2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-10382 | MEDIUM | 6.5 | 0.8% | Aug 7, 2019 | Jenkins VMware Lab Manager Slaves Plugin 0.2.8 and earlier disables SSL/TLS and hostname verification globally for the J... |
| CVE-2019-10381 | HIGH | 7.5 | 1.1% | Aug 7, 2019 | Jenkins Codefresh Integration Plugin 1.8 and earlier disables SSL/TLS and hostname verification globally for the Jenkins... |
| CVE-2019-10380 | HIGH | 8.8 | 1.8% | Aug 7, 2019 | Jenkins Simple Travis Pipeline Runner Plugin 1.0 and earlier specifies unsafe values in its custom Script Security white... |
| CVE-2019-10379 | MEDIUM | 6.5 | 0.4% | Aug 7, 2019 | Jenkins Google Cloud Messaging Notification Plugin 1.0 and earlier stores credentials unencrypted in its global configur... |
| CVE-2019-10378 | MEDIUM | 5.3 | 0.5% | Aug 7, 2019 | Jenkins TestLink Plugin 3.16 and earlier stores credentials unencrypted in its global configuration file on the Jenkins ... |
| CVE-2019-10377 | MEDIUM | 4.3 | 0.7% | Aug 7, 2019 | A missing permission check in Jenkins Avatar Plugin 1.2 and earlier allows attackers with Overall/Read access to change ... |
| CVE-2019-10376 | MEDIUM | 6.1 | 0.8% | Aug 7, 2019 | A reflected cross-site scripting vulnerability in Jenkins Wall Display Plugin 0.6.34 and earlier allows attackers to inj... |
| CVE-2019-10375 | MEDIUM | 6.5 | 1.0% | Aug 7, 2019 | An arbitrary file read vulnerability in Jenkins File System SCM Plugin 2.1 and earlier allows attackers able to configur... |
| CVE-2019-10374 | MEDIUM | 5.4 | 0.7% | Aug 7, 2019 | A stored cross-site scripting vulnerability in Jenkins PegDown Formatter Plugin 1.3 and earlier allows attackers able to... |
| CVE-2019-10373 | MEDIUM | 5.4 | 0.7% | Aug 7, 2019 | A stored cross-site scripting vulnerability in Jenkins Build Pipeline Plugin 1.5.8 and earlier allows attackers able to ... |
| CVE-2019-10372 | MEDIUM | 6.1 | 1.0% | Aug 7, 2019 | An open redirect vulnerability in Jenkins Gitlab Authentication Plugin 1.4 and earlier in GitLabSecurityRealm.java allow... |
| CVE-2019-10371 | HIGH | 7.5 | 1.3% | Aug 7, 2019 | A session fixation vulnerability in Jenkins Gitlab Authentication Plugin 1.4 and earlier in GitLabSecurityRealm.java all... |
| CVE-2019-10370 | MEDIUM | 6.5 | 1.3% | Aug 7, 2019 | Jenkins Mask Passwords Plugin 2.12.0 and earlier transmits globally configured passwords in plain text as part of the co... |
| CVE-2019-10369 | MEDIUM | 6.5 | 1.0% | Aug 7, 2019 | A missing permission check in Jenkins JClouds Plugin 2.14 and earlier in BlobStoreProfile.DescriptorImpl#doTestConnectio... |
| CVE-2019-10368 | — | — | 0.8% | Aug 7, 2019 | A cross-site request forgery vulnerability in Jenkins JClouds Plugin 2.14 and earlier in BlobStoreProfile.DescriptorImpl... |
| CVE-2019-10367 | MEDIUM | 5.5 | 0.4% | Aug 7, 2019 | Due to an incomplete fix of CVE-2019-10343, Jenkins Configuration as Code Plugin 1.26 and earlier did not properly apply... |
| CVE-2019-1914 | HIGH | 7.2 | 24.9% | Aug 7, 2019 | A vulnerability in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an authent... |
| CVE-2019-1913 | CRITICAL | 9.8 | 25.9% | Aug 7, 2019 | Multiple vulnerabilities in the web management interface of Cisco Small Business 220 Series Smart Switches could allow a... |
| CVE-2019-1912 | CRITICAL | 9.1 | 17.0% | Aug 7, 2019 | A vulnerability in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an unauthe... |
| CVE-2019-14734 | HIGH | 8.8 | 1.9% | Aug 7, 2019 | AdPlug 2.3.1 has multiple heap-based buffer overflows in CmtkLoader::load() in mtk.cpp. |
| CVE-2019-14733 | HIGH | 8.8 | 1.7% | Aug 7, 2019 | AdPlug 2.3.1 has multiple heap-based buffer overflows in CradLoader::load() in rad.cpp. |
| CVE-2019-14732 | HIGH | 8.8 | 1.5% | Aug 7, 2019 | AdPlug 2.3.1 has multiple heap-based buffer overflows in Ca2mLoader::load() in a2m.cpp. |
| CVE-2019-14731 | — | — | 0.6% | Aug 7, 2019 | An issue was discovered in ZenTao 11.5.1. There is an XSS (stored) vulnerability that leads to the capture of other peop... |
| CVE-2019-14709 | — | — | 1.8% | Aug 6, 2019 | A cleartext password storage issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. The... |
| CVE-2019-14708 | — | — | 4.5% | Aug 6, 2019 | An issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. A buffer overflow in the acti... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now