...
CVE-2019-10424MEDIUM5.5Jenkins elOyente Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they...
CVE-2019-10423MEDIUM5.5Jenkins CodeScan Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now