2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-5590The URL part of the report message is not encoded in Fortinet FortiWeb 6.0.2 and below which may allow an attacker to ex...
CVE-2019-15720CloudBerry Backup v6.1.2.34 allows local privilege escalation via a Pre or Post backup action. With only user-level acce...
CVE-2019-15496MyT Project Management 1.5.1 lacks CSRF protection and, for example, allows a user/create CSRF attack. This could lead t...
CVE-2019-15230LibreNMS v1.54 has XSS in the Create User, Inventory, Add Device, Notifications, Alert Rule, Create Maintenance, and Ale...
CVE-2019-9935Various Lexmark products have Incorrect Access Control (issue 2 of 2).
CVE-2019-9934Various Lexmark products have Incorrect Access Control (issue 1 of 2).
CVE-2019-13348In Knowage through 6.1.1, an authenticated user who accesses the datasources page will gain access to any data source cr...
CVE-2019-13189In Knowage through 6.1.1, there is XSS via the start_url or user_id field to the ChangePwdServlet page.
CVE-2019-10391MEDIUM6.5Jenkins IBM Application Security on Cloud Plugin 1.2.4 and earlier transmitted configured passwords in plain text as par...
CVE-2019-10390HIGH8.8A sandbox bypass vulnerability in Jenkins Splunk Plugin 1.7.4 and earlier allowed attackers with Overall/Read permission...
CVE-2019-10384HIGH8.8Jenkins 2.191 and earlier, LTS 2.176.2 and earlier allowed users to obtain CSRF tokens without an associated web session...
CVE-2019-10383MEDIUM4.8A stored cross-site scripting vulnerability in Jenkins 2.191 and earlier, LTS 2.176.2 and earlier allowed attackers with...
CVE-2019-10058Various Lexmark products have Incorrect Access Control.
CVE-2019-15716WTF before 0.19.0 does not set the permissions of config.yml, which might make it easier for local attackers to read pas...
CVE-2019-15714cli/lib/main.js in Entropic before 2019-06-13 does not reject / and \ in command names, which might allow a directory tr...
CVE-2019-15713The my-calendar plugin before 3.1.10 for WordPress has XSS.
CVE-2019-15294An issue was discovered in Gallagher Command Centre 8.10 before 8.10.1092(MR2). Upon an upgrade, if a custom service acc...
CVE-2019-15702HIGH7.5In the TCP implementation (gnrc_tcp) in RIOT through 2019.07, the parser for TCP options does not terminate on all input...
CVE-2019-15701components/Modals/HelpModal.jsx in BloodHound 2.2.0 allows remote attackers to execute arbitrary OS commands (by spawnin...
CVE-2019-15700public/js/frappe/form/footer/timeline.js in Frappe Framework 12 through 12.0.8 does not escape HTML in the timeline and ...
CVE-2019-13270Edimax BR-6208AC V1 devices have Insufficient Compartmentalization between a host network and a guest network that are e...
CVE-2019-13269Edimax BR-6208AC V1 devices have Insufficient Compartmentalization between a host network and a guest network that are e...
CVE-2019-13268TP-Link Archer C3200 V1 and Archer C2 V1 devices have Insufficient Compartmentalization between a host network and a gue...
CVE-2019-13267TP-Link Archer C3200 V1 and Archer C2 V1 devices have Insufficient Compartmentalization between a host network and a gue...
CVE-2019-13266TP-Link Archer C3200 V1 and Archer C2 V1 devices have Insufficient Compartmentalization between a host network and a gue...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now