2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-10314 | — | — | 1.5% | Apr 30, 2019 | Jenkins Koji Plugin disables SSL/TLS and hostname verification globally for the Jenkins master JVM. |
| CVE-2019-10313 | HIGH | 8.8 | 1.8% | Apr 30, 2019 | Jenkins Twitter Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they ... |
| CVE-2019-10312 | MEDIUM | 4.3 | 1.4% | Apr 30, 2019 | A missing permission check in Jenkins Ansible Tower Plugin 0.9.1 and earlier in the TowerInstallation.TowerInstallationD... |
| CVE-2019-10311 | HIGH | 8.8 | 1.8% | Apr 30, 2019 | A missing permission check in Jenkins Ansible Tower Plugin 0.9.1 and earlier in the TowerInstallation.TowerInstallationD... |
| CVE-2019-10310 | — | — | 1.5% | Apr 30, 2019 | A cross-site request forgery vulnerability in Jenkins Ansible Tower Plugin 0.9.1 and earlier in the TowerInstallation.To... |
| CVE-2019-10309 | — | — | 1.8% | Apr 30, 2019 | Jenkins Self-Organizing Swarm Plug-in Modules Plugin clients that use UDP broadcasts to discover Jenkins masters do not ... |
| CVE-2019-10308 | MEDIUM | 6.5 | 1.5% | Apr 30, 2019 | A missing permission check in Jenkins Static Analysis Utilities Plugin 1.95 and earlier in the DefaultGraphConfiguration... |
| CVE-2019-10307 | — | — | 1.0% | Apr 30, 2019 | A cross-site request forgery vulnerability in Jenkins Static Analysis Utilities Plugin 1.95 and earlier in the DefaultGr... |
| CVE-2019-3892 | — | — | — | Apr 30, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-11599. Reason: This candidate is a reservation d... |
| CVE-2019-11599 | HIGH | 7 | 1.0% | Apr 29, 2019 | The coredump implementation in the Linux kernel before 5.0.10 does not use locking or other mechanisms to prevent vma la... |
| CVE-2019-4047 | MEDIUM | 4.3 | 1.5% | Apr 29, 2019 | IBM Jazz Reporting Service (JRS) 6.0.6 could allow an authenticated user to access the execution log files as a guest us... |
| CVE-2019-8454 | HIGH | 7 | 0.3% | Apr 29, 2019 | A local attacker can create a hard-link between a file to which the Check Point Endpoint Security client for Windows bef... |
| CVE-2019-3563 | CRITICAL | 9.8 | 1.7% | Apr 29, 2019 | Wangle's LineBasedFrameDecoder contains logic for identifying newlines which incorrectly advances a buffer, leading to a... |
| CVE-2019-3562 | — | — | 1.1% | Apr 29, 2019 | A remote web page could inject arbitrary HTML code into the Oculus Browser UI, allowing an attacker to spoof UI and pote... |
| CVE-2019-3561 | — | — | 1.7% | Apr 29, 2019 | Insufficient boundary checks for the strrpos and strripos functions allow access to out-of-bounds memory. This affects a... |
| CVE-2019-3560 | HIGH | 7.5 | 2.4% | Apr 29, 2019 | An improperly performed length calculation on a buffer in PlaintextRecordLayer could lead to an infinite loop and denial... |
| CVE-2019-3493 | — | — | 1.8% | Apr 29, 2019 | A potential security vulnerability has been identified in Micro Focus Network Automation Software 9.20, 9.21, 10.00, 10.... |
| CVE-2019-11598 | — | — | 4.1% | Apr 29, 2019 | In ImageMagick 7.0.8-40 Q16, there is a heap-based buffer over-read in the function WritePNMImage of coders/pnm.c, which... |
| CVE-2019-11597 | — | — | 3.7% | Apr 29, 2019 | In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer over-read in the function WriteTIFFImage of coders/tiff.c, whi... |
| CVE-2019-5429 | HIGH | 7.8 | 2.5% | Apr 29, 2019 | Untrusted search path in FileZilla before 3.41.0-rc1 allows an attacker to gain privileges via a malicious 'fzsftp' bina... |
| CVE-2019-11596 | — | — | 3.0% | Apr 29, 2019 | In memcached before 1.5.14, a NULL pointer dereference was found in the "lru mode" and "lru temp_ttl" commands. This cau... |
| CVE-2019-11595 | — | — | 2.4% | Apr 29, 2019 | In uBlock before 0.9.5.15, the $rewrite filter option allows filter-list maintainers to run arbitrary code in a client-s... |
| CVE-2019-11594 | — | — | 2.4% | Apr 29, 2019 | In AdBlock before 3.45.0, the $rewrite filter option allows filter-list maintainers to run arbitrary code in a client-si... |
| CVE-2019-11593 | — | — | 2.5% | Apr 29, 2019 | In Adblock Plus before 3.5.2, the $rewrite filter option allows filter-list maintainers to run arbitrary code in a clien... |
| CVE-2019-5492 | — | — | 1.5% | Apr 29, 2019 | Element Plug-in for vCenter Server versions prior to 4.2.3 may disclose sensitive account information to an unauthentica... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now