2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-3719 | HIGH | 8 | 17.6% | Apr 18, 2019 | Dell SupportAssist Client versions prior to 3.2.0.90 contain a remote code execution vulnerability. An unauthenticated a... |
| CVE-2019-3718 | HIGH | 8.8 | 0.7% | Apr 18, 2019 | Dell SupportAssist Client versions prior to 3.2.0.90 contain an improper origin validation vulnerability. An unauthentic... |
| CVE-2019-10893 | — | — | 2.9% | Apr 18, 2019 | CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.793 (Free/Open Source Version) and 0.9.8.753 (Pro) is vulnerable to... |
| CVE-2019-11084 | — | — | 0.8% | Apr 18, 2019 | GAuth 0.9.9 beta has stored XSS that shows a popup repeatedly and discloses cookies. |
| CVE-2019-9005 | — | — | 2.1% | Apr 18, 2019 | The Cprime Power Scripts app before 4.0.14 for Atlassian Jira allows Directory Traversal. |
| CVE-2019-3885 | LOW | 3.3 | 2.0% | Apr 18, 2019 | A use-after-free flaw was found in pacemaker up to and including version 2.0.1 which could result in certain sensitive i... |
| CVE-2019-3398 | HIGH | 8.8 | 97.2% | Apr 18, 2019 | Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote at... |
| CVE-2019-11223 | — | — | 8.8% | Apr 18, 2019 | An Unrestricted File Upload Vulnerability in the SupportCandy plugin through 2.0.0 for WordPress allows remote attackers... |
| CVE-2019-11017 | MEDIUM | 4.8 | 1.5% | Apr 18, 2019 | On D-Link DI-524 V2.06RU devices, multiple Stored and Reflected XSS vulnerabilities were found in the Web Configuration:... |
| CVE-2019-8999 | — | — | 1.5% | Apr 18, 2019 | An XML External Entity vulnerability in the UEM Core of BlackBerry UEM version(s) earlier than 12.10.1a could allow an a... |
| CVE-2019-11322 | — | — | 3.9% | Apr 18, 2019 | An issue was discovered in Motorola CX2 1.01 and M2 1.01. There is a command injection in the function startRmtAssist in... |
| CVE-2019-11321 | — | — | 1.3% | Apr 18, 2019 | An issue was discovered in Motorola CX2 1.01 and M2 1.01. The router opens TCP port 8010. Users can send hnap requests t... |
| CVE-2019-11320 | — | — | 1.7% | Apr 18, 2019 | In Motorola CX2 1.01 and M2 1.01, users can access the router's /priv_mgt.html web page to launch telnetd, as demonstrat... |
| CVE-2019-11319 | — | — | 3.9% | Apr 18, 2019 | An issue was discovered in Motorola CX2 1.01 and M2 1.01. There is a command injection in the function downloadFirmware ... |
| CVE-2019-11035 | CRITICAL | 9.1 | 4.3% | Apr 18, 2019 | When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.28, 7.2.x below 7.2.17 and 7.3.x below 7.3... |
| CVE-2019-11034 | CRITICAL | 9.1 | 4.0% | Apr 18, 2019 | When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.28, 7.2.x below 7.2.17 and 7.3.x below 7.3... |
| CVE-2019-10306 | CRITICAL | 9.9 | 2.4% | Apr 18, 2019 | A sandbox bypass vulnerability in Jenkins ontrack Plugin 3.4 and earlier allowed attackers with control over ontrack DSL... |
| CVE-2019-10305 | MEDIUM | 6.5 | 1.1% | Apr 18, 2019 | A missing permission check in Jenkins XebiaLabs XL Deploy Plugin in the Credential#doValidateUserNamePassword form valid... |
| CVE-2019-10304 | — | — | 0.9% | Apr 18, 2019 | A cross-site request forgery vulnerability in Jenkins XebiaLabs XL Deploy Plugin in the Credential#doValidateUserNamePas... |
| CVE-2019-10303 | HIGH | 8.8 | 1.4% | Apr 18, 2019 | Jenkins Azure PublisherSettings Credentials Plugin 1.2 and earlier stored credentials unencrypted in the credentials.xml... |
| CVE-2019-10302 | HIGH | 8.8 | 1.4% | Apr 18, 2019 | Jenkins jira-ext Plugin 0.8 and earlier stored credentials unencrypted in its global configuration file on the Jenkins m... |
| CVE-2019-10301 | HIGH | 8.8 | 1.4% | Apr 18, 2019 | A missing permission check in Jenkins GitLab Plugin 1.5.11 and earlier in the GitLabConnectionConfig#doTestConnection fo... |
| CVE-2019-10300 | — | — | 1.4% | Apr 18, 2019 | A cross-site request forgery vulnerability in Jenkins GitLab Plugin 1.5.11 and earlier in the GitLabConnectionConfig#doT... |
| CVE-2019-1841 | MEDIUM | 6.5 | 2.6% | Apr 18, 2019 | A vulnerability in the Software Image Management feature of Cisco DNA Center could allow an authenticated, remote attack... |
| CVE-2019-1840 | HIGH | 8.6 | 2.4% | Apr 18, 2019 | A vulnerability in the DHCPv6 input packet processor of Cisco Prime Network Registrar could allow an unauthenticated, re... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now