2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-10335 | — | — | 1.1% | Jun 11, 2019 | A stored cross site scripting vulnerability in Jenkins ElectricFlow Plugin 1.1.5 and earlier allowed attackers able to c... |
| CVE-2019-10334 | — | — | 1.3% | Jun 11, 2019 | Jenkins ElectricFlow Plugin 1.1.5 and earlier disabled SSL/TLS and hostname verification globally for the Jenkins master... |
| CVE-2019-10333 | MEDIUM | 4.3 | 1.4% | Jun 11, 2019 | Missing permission checks in Jenkins ElectricFlow Plugin 1.1.5 and earlier in various HTTP endpoints allowed users with ... |
| CVE-2019-10332 | MEDIUM | 4.3 | 1.8% | Jun 11, 2019 | A missing permission check in Jenkins ElectricFlow Plugin 1.1.5 and earlier in Configuration#doTestConnection allowed us... |
| CVE-2019-10331 | — | — | 1.1% | Jun 11, 2019 | A cross-site request forgery vulnerability in Jenkins ElectricFlow Plugin 1.1.5 and earlier in Configuration#doTestConne... |
| CVE-2019-10226 | — | — | 4.7% | Jun 10, 2019 | HTML Injection has been discovered in the v0.19.0 version of the Fat Free CRM product via an authenticated request to th... |
| CVE-2019-11881 | — | — | 2.3% | Jun 10, 2019 | A vulnerability exists in Rancher before 2.2.4 in the login component, where the errorMsg parameter can be tampered to d... |
| CVE-2019-12790 | — | — | 1.7% | Jun 10, 2019 | In radare2 through 3.5.1, there is a heap-based buffer over-read in the r_egg_lang_parsechar function of egg_lang.c. Thi... |
| CVE-2019-12788 | HIGH | 7.8 | 4.5% | Jun 10, 2019 | An issue was discovered in Photodex ProShow Producer v9.0.3797 (an application that runs with Administrator privileges).... |
| CVE-2019-11027 | — | — | 2.9% | Jun 10, 2019 | Ruby OpenID (aka ruby-openid) through 2.8.0 has a remotely exploitable flaw. This library is used by Rails web applicati... |
| CVE-2019-9881 | — | — | 18.8% | Jun 10, 2019 | The createComment mutation in the WPGraphQL 0.2.3 plugin for WordPress allows unauthenticated users to post comments on ... |
| CVE-2019-9880 | — | — | 34.8% | Jun 10, 2019 | An issue was discovered in the WPGraphQL 0.2.3 plugin for WordPress. By querying the 'users' RootQuery, it is possible, ... |
| CVE-2019-9879 | — | — | 46.6% | Jun 10, 2019 | The WPGraphQL 0.2.3 plugin for WordPress allows remote attackers to register a new user with admin privileges, whenever ... |
| CVE-2019-12787 | HIGH | 8.8 | 2.9% | Jun 10, 2019 | An issue was discovered on D-Link DIR-818LW devices from 2.05.B03 to 2.06B01 BETA. There is a command injection in HNAP1... |
| CVE-2019-12786 | HIGH | 8.8 | 2.9% | Jun 10, 2019 | An issue was discovered on D-Link DIR-818LW devices from 2.05.B03 to 2.06B01 BETA. There is a command injection in HNAP1... |
| CVE-2019-11517 | — | — | 0.4% | Jun 10, 2019 | WampServer before 3.1.9 has CSRF in add_vhost.php because the synchronizer pattern implemented as remediation of CVE-201... |
| CVE-2019-6241 | — | — | 1.1% | Jun 10, 2019 | In Bevywise MQTTRoute 1.1 build 1018-002, a connect packet combined with a malformed unsubscribe request packet can be u... |
| CVE-2019-11877 | — | — | 0.9% | Jun 10, 2019 | XSS on the PIX-Link Repeater/Router LV-WR09 with firmware v28K.MiniRouter.20180616 allows attackers to steal credentials... |
| CVE-2019-12780 | — | — | 72.0% | Jun 10, 2019 | The Belkin Wemo Enabled Crock-Pot allows command injection in the Wemo UPnP API via the SmartDevURL argument to the SetS... |
| CVE-2019-5243 | — | — | 0.6% | Jun 10, 2019 | There is a Clickjacking vulnerability in Huawei HG255s product. An attacker may trick user to click a link and affect th... |
| CVE-2019-0209 | — | — | — | Jun 10, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2019-12387 | MEDIUM | 6.1 | 2.5% | Jun 10, 2019 | In Twisted before 19.2.1, twisted.web did not validate or sanitize URIs or HTTP methods, allowing an attacker to inject ... |
| CVE-2019-9087 | — | — | 1.6% | Jun 7, 2019 | HotelDruid before v2.3.1 has SQL Injection via the /tab_tariffe.php numtariffa1 parameter. |
| CVE-2019-9086 | — | — | 1.6% | Jun 7, 2019 | HotelDruid before v2.3.1 has SQL Injection via the /visualizza_tabelle.php anno parameter. |
| CVE-2019-9084 | — | — | 1.7% | Jun 7, 2019 | In Hoteldruid before 2.3.1, a division by zero was discovered in $num_tabelle in tab_tariffe.php (aka the numtariffa1 pa... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now