2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-10314Jenkins Koji Plugin disables SSL/TLS and hostname verification globally for the Jenkins master JVM.
CVE-2019-10313HIGH8.8Jenkins Twitter Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they ...
CVE-2019-10312MEDIUM4.3A missing permission check in Jenkins Ansible Tower Plugin 0.9.1 and earlier in the TowerInstallation.TowerInstallationD...
CVE-2019-10311HIGH8.8A missing permission check in Jenkins Ansible Tower Plugin 0.9.1 and earlier in the TowerInstallation.TowerInstallationD...
CVE-2019-10310A cross-site request forgery vulnerability in Jenkins Ansible Tower Plugin 0.9.1 and earlier in the TowerInstallation.To...
CVE-2019-10309Jenkins Self-Organizing Swarm Plug-in Modules Plugin clients that use UDP broadcasts to discover Jenkins masters do not ...
CVE-2019-10308MEDIUM6.5A missing permission check in Jenkins Static Analysis Utilities Plugin 1.95 and earlier in the DefaultGraphConfiguration...
CVE-2019-10307A cross-site request forgery vulnerability in Jenkins Static Analysis Utilities Plugin 1.95 and earlier in the DefaultGr...
CVE-2019-3892Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-11599. Reason: This candidate is a reservation d...
CVE-2019-11599HIGH7The coredump implementation in the Linux kernel before 5.0.10 does not use locking or other mechanisms to prevent vma la...
CVE-2019-4047MEDIUM4.3IBM Jazz Reporting Service (JRS) 6.0.6 could allow an authenticated user to access the execution log files as a guest us...
CVE-2019-8454HIGH7A local attacker can create a hard-link between a file to which the Check Point Endpoint Security client for Windows bef...
CVE-2019-3563CRITICAL9.8Wangle's LineBasedFrameDecoder contains logic for identifying newlines which incorrectly advances a buffer, leading to a...
CVE-2019-3562A remote web page could inject arbitrary HTML code into the Oculus Browser UI, allowing an attacker to spoof UI and pote...
CVE-2019-3561Insufficient boundary checks for the strrpos and strripos functions allow access to out-of-bounds memory. This affects a...
CVE-2019-3560HIGH7.5An improperly performed length calculation on a buffer in PlaintextRecordLayer could lead to an infinite loop and denial...
CVE-2019-3493A potential security vulnerability has been identified in Micro Focus Network Automation Software 9.20, 9.21, 10.00, 10....
CVE-2019-11598In ImageMagick 7.0.8-40 Q16, there is a heap-based buffer over-read in the function WritePNMImage of coders/pnm.c, which...
CVE-2019-11597In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer over-read in the function WriteTIFFImage of coders/tiff.c, whi...
CVE-2019-5429HIGH7.8Untrusted search path in FileZilla before 3.41.0-rc1 allows an attacker to gain privileges via a malicious 'fzsftp' bina...
CVE-2019-11596In memcached before 1.5.14, a NULL pointer dereference was found in the "lru mode" and "lru temp_ttl" commands. This cau...
CVE-2019-11595In uBlock before 0.9.5.15, the $rewrite filter option allows filter-list maintainers to run arbitrary code in a client-s...
CVE-2019-11594In AdBlock before 3.45.0, the $rewrite filter option allows filter-list maintainers to run arbitrary code in a client-si...
CVE-2019-11593In Adblock Plus before 3.5.2, the $rewrite filter option allows filter-list maintainers to run arbitrary code in a clien...
CVE-2019-5492Element Plug-in for vCenter Server versions prior to 4.2.3 may disclose sensitive account information to an unauthentica...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now