2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-3638 | CRITICAL | 9.6 | 1.9% | Sep 12, 2019 | Reflected Cross Site Scripting vulnerability in Administrators web console in McAfee Web Gateway (MWG) 7.8.x prior to 7.... |
| CVE-2019-16238 | MEDIUM | 6.1 | 0.9% | Sep 12, 2019 | Afterlogic Aurora through 8.3.9-build-a3 has XSS that can be leveraged for session hijacking by retrieving the session c... |
| CVE-2019-16261 | CRITICAL | 9.1 | 2.8% | Sep 12, 2019 | Tripp Lite PDUMH15AT 12.04.0053 and SU750XL 12.04.0052 devices allow unauthenticated POST requests to the /Forms/ direct... |
| CVE-2019-10400 | MEDIUM | 4.2 | 1.0% | Sep 12, 2019 | A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.62 and earlier related to the handling of subexpressi... |
| CVE-2019-10399 | MEDIUM | 4.2 | 1.0% | Sep 12, 2019 | A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.62 and earlier related to the handling of property na... |
| CVE-2019-10398 | MEDIUM | 5.5 | 0.3% | Sep 12, 2019 | Jenkins Beaker Builder Plugin 1.9 and earlier stored credentials unencrypted in its global configuration file on the Jen... |
| CVE-2019-10397 | LOW | 3.1 | 0.6% | Sep 12, 2019 | Jenkins Aqua Security Serverless Scanner Plugin 1.0.4 and earlier transmitted configured passwords in plain text as part... |
| CVE-2019-10396 | MEDIUM | 5.4 | 0.7% | Sep 12, 2019 | Jenkins Dashboard View Plugin 2.11 and earlier did not escape build descriptions, resulting in a cross-site scripting vu... |
| CVE-2019-10395 | MEDIUM | 5.4 | 0.7% | Sep 12, 2019 | Jenkins Build Environment Plugin 1.6 and earlier did not escape variables shown on its views, resulting in a cross-site ... |
| CVE-2019-10394 | MEDIUM | 4.2 | 1.0% | Sep 12, 2019 | A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.62 and earlier related to the handling of property na... |
| CVE-2019-10393 | MEDIUM | 4.2 | 1.0% | Sep 12, 2019 | A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.62 and earlier related to the handling of method name... |
| CVE-2019-10392 | HIGH | 8.8 | 25.6% | Sep 12, 2019 | Jenkins Git Client Plugin 2.8.4 and earlier and 3.0.0-rc did not properly restrict values passed as URL argument to an i... |
| CVE-2019-16257 | CRITICAL | 9.8 | 2.1% | Sep 12, 2019 | Some Motorola devices include the SIMalliance Toolbox Browser (aka S@T Browser) on the UICC, which might allow remote at... |
| CVE-2019-16256 | CRITICAL | 9.8 | 4.9% | Sep 12, 2019 | Some Samsung devices include the SIMalliance Toolbox Browser (aka S@T Browser) on the UICC, which might allow remote att... |
| CVE-2019-16250 | HIGH | 7.5 | 1.4% | Sep 11, 2019 | includes/wizard/wizard.php in the Ocean Extra plugin through 1.5.8 for WordPress allows unauthenticated options changes ... |
| CVE-2019-16249 | MEDIUM | 5.3 | 1.7% | Sep 11, 2019 | OpenCV 4.1.1 has an out-of-bounds read in hal_baseline::v_load in core/hal/intrin_sse.hpp when called from computeSSDMea... |
| CVE-2019-16248 | MEDIUM | 5.5 | 0.4% | Sep 11, 2019 | The "delete for" feature in Telegram before 5.11 on Android does not delete shared media files from the Telegram Images ... |
| CVE-2019-5055 | HIGH | 7.5 | 2.0% | Sep 11, 2019 | An exploitable denial-of-service vulnerability exists in the Host Access Point Daemon (hostapd) on the NETGEAR N300 (WNR... |
| CVE-2019-5054 | HIGH | 7.5 | 3.1% | Sep 11, 2019 | An exploitable denial-of-service vulnerability exists in the session handling functionality of the NETGEAR N300 (WNR2000... |
| CVE-2019-1306 | CRITICAL | 9.8 | 15.9% | Sep 11, 2019 | A remote code execution vulnerability exists when Azure DevOps Server (ADO) and Team Foundation Server (TFS) fail to val... |
| CVE-2019-1305 | MEDIUM | 5.4 | 1.4% | Sep 11, 2019 | A Cross-site Scripting (XSS) vulnerability exists when Team Foundation Server does not properly sanitize user provided i... |
| CVE-2019-1303 | HIGH | 7.8 | 1.1% | Sep 11, 2019 | An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To e... |
| CVE-2019-1302 | HIGH | 8.8 | 4.5% | Sep 11, 2019 | An elevation of privilege vulnerability exists when a ASP.NET Core web application, created using vulnerable project tem... |
| CVE-2019-1301 | HIGH | 7.5 | 5.0% | Sep 11, 2019 | A denial of service vulnerability exists when .NET Core improperly handles web requests, aka '.NET Core Denial of Servic... |
| CVE-2019-1300 | HIGH | 7.5 | 8.1% | Sep 11, 2019 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now