2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-10356HIGH8.8A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.61 and earlier related to the handling of method poin...
CVE-2019-10355HIGH8.8A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.61 and earlier related to the handling of type casts ...
CVE-2019-10345MEDIUM5.5Jenkins Configuration as Code Plugin 1.20 and earlier did not treat the proxy password as a secret to be masked when log...
CVE-2019-10344MEDIUM4.3Missing permission checks in Jenkins Configuration as Code Plugin 1.24 and earlier in various HTTP endpoints allowed use...
CVE-2019-10343LOW3.3Jenkins Configuration as Code Plugin 1.24 and earlier did not properly apply masking to values expected to be hidden whe...
CVE-2019-14361Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-14439. Reason: This candidate is a reservation d...
CVE-2019-14452Sigil before 0.9.16 is vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ../ (dot d...
CVE-2019-10165LOW2.3OpenShift Container Platform before version 4.1.3 writes OAuth tokens in plaintext to the audit logs for the Kubernetes ...
CVE-2019-10163MEDIUM4.3A Vulnerability has been found in PowerDNS Authoritative Server before versions 4.1.9, 4.0.8 allowing a remote, authoriz...
CVE-2019-10162HIGH7.5A vulnerability has been found in PowerDNS Authoritative Server before versions 4.1.10, 4.0.8 allowing an authorized use...
CVE-2019-10161HIGH7.8It was discovered that libvirtd before versions 4.10.1 and 5.4.1 would permit read-only clients to use the virDomainSave...
CVE-2019-10156MEDIUM5.4A flaw was discovered in the way Ansible templating was implemented in versions before 2.6.18, 2.7.12 and 2.8.2, causing...
CVE-2019-10153MEDIUM5A flaw was discovered in fence-agents, prior to version 4.3.4, where using non-ASCII characters in a guest VM's comment ...
CVE-2019-10152HIGH7.2A path traversal vulnerability has been discovered in podman before version 1.4.0 in the way it handles symlinks inside ...
CVE-2019-7616MEDIUM4.9Kibana versions before 6.8.2 and 7.2.1 contain a server side request forgery (SSRF) flaw in the graphite integration for...
CVE-2019-7615HIGH7.4A TLS certificate validation flaw was found in Elastic APM agent for Ruby versions before 2.9.0. When specifying a trust...
CVE-2019-7614MEDIUM5.9A race condition flaw was found in the response headers Elasticsearch versions before 7.2.1 and 6.8.2 returns to a reque...
CVE-2019-5460MEDIUM5.5Double Free in VLC versions <= 3.0.6 leads to a crash.
CVE-2019-5459HIGH7.1An Integer underflow in VLC Media Player versions < 3.0.7 leads to an out-of-band read.
CVE-2019-5458MEDIUM5.4Cross-site scripting (XSS) vulnerability in http-file-server (all versions) allows an attacker with access to the server...
CVE-2019-5457MEDIUM5.4Cross-site scripting (XSS) vulnerability in min-http-server (all versions) allows an attacker with access to the server ...
CVE-2019-5456HIGH8.1SMTP MITM refers to a malicious actor setting up an SMTP proxy server between the UniFi Controller version <= 5.10.21 an...
CVE-2019-5455MEDIUM6.8Bypassing lock protection exists in Nextcloud Android app 3.6.0 when creating a multi-account and aborting the process.
CVE-2019-5454CRITICAL9.8SQL Injection in the Nextcloud Android app prior to version 3.0.0 allows to destroy a local cache when a harmful query i...
CVE-2019-5453MEDIUM6.1Bypass lock protection in the Nextcloud Android app prior to version 3.3.0 allowed access to files when being prompted f...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now