2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-6725The rpWLANRedirect.asp ASP page is accessible without authentication on ZyXEL P-660HN-T1 V2 (2.00(AAKK.3)) devices. Afte...
CVE-2019-5678NVIDIA GeForce Experience versions prior to 3.19 contains a vulnerability in the Web Helper component, in which an attac...
CVE-2019-10123SQL Injection in Advanced InfoData Systems (AIS) ESEL-Server 67 (which is the backend for the AIS logistics mobile app) ...
CVE-2019-10069In Godot through 3.1, remote code execution is possible due to the deserialization policy not being applied correctly.
CVE-2019-10049It is possible for an attacker with regular user access to the web application of Pydio through 8.2.2 to trick an admini...
CVE-2019-10048The ImageMagick plugin that is installed by default in Pydio through 8.2.2 does not perform the appropriate validation a...
CVE-2019-10047A stored XSS vulnerability exists in the web application of Pydio through 8.2.2 that can be exploited by levering the fi...
CVE-2019-10046An unauthenticated attacker can obtain information about the Pydio 8.2.2 configuration including session timeout, librar...
CVE-2019-10045The "action" get_sess_id in the web application of Pydio through 8.2.2 discloses the session cookie value in the respons...
CVE-2019-10038Evernote 7.9 on macOS allows attackers to execute arbitrary programs by embedding a reference to a local executable file...
CVE-2019-9891The function getopt_simple as described in Advanced Bash Scripting Guide (ISBN 978-1435752184) allows privilege escalati...
CVE-2019-9875HIGH8.8Deserialization of Untrusted Data in the anti CSRF module in Sitecore through 9.1 allows an authenticated attacker to ex...
CVE-2019-9874CRITICAL9.8Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 an...
CVE-2019-10981HIGH7.8In Vijeo Citect 7.30 and 7.40, and CitectSCADA 7.30 and 7.40, a vulnerability has been identified that may allow an auth...
CVE-2019-9871Jector Smart TV FM-K75 devices allow remote code execution because there is an adb open port with root permission.
CVE-2019-10330HIGH7.5Jenkins Gitea Plugin 1.1.1 and earlier did not implement trusted revisions, allowing attackers without commit access to ...
CVE-2019-10329HIGH8.8Jenkins InfluxDB Plugin 1.21 and earlier stored credentials unencrypted in its global configuration file on the Jenkins ...
CVE-2019-10328Jenkins Pipeline Remote Loader Plugin 1.4 and earlier provided a custom whitelist for script security that allowed attac...
CVE-2019-10327An XML external entities (XXE) vulnerability in Jenkins Pipeline Maven Integration Plugin 1.7.0 and earlier allowed atta...
CVE-2019-10326A cross-site request forgery vulnerability in Jenkins Warnings NG Plugin 5.0.0 and earlier allowed attackers to reset wa...
CVE-2019-10325A cross-site scripting vulnerability in Jenkins Warnings NG Plugin 5.0.0 and earlier allowed attacker with Job/Configure...
CVE-2019-10324A cross-site request forgery vulnerability in Jenkins Artifactory Plugin 3.2.2 and earlier in ReleaseAction#doSubmit, Gr...
CVE-2019-10323MEDIUM4.3A missing permission check in Jenkins Artifactory Plugin 3.2.3 and earlier in various 'fillCredentialsIdItems' methods a...
CVE-2019-10322MEDIUM4.3A missing permission check in Jenkins Artifactory Plugin 3.2.2 and earlier in ArtifactoryBuilder.DescriptorImpl#doTestCo...
CVE-2019-10321A cross-site request forgery vulnerability in Jenkins Artifactory Plugin 3.2.2 and earlier in ArtifactoryBuilder.Descrip...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now