2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-10422 | MEDIUM | 6.5 | 1.0% | Sep 25, 2019 | Jenkins Call Remote Job Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they c... |
| CVE-2019-10421 | MEDIUM | 4.3 | 0.8% | Sep 25, 2019 | Jenkins Azure Event Grid Build Notifier Plugin stores credentials unencrypted in job config.xml files on the Jenkins mas... |
| CVE-2019-10420 | MEDIUM | 5.5 | 0.3% | Sep 25, 2019 | Jenkins Assembla Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they... |
| CVE-2019-10419 | MEDIUM | 5.5 | 0.3% | Sep 25, 2019 | Jenkins vFabric Application Director Plugin stores credentials unencrypted in its global configuration file on the Jenki... |
| CVE-2019-10418 | CRITICAL | 9.9 | 1.2% | Sep 25, 2019 | Jenkins Kubernetes :: Pipeline :: Arquillian Steps Plugin provides a custom whitelist for script security that allowed a... |
| CVE-2019-10417 | CRITICAL | 9.9 | 1.2% | Sep 25, 2019 | Jenkins Kubernetes :: Pipeline :: Kubernetes Steps Plugin provides a custom whitelist for script security that allowed a... |
| CVE-2019-10416 | MEDIUM | 6.5 | 1.1% | Sep 25, 2019 | Jenkins Violation Comments to GitLab Plugin 2.28 and earlier stored credentials unencrypted in job config.xml files on t... |
| CVE-2019-10415 | MEDIUM | 6.5 | 1.1% | Sep 25, 2019 | Jenkins Violation Comments to GitLab Plugin 2.28 and earlier stored credentials unencrypted in its global configuration ... |
| CVE-2019-10414 | MEDIUM | 6.5 | 1.0% | Sep 25, 2019 | Jenkins Git Changelog Plugin 2.17 and earlier stored credentials unencrypted in job config.xml files on the Jenkins mast... |
| CVE-2019-10413 | MEDIUM | 6.5 | 1.0% | Sep 25, 2019 | Jenkins Data Theorem: CI/CD Plugin 1.3 and earlier stored credentials unencrypted in job config.xml files on the Jenkins... |
| CVE-2019-10412 | HIGH | 7.5 | 0.9% | Sep 25, 2019 | Jenkins Inedo ProGet Plugin 1.2 and earlier transmitted configured credentials in plain text as part of the global Jenki... |
| CVE-2019-10411 | HIGH | 7.5 | 0.9% | Sep 25, 2019 | Jenkins Inedo BuildMaster Plugin 2.4.0 and earlier transmitted configured credentials in plain text as part of the globa... |
| CVE-2019-10410 | MEDIUM | 5.4 | 0.9% | Sep 25, 2019 | Jenkins Log Parser Plugin 2.0 and earlier did not escape an error message, resulting in a cross-site scripting vulnerabi... |
| CVE-2019-10409 | MEDIUM | 4.3 | 0.6% | Sep 25, 2019 | A missing permission check in Jenkins Project Inheritance Plugin 2.0.0 and earlier allowed attackers with Overall/Read p... |
| CVE-2019-10408 | MEDIUM | 4.3 | 0.6% | Sep 25, 2019 | A cross-site request forgery vulnerability in Jenkins Project Inheritance Plugin 2.0.0 and earlier allowed attackers to ... |
| CVE-2019-10407 | MEDIUM | 6.5 | 1.2% | Sep 25, 2019 | Jenkins Project Inheritance Plugin 2.0.0 and earlier displayed a list of environment variables passed to a build without... |
| CVE-2019-10406 | MEDIUM | 4.8 | 1.0% | Sep 25, 2019 | Jenkins 2.196 and earlier, LTS 2.176.3 and earlier did not restrict or filter values set as Jenkins URL in the global co... |
| CVE-2019-10405 | MEDIUM | 5.4 | 65.8% | Sep 25, 2019 | Jenkins 2.196 and earlier, LTS 2.176.3 and earlier printed the value of the "Cookie" HTTP request header on the /whoAmI/... |
| CVE-2019-10404 | MEDIUM | 5.4 | 1.0% | Sep 25, 2019 | Jenkins 2.196 and earlier, LTS 2.176.3 and earlier did not escape the reason why a queue items is blcoked in tooltips, r... |
| CVE-2019-10403 | MEDIUM | 5.4 | 1.0% | Sep 25, 2019 | Jenkins 2.196 and earlier, LTS 2.176.3 and earlier did not escape the SCM tag name on the tooltip for SCM tag actions, r... |
| CVE-2019-10402 | MEDIUM | 5.4 | 1.0% | Sep 25, 2019 | In Jenkins 2.196 and earlier, LTS 2.176.3 and earlier, the f:combobox form control interpreted its item labels as HTML, ... |
| CVE-2019-10401 | MEDIUM | 5.4 | 1.0% | Sep 25, 2019 | In Jenkins 2.196 and earlier, LTS 2.176.3 and earlier, the f:expandableTextBox form control interpreted its content as H... |
| CVE-2019-13627 | MEDIUM | 6.3 | 0.5% | Sep 25, 2019 | It was discovered that there was a ECDSA timing attack in the libgcrypt20 cryptographic library. Version affected: 1.8.4... |
| CVE-2019-16868 | CRITICAL | 9.8 | 2.6% | Sep 25, 2019 | emlog through 6.0.0beta has an arbitrary file deletion vulnerability via an admin/data.php?action=dell_all_bak request w... |
| CVE-2019-16867 | MEDIUM | 6.5 | 1.1% | Sep 25, 2019 | HongCMS 3.0.0 allows arbitrary file deletion via a ../ in the file parameter to admin/index.php/database/ajax?action=del... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now