2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-10356 | HIGH | 8.8 | 2.5% | Jul 31, 2019 | A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.61 and earlier related to the handling of method poin... |
| CVE-2019-10355 | HIGH | 8.8 | 2.5% | Jul 31, 2019 | A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.61 and earlier related to the handling of type casts ... |
| CVE-2019-10345 | MEDIUM | 5.5 | 0.3% | Jul 31, 2019 | Jenkins Configuration as Code Plugin 1.20 and earlier did not treat the proxy password as a secret to be masked when log... |
| CVE-2019-10344 | MEDIUM | 4.3 | 0.7% | Jul 31, 2019 | Missing permission checks in Jenkins Configuration as Code Plugin 1.24 and earlier in various HTTP endpoints allowed use... |
| CVE-2019-10343 | LOW | 3.3 | 0.4% | Jul 31, 2019 | Jenkins Configuration as Code Plugin 1.24 and earlier did not properly apply masking to values expected to be hidden whe... |
| CVE-2019-14361 | — | — | — | Jul 31, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-14439. Reason: This candidate is a reservation d... |
| CVE-2019-14452 | — | — | 3.7% | Jul 31, 2019 | Sigil before 0.9.16 is vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ../ (dot d... |
| CVE-2019-10165 | LOW | 2.3 | 0.4% | Jul 30, 2019 | OpenShift Container Platform before version 4.1.3 writes OAuth tokens in plaintext to the audit logs for the Kubernetes ... |
| CVE-2019-10163 | MEDIUM | 4.3 | 1.0% | Jul 30, 2019 | A Vulnerability has been found in PowerDNS Authoritative Server before versions 4.1.9, 4.0.8 allowing a remote, authoriz... |
| CVE-2019-10162 | HIGH | 7.5 | 1.7% | Jul 30, 2019 | A vulnerability has been found in PowerDNS Authoritative Server before versions 4.1.10, 4.0.8 allowing an authorized use... |
| CVE-2019-10161 | HIGH | 7.8 | 0.5% | Jul 30, 2019 | It was discovered that libvirtd before versions 4.10.1 and 5.4.1 would permit read-only clients to use the virDomainSave... |
| CVE-2019-10156 | MEDIUM | 5.4 | 1.8% | Jul 30, 2019 | A flaw was discovered in the way Ansible templating was implemented in versions before 2.6.18, 2.7.12 and 2.8.2, causing... |
| CVE-2019-10153 | MEDIUM | 5 | 2.2% | Jul 30, 2019 | A flaw was discovered in fence-agents, prior to version 4.3.4, where using non-ASCII characters in a guest VM's comment ... |
| CVE-2019-10152 | HIGH | 7.2 | 0.5% | Jul 30, 2019 | A path traversal vulnerability has been discovered in podman before version 1.4.0 in the way it handles symlinks inside ... |
| CVE-2019-7616 | MEDIUM | 4.9 | 2.1% | Jul 30, 2019 | Kibana versions before 6.8.2 and 7.2.1 contain a server side request forgery (SSRF) flaw in the graphite integration for... |
| CVE-2019-7615 | HIGH | 7.4 | 0.6% | Jul 30, 2019 | A TLS certificate validation flaw was found in Elastic APM agent for Ruby versions before 2.9.0. When specifying a trust... |
| CVE-2019-7614 | MEDIUM | 5.9 | 1.0% | Jul 30, 2019 | A race condition flaw was found in the response headers Elasticsearch versions before 7.2.1 and 6.8.2 returns to a reque... |
| CVE-2019-5460 | MEDIUM | 5.5 | 2.5% | Jul 30, 2019 | Double Free in VLC versions <= 3.0.6 leads to a crash. |
| CVE-2019-5459 | HIGH | 7.1 | 2.8% | Jul 30, 2019 | An Integer underflow in VLC Media Player versions < 3.0.7 leads to an out-of-band read. |
| CVE-2019-5458 | MEDIUM | 5.4 | 0.7% | Jul 30, 2019 | Cross-site scripting (XSS) vulnerability in http-file-server (all versions) allows an attacker with access to the server... |
| CVE-2019-5457 | MEDIUM | 5.4 | 0.7% | Jul 30, 2019 | Cross-site scripting (XSS) vulnerability in min-http-server (all versions) allows an attacker with access to the server ... |
| CVE-2019-5456 | HIGH | 8.1 | 1.3% | Jul 30, 2019 | SMTP MITM refers to a malicious actor setting up an SMTP proxy server between the UniFi Controller version <= 5.10.21 an... |
| CVE-2019-5455 | MEDIUM | 6.8 | 0.5% | Jul 30, 2019 | Bypassing lock protection exists in Nextcloud Android app 3.6.0 when creating a multi-account and aborting the process. |
| CVE-2019-5454 | CRITICAL | 9.8 | 2.0% | Jul 30, 2019 | SQL Injection in the Nextcloud Android app prior to version 3.0.0 allows to destroy a local cache when a harmful query i... |
| CVE-2019-5453 | MEDIUM | 6.1 | 0.5% | Jul 30, 2019 | Bypass lock protection in the Nextcloud Android app prior to version 3.3.0 allowed access to files when being prompted f... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now