2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-15067 | CRITICAL | 9.8 | 1.9% | Sep 25, 2019 | An authentication bypass vulnerability discovered in Smart Battery A2-25DE, a multifunctional portable charger, firmware... |
| CVE-2019-12245 | MEDIUM | 5.3 | 1.4% | Sep 25, 2019 | SilverStripe through 4.3.3 has incorrect access control for protected files uploaded via Upload::loadIntoFile(). An atta... |
| CVE-2019-12205 | MEDIUM | 6.1 | 0.9% | Sep 25, 2019 | SilverStripe through 4.3.3 has Flash Clipboard Reflected XSS. |
| CVE-2019-12204 | CRITICAL | 9.8 | 1.5% | Sep 25, 2019 | In SilverStripe through 4.3.3, a missing warning about leaving install.php in a public webroot can lead to unauthenticat... |
| CVE-2019-12203 | MEDIUM | 6.3 | 0.4% | Sep 25, 2019 | SilverStripe through 4.3.3 allows session fixation in the "change password" form. |
| CVE-2019-6653 | MEDIUM | 5.4 | 0.6% | Sep 25, 2019 | There is a Stored Cross Site Scripting vulnerability in the undisclosed page of a BIG-IQ 6.0.0-6.1.0 or 5.2.0-5.4.0 syst... |
| CVE-2019-6652 | MEDIUM | 6.5 | 0.6% | Sep 25, 2019 | In BIG-IQ 6.0.0-6.1.0, services for stats do not require authentication nor do they implement any form of Transport Laye... |
| CVE-2019-6651 | MEDIUM | 5.3 | 1.1% | Sep 25, 2019 | In BIG-IP 15.0.0, 14.1.0-14.1.0.6, 14.0.0-14.0.0.5, 13.0.0-13.1.1.5, 12.1.0-12.1.4.1, 11.5.1-11.6.4, BIG-IQ 7.0.0, 6.0.0... |
| CVE-2019-16887 | HIGH | 7.8 | 1.9% | Sep 25, 2019 | In IrfanView 4.53, Data from a Faulting Address controls a subsequent Write Address starting at image00400000+0x00000000... |
| CVE-2019-16884 | HIGH | 7.5 | 4.4% | Sep 25, 2019 | runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass beca... |
| CVE-2019-16882 | HIGH | 7.5 | 1.5% | Sep 25, 2019 | An issue was discovered in the string-interner crate before 0.7.1 for Rust. It allows attackers to read from memory loca... |
| CVE-2019-16881 | CRITICAL | 9.8 | 2.5% | Sep 25, 2019 | An issue was discovered in the portaudio-rs crate through 0.3.1 for Rust. There is a use-after-free with resultant arbit... |
| CVE-2019-16880 | CRITICAL | 9.8 | 1.7% | Sep 25, 2019 | An issue was discovered in the linea crate through 0.9.4 for Rust. There is double free in the Matrix::zip_elements meth... |
| CVE-2019-16188 | HIGH | 7.1 | 0.8% | Sep 25, 2019 | HCL AppScan Source before 9.03.13 is susceptible to XML External Entity (XXE) attacks in multiple locations. In particul... |
| CVE-2019-10098 | MEDIUM | 6.1 | 74.0% | Sep 25, 2019 | In Apache HTTP server 2.4.0 to 2.4.39, Redirects configured with mod_rewrite that were intended to be self-referential m... |
| CVE-2019-16701 | HIGH | 8.8 | 19.6% | Sep 25, 2019 | pfSense through 2.3.4 through 2.4.4-p3 allows Remote Code Injection via a methodCall XML document with a pfsense.exec_ph... |
| CVE-2019-16194 | CRITICAL | 9.8 | 1.6% | Sep 25, 2019 | SQL injection vulnerabilities in Centreon through 19.04 allow attacks via the svc_id parameter in include/monitoring/sta... |
| CVE-2019-10430 | MEDIUM | 5.5 | 0.3% | Sep 25, 2019 | Jenkins NeuVector Vulnerability Scanner Plugin 1.5 and earlier stored credentials unencrypted in its global configuratio... |
| CVE-2019-10429 | MEDIUM | 5.5 | 0.3% | Sep 25, 2019 | Jenkins GitLab Logo Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where t... |
| CVE-2019-10428 | HIGH | 7.5 | 0.9% | Sep 25, 2019 | Jenkins Aqua Security Scanner Plugin 3.0.17 and earlier transmitted configured credentials in plain text as part of the ... |
| CVE-2019-10427 | MEDIUM | 5.3 | 0.8% | Sep 25, 2019 | Jenkins Aqua MicroScanner Plugin 1.0.7 and earlier transmitted configured credentials in plain text as part of the globa... |
| CVE-2019-10426 | MEDIUM | 5.5 | 0.3% | Sep 25, 2019 | Jenkins Gem Publisher Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where... |
| CVE-2019-10425 | MEDIUM | 6.5 | 1.0% | Sep 25, 2019 | Jenkins Google Calendar Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they c... |
| CVE-2019-10424 | MEDIUM | 5.5 | 0.3% | Sep 25, 2019 | Jenkins elOyente Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they... |
| CVE-2019-10423 | MEDIUM | 5.5 | 0.3% | Sep 25, 2019 | Jenkins CodeScan Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now