2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-12363An CSRF issue was discovered in the JN-Jones MyBB-2FA plugin through 2014-11-05 for MyBB. An attacker can forge a reques...
CVE-2019-10351HIGH8.8Jenkins Caliper CI Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be...
CVE-2019-10350HIGH8.8Jenkins Port Allocator Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they ca...
CVE-2019-10349MEDIUM5.4A stored cross site scripting vulnerability in Jenkins Dependency Graph Viewer Plugin 0.13 and earlier allowed attackers...
CVE-2019-10348HIGH8.8Jenkins Gogs Plugin stored credentials unencrypted in job config.xml files on the Jenkins master where they can be viewe...
CVE-2019-10347HIGH8.8Jenkins Mashup Portlets Plugin stored credentials unencrypted on the Jenkins master where they can be viewed by users wi...
CVE-2019-10346MEDIUM6.1A reflected cross site scripting vulnerability in Jenkins Embeddable Build Status Plugin 2.0.1 and earlier allowed attac...
CVE-2019-10342MEDIUM4.3A missing permission check in Jenkins Docker Plugin 1.1.6 and earlier in various 'fillCredentialsIdItems' methods allowe...
CVE-2019-10341MEDIUM6.5A missing permission check in Jenkins Docker Plugin 1.1.6 and earlier in DockerAPI.DescriptorImpl#doTestConnection allow...
CVE-2019-10340HIGH8.8A cross-site request forgery vulnerability in Jenkins Docker Plugin 1.1.6 and earlier in DockerAPI.DescriptorImpl#doTest...
CVE-2019-13505MEDIUM6.1The Appointment Hour Booking plugin 1.1.44 for WordPress allows XSS via the E-mail field, as demonstrated by email_1.
CVE-2019-12838CRITICAL9.8SchedMD Slurm 17.11.x, 18.08.0 through 18.08.7, and 19.05.0 allows SQL Injection.
CVE-2019-1010003Leanote prior to version 2.6 is affected by: Cross Site Scripting (XSS).
CVE-2019-13504MEDIUM6.5There is an out-of-bounds read in Exiv2::MrwImage::readMetadata in mrwimage.cpp in Exiv2 through 0.27.2.
CVE-2019-13503HIGH7.5mq_parse_http in mongoose.c in Mongoose 6.15 has a heap-based buffer over-read.
CVE-2019-13489Trape through 2019-05-08 has SQL injection via the data[2] variable in core/db.py, as demonstrated by the /bs t paramete...
CVE-2019-13488A cross-site scripting (XSS) vulnerability in static/js/trape.js in Trape through 2019-05-08 allows remote attackers to ...
CVE-2019-13381Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2019-5446HIGH7.2Command Injection in EdgeMAX EdgeSwitch prior to 1.8.2 allow an Admin user to execute commands as root.
CVE-2019-5445MEDIUM4.9DoS in EdgeMAX EdgeSwitch prior to 1.8.2 allow an Admin user to Crash the SSH CLI interface by using crafted commands.
CVE-2019-5444MEDIUM5.3Path traversal vulnerability in version up to v1.1.3 in serve-here.js npm module allows attackers to list any file in ar...
CVE-2019-13482HIGH8.8An issue was discovered on D-Link DIR-818LW devices with firmware 2.06betab01. There is a command injection in HNAP1 (ex...
CVE-2019-13481HIGH8.8An issue was discovered on D-Link DIR-818LW devices with firmware 2.06betab01. There is a command injection in HNAP1 (ex...
CVE-2019-12804MEDIUM5.5In Hunesion i-oneNet version 3.0.7 ~ 3.0.53 and 4.0.4 ~ 4.0.16, due to the lack of update file integrity checking in the...
CVE-2019-12803CRITICAL9.8In Hunesion i-oneNet version 3.0.7 ~ 3.0.53 and 4.0.4 ~ 4.0.16, the specific upload web module doesn't verify the file e...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now