2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-6725 | — | — | 1.8% | May 31, 2019 | The rpWLANRedirect.asp ASP page is accessible without authentication on ZyXEL P-660HN-T1 V2 (2.00(AAKK.3)) devices. Afte... |
| CVE-2019-5678 | — | — | 0.9% | May 31, 2019 | NVIDIA GeForce Experience versions prior to 3.19 contains a vulnerability in the Web Helper component, in which an attac... |
| CVE-2019-10123 | — | — | 65.8% | May 31, 2019 | SQL Injection in Advanced InfoData Systems (AIS) ESEL-Server 67 (which is the backend for the AIS logistics mobile app) ... |
| CVE-2019-10069 | — | — | 3.4% | May 31, 2019 | In Godot through 3.1, remote code execution is possible due to the deserialization policy not being applied correctly. |
| CVE-2019-10049 | — | — | 1.2% | May 31, 2019 | It is possible for an attacker with regular user access to the web application of Pydio through 8.2.2 to trick an admini... |
| CVE-2019-10048 | — | — | 3.3% | May 31, 2019 | The ImageMagick plugin that is installed by default in Pydio through 8.2.2 does not perform the appropriate validation a... |
| CVE-2019-10047 | — | — | 0.7% | May 31, 2019 | A stored XSS vulnerability exists in the web application of Pydio through 8.2.2 that can be exploited by levering the fi... |
| CVE-2019-10046 | — | — | 1.2% | May 31, 2019 | An unauthenticated attacker can obtain information about the Pydio 8.2.2 configuration including session timeout, librar... |
| CVE-2019-10045 | — | — | 1.0% | May 31, 2019 | The "action" get_sess_id in the web application of Pydio through 8.2.2 discloses the session cookie value in the respons... |
| CVE-2019-10038 | — | — | 1.3% | May 31, 2019 | Evernote 7.9 on macOS allows attackers to execute arbitrary programs by embedding a reference to a local executable file... |
| CVE-2019-9891 | — | — | 3.3% | May 31, 2019 | The function getopt_simple as described in Advanced Bash Scripting Guide (ISBN 978-1435752184) allows privilege escalati... |
| CVE-2019-9875 | HIGH | 8.8 | 14.2% | May 31, 2019 | Deserialization of Untrusted Data in the anti CSRF module in Sitecore through 9.1 allows an authenticated attacker to ex... |
| CVE-2019-9874 | CRITICAL | 9.8 | 83.9% | May 31, 2019 | Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 an... |
| CVE-2019-10981 | HIGH | 7.8 | 0.4% | May 31, 2019 | In Vijeo Citect 7.30 and 7.40, and CitectSCADA 7.30 and 7.40, a vulnerability has been identified that may allow an auth... |
| CVE-2019-9871 | — | — | 5.8% | May 31, 2019 | Jector Smart TV FM-K75 devices allow remote code execution because there is an adb open port with root permission. |
| CVE-2019-10330 | HIGH | 7.5 | 2.1% | May 31, 2019 | Jenkins Gitea Plugin 1.1.1 and earlier did not implement trusted revisions, allowing attackers without commit access to ... |
| CVE-2019-10329 | HIGH | 8.8 | 1.8% | May 31, 2019 | Jenkins InfluxDB Plugin 1.21 and earlier stored credentials unencrypted in its global configuration file on the Jenkins ... |
| CVE-2019-10328 | — | — | 1.9% | May 31, 2019 | Jenkins Pipeline Remote Loader Plugin 1.4 and earlier provided a custom whitelist for script security that allowed attac... |
| CVE-2019-10327 | — | — | 1.5% | May 31, 2019 | An XML external entities (XXE) vulnerability in Jenkins Pipeline Maven Integration Plugin 1.7.0 and earlier allowed atta... |
| CVE-2019-10326 | — | — | 1.0% | May 31, 2019 | A cross-site request forgery vulnerability in Jenkins Warnings NG Plugin 5.0.0 and earlier allowed attackers to reset wa... |
| CVE-2019-10325 | — | — | 1.1% | May 31, 2019 | A cross-site scripting vulnerability in Jenkins Warnings NG Plugin 5.0.0 and earlier allowed attacker with Job/Configure... |
| CVE-2019-10324 | — | — | 0.8% | May 31, 2019 | A cross-site request forgery vulnerability in Jenkins Artifactory Plugin 3.2.2 and earlier in ReleaseAction#doSubmit, Gr... |
| CVE-2019-10323 | MEDIUM | 4.3 | 1.9% | May 31, 2019 | A missing permission check in Jenkins Artifactory Plugin 3.2.3 and earlier in various 'fillCredentialsIdItems' methods a... |
| CVE-2019-10322 | MEDIUM | 4.3 | 1.8% | May 31, 2019 | A missing permission check in Jenkins Artifactory Plugin 3.2.2 and earlier in ArtifactoryBuilder.DescriptorImpl#doTestCo... |
| CVE-2019-10321 | — | — | 0.9% | May 31, 2019 | A cross-site request forgery vulnerability in Jenkins Artifactory Plugin 3.2.2 and earlier in ArtifactoryBuilder.Descrip... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now