2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-12363 | — | — | 0.6% | Jul 11, 2019 | An CSRF issue was discovered in the JN-Jones MyBB-2FA plugin through 2014-11-05 for MyBB. An attacker can forge a reques... |
| CVE-2019-10351 | HIGH | 8.8 | 1.6% | Jul 11, 2019 | Jenkins Caliper CI Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be... |
| CVE-2019-10350 | HIGH | 8.8 | 1.7% | Jul 11, 2019 | Jenkins Port Allocator Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they ca... |
| CVE-2019-10349 | MEDIUM | 5.4 | 3.9% | Jul 11, 2019 | A stored cross site scripting vulnerability in Jenkins Dependency Graph Viewer Plugin 0.13 and earlier allowed attackers... |
| CVE-2019-10348 | HIGH | 8.8 | 1.7% | Jul 11, 2019 | Jenkins Gogs Plugin stored credentials unencrypted in job config.xml files on the Jenkins master where they can be viewe... |
| CVE-2019-10347 | HIGH | 8.8 | 1.8% | Jul 11, 2019 | Jenkins Mashup Portlets Plugin stored credentials unencrypted on the Jenkins master where they can be viewed by users wi... |
| CVE-2019-10346 | MEDIUM | 6.1 | 1.7% | Jul 11, 2019 | A reflected cross site scripting vulnerability in Jenkins Embeddable Build Status Plugin 2.0.1 and earlier allowed attac... |
| CVE-2019-10342 | MEDIUM | 4.3 | 1.4% | Jul 11, 2019 | A missing permission check in Jenkins Docker Plugin 1.1.6 and earlier in various 'fillCredentialsIdItems' methods allowe... |
| CVE-2019-10341 | MEDIUM | 6.5 | 1.7% | Jul 11, 2019 | A missing permission check in Jenkins Docker Plugin 1.1.6 and earlier in DockerAPI.DescriptorImpl#doTestConnection allow... |
| CVE-2019-10340 | HIGH | 8.8 | 1.4% | Jul 11, 2019 | A cross-site request forgery vulnerability in Jenkins Docker Plugin 1.1.6 and earlier in DockerAPI.DescriptorImpl#doTest... |
| CVE-2019-13505 | MEDIUM | 6.1 | 1.4% | Jul 11, 2019 | The Appointment Hour Booking plugin 1.1.44 for WordPress allows XSS via the E-mail field, as demonstrated by email_1. |
| CVE-2019-12838 | CRITICAL | 9.8 | 2.7% | Jul 11, 2019 | SchedMD Slurm 17.11.x, 18.08.0 through 18.08.7, and 19.05.0 allows SQL Injection. |
| CVE-2019-1010003 | — | — | 0.6% | Jul 11, 2019 | Leanote prior to version 2.6 is affected by: Cross Site Scripting (XSS). |
| CVE-2019-13504 | MEDIUM | 6.5 | 2.4% | Jul 11, 2019 | There is an out-of-bounds read in Exiv2::MrwImage::readMetadata in mrwimage.cpp in Exiv2 through 0.27.2. |
| CVE-2019-13503 | HIGH | 7.5 | 1.4% | Jul 11, 2019 | mq_parse_http in mongoose.c in Mongoose 6.15 has a heap-based buffer over-read. |
| CVE-2019-13489 | — | — | 1.4% | Jul 10, 2019 | Trape through 2019-05-08 has SQL injection via the data[2] variable in core/db.py, as demonstrated by the /bs t paramete... |
| CVE-2019-13488 | — | — | 1.1% | Jul 10, 2019 | A cross-site scripting (XSS) vulnerability in static/js/trape.js in Trape through 2019-05-08 allows remote attackers to ... |
| CVE-2019-13381 | — | — | — | Jul 10, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2019-5446 | HIGH | 7.2 | 2.7% | Jul 10, 2019 | Command Injection in EdgeMAX EdgeSwitch prior to 1.8.2 allow an Admin user to execute commands as root. |
| CVE-2019-5445 | MEDIUM | 4.9 | 1.3% | Jul 10, 2019 | DoS in EdgeMAX EdgeSwitch prior to 1.8.2 allow an Admin user to Crash the SSH CLI interface by using crafted commands. |
| CVE-2019-5444 | MEDIUM | 5.3 | 1.5% | Jul 10, 2019 | Path traversal vulnerability in version up to v1.1.3 in serve-here.js npm module allows attackers to list any file in ar... |
| CVE-2019-13482 | HIGH | 8.8 | 8.1% | Jul 10, 2019 | An issue was discovered on D-Link DIR-818LW devices with firmware 2.06betab01. There is a command injection in HNAP1 (ex... |
| CVE-2019-13481 | HIGH | 8.8 | 8.2% | Jul 10, 2019 | An issue was discovered on D-Link DIR-818LW devices with firmware 2.06betab01. There is a command injection in HNAP1 (ex... |
| CVE-2019-12804 | MEDIUM | 5.5 | 0.4% | Jul 10, 2019 | In Hunesion i-oneNet version 3.0.7 ~ 3.0.53 and 4.0.4 ~ 4.0.16, due to the lack of update file integrity checking in the... |
| CVE-2019-12803 | CRITICAL | 9.8 | 1.9% | Jul 10, 2019 | In Hunesion i-oneNet version 3.0.7 ~ 3.0.53 and 4.0.4 ~ 4.0.16, the specific upload web module doesn't verify the file e... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now