2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-3638CRITICAL9.6Reflected Cross Site Scripting vulnerability in Administrators web console in McAfee Web Gateway (MWG) 7.8.x prior to 7....
CVE-2019-16238MEDIUM6.1Afterlogic Aurora through 8.3.9-build-a3 has XSS that can be leveraged for session hijacking by retrieving the session c...
CVE-2019-16261CRITICAL9.1Tripp Lite PDUMH15AT 12.04.0053 and SU750XL 12.04.0052 devices allow unauthenticated POST requests to the /Forms/ direct...
CVE-2019-10400MEDIUM4.2A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.62 and earlier related to the handling of subexpressi...
CVE-2019-10399MEDIUM4.2A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.62 and earlier related to the handling of property na...
CVE-2019-10398MEDIUM5.5Jenkins Beaker Builder Plugin 1.9 and earlier stored credentials unencrypted in its global configuration file on the Jen...
CVE-2019-10397LOW3.1Jenkins Aqua Security Serverless Scanner Plugin 1.0.4 and earlier transmitted configured passwords in plain text as part...
CVE-2019-10396MEDIUM5.4Jenkins Dashboard View Plugin 2.11 and earlier did not escape build descriptions, resulting in a cross-site scripting vu...
CVE-2019-10395MEDIUM5.4Jenkins Build Environment Plugin 1.6 and earlier did not escape variables shown on its views, resulting in a cross-site ...
CVE-2019-10394MEDIUM4.2A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.62 and earlier related to the handling of property na...
CVE-2019-10393MEDIUM4.2A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.62 and earlier related to the handling of method name...
CVE-2019-10392HIGH8.8Jenkins Git Client Plugin 2.8.4 and earlier and 3.0.0-rc did not properly restrict values passed as URL argument to an i...
CVE-2019-16257CRITICAL9.8Some Motorola devices include the SIMalliance Toolbox Browser (aka S@T Browser) on the UICC, which might allow remote at...
CVE-2019-16256CRITICAL9.8Some Samsung devices include the SIMalliance Toolbox Browser (aka S@T Browser) on the UICC, which might allow remote att...
CVE-2019-16250HIGH7.5includes/wizard/wizard.php in the Ocean Extra plugin through 1.5.8 for WordPress allows unauthenticated options changes ...
CVE-2019-16249MEDIUM5.3OpenCV 4.1.1 has an out-of-bounds read in hal_baseline::v_load in core/hal/intrin_sse.hpp when called from computeSSDMea...
CVE-2019-16248MEDIUM5.5The "delete for" feature in Telegram before 5.11 on Android does not delete shared media files from the Telegram Images ...
CVE-2019-5055HIGH7.5An exploitable denial-of-service vulnerability exists in the Host Access Point Daemon (hostapd) on the NETGEAR N300 (WNR...
CVE-2019-5054HIGH7.5An exploitable denial-of-service vulnerability exists in the session handling functionality of the NETGEAR N300 (WNR2000...
CVE-2019-1306CRITICAL9.8A remote code execution vulnerability exists when Azure DevOps Server (ADO) and Team Foundation Server (TFS) fail to val...
CVE-2019-1305MEDIUM5.4A Cross-site Scripting (XSS) vulnerability exists when Team Foundation Server does not properly sanitize user provided i...
CVE-2019-1303HIGH7.8An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To e...
CVE-2019-1302HIGH8.8An elevation of privilege vulnerability exists when a ASP.NET Core web application, created using vulnerable project tem...
CVE-2019-1301HIGH7.5A denial of service vulnerability exists when .NET Core improperly handles web requests, aka '.NET Core Denial of Servic...
CVE-2019-1300HIGH7.5A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now