2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-10382MEDIUM6.5Jenkins VMware Lab Manager Slaves Plugin 0.2.8 and earlier disables SSL/TLS and hostname verification globally for the J...
CVE-2019-10381HIGH7.5Jenkins Codefresh Integration Plugin 1.8 and earlier disables SSL/TLS and hostname verification globally for the Jenkins...
CVE-2019-10380HIGH8.8Jenkins Simple Travis Pipeline Runner Plugin 1.0 and earlier specifies unsafe values in its custom Script Security white...
CVE-2019-10379MEDIUM6.5Jenkins Google Cloud Messaging Notification Plugin 1.0 and earlier stores credentials unencrypted in its global configur...
CVE-2019-10378MEDIUM5.3Jenkins TestLink Plugin 3.16 and earlier stores credentials unencrypted in its global configuration file on the Jenkins ...
CVE-2019-10377MEDIUM4.3A missing permission check in Jenkins Avatar Plugin 1.2 and earlier allows attackers with Overall/Read access to change ...
CVE-2019-10376MEDIUM6.1A reflected cross-site scripting vulnerability in Jenkins Wall Display Plugin 0.6.34 and earlier allows attackers to inj...
CVE-2019-10375MEDIUM6.5An arbitrary file read vulnerability in Jenkins File System SCM Plugin 2.1 and earlier allows attackers able to configur...
CVE-2019-10374MEDIUM5.4A stored cross-site scripting vulnerability in Jenkins PegDown Formatter Plugin 1.3 and earlier allows attackers able to...
CVE-2019-10373MEDIUM5.4A stored cross-site scripting vulnerability in Jenkins Build Pipeline Plugin 1.5.8 and earlier allows attackers able to ...
CVE-2019-10372MEDIUM6.1An open redirect vulnerability in Jenkins Gitlab Authentication Plugin 1.4 and earlier in GitLabSecurityRealm.java allow...
CVE-2019-10371HIGH7.5A session fixation vulnerability in Jenkins Gitlab Authentication Plugin 1.4 and earlier in GitLabSecurityRealm.java all...
CVE-2019-10370MEDIUM6.5Jenkins Mask Passwords Plugin 2.12.0 and earlier transmits globally configured passwords in plain text as part of the co...
CVE-2019-10369MEDIUM6.5A missing permission check in Jenkins JClouds Plugin 2.14 and earlier in BlobStoreProfile.DescriptorImpl#doTestConnectio...
CVE-2019-10368A cross-site request forgery vulnerability in Jenkins JClouds Plugin 2.14 and earlier in BlobStoreProfile.DescriptorImpl...
CVE-2019-10367MEDIUM5.5Due to an incomplete fix of CVE-2019-10343, Jenkins Configuration as Code Plugin 1.26 and earlier did not properly apply...
CVE-2019-1914HIGH7.2A vulnerability in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an authent...
CVE-2019-1913CRITICAL9.8Multiple vulnerabilities in the web management interface of Cisco Small Business 220 Series Smart Switches could allow a...
CVE-2019-1912CRITICAL9.1A vulnerability in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an unauthe...
CVE-2019-14734HIGH8.8AdPlug 2.3.1 has multiple heap-based buffer overflows in CmtkLoader::load() in mtk.cpp.
CVE-2019-14733HIGH8.8AdPlug 2.3.1 has multiple heap-based buffer overflows in CradLoader::load() in rad.cpp.
CVE-2019-14732HIGH8.8AdPlug 2.3.1 has multiple heap-based buffer overflows in Ca2mLoader::load() in a2m.cpp.
CVE-2019-14731An issue was discovered in ZenTao 11.5.1. There is an XSS (stored) vulnerability that leads to the capture of other peop...
CVE-2019-14709A cleartext password storage issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. The...
CVE-2019-14708An issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. A buffer overflow in the acti...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now