2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-3719HIGH8Dell SupportAssist Client versions prior to 3.2.0.90 contain a remote code execution vulnerability. An unauthenticated a...
CVE-2019-3718HIGH8.8Dell SupportAssist Client versions prior to 3.2.0.90 contain an improper origin validation vulnerability. An unauthentic...
CVE-2019-10893CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.793 (Free/Open Source Version) and 0.9.8.753 (Pro) is vulnerable to...
CVE-2019-11084GAuth 0.9.9 beta has stored XSS that shows a popup repeatedly and discloses cookies.
CVE-2019-9005The Cprime Power Scripts app before 4.0.14 for Atlassian Jira allows Directory Traversal.
CVE-2019-3885LOW3.3A use-after-free flaw was found in pacemaker up to and including version 2.0.1 which could result in certain sensitive i...
CVE-2019-3398HIGH8.8Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote at...
CVE-2019-11223An Unrestricted File Upload Vulnerability in the SupportCandy plugin through 2.0.0 for WordPress allows remote attackers...
CVE-2019-11017MEDIUM4.8On D-Link DI-524 V2.06RU devices, multiple Stored and Reflected XSS vulnerabilities were found in the Web Configuration:...
CVE-2019-8999An XML External Entity vulnerability in the UEM Core of BlackBerry UEM version(s) earlier than 12.10.1a could allow an a...
CVE-2019-11322An issue was discovered in Motorola CX2 1.01 and M2 1.01. There is a command injection in the function startRmtAssist in...
CVE-2019-11321An issue was discovered in Motorola CX2 1.01 and M2 1.01. The router opens TCP port 8010. Users can send hnap requests t...
CVE-2019-11320In Motorola CX2 1.01 and M2 1.01, users can access the router's /priv_mgt.html web page to launch telnetd, as demonstrat...
CVE-2019-11319An issue was discovered in Motorola CX2 1.01 and M2 1.01. There is a command injection in the function downloadFirmware ...
CVE-2019-11035CRITICAL9.1When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.28, 7.2.x below 7.2.17 and 7.3.x below 7.3...
CVE-2019-11034CRITICAL9.1When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.28, 7.2.x below 7.2.17 and 7.3.x below 7.3...
CVE-2019-10306CRITICAL9.9A sandbox bypass vulnerability in Jenkins ontrack Plugin 3.4 and earlier allowed attackers with control over ontrack DSL...
CVE-2019-10305MEDIUM6.5A missing permission check in Jenkins XebiaLabs XL Deploy Plugin in the Credential#doValidateUserNamePassword form valid...
CVE-2019-10304A cross-site request forgery vulnerability in Jenkins XebiaLabs XL Deploy Plugin in the Credential#doValidateUserNamePas...
CVE-2019-10303HIGH8.8Jenkins Azure PublisherSettings Credentials Plugin 1.2 and earlier stored credentials unencrypted in the credentials.xml...
CVE-2019-10302HIGH8.8Jenkins jira-ext Plugin 0.8 and earlier stored credentials unencrypted in its global configuration file on the Jenkins m...
CVE-2019-10301HIGH8.8A missing permission check in Jenkins GitLab Plugin 1.5.11 and earlier in the GitLabConnectionConfig#doTestConnection fo...
CVE-2019-10300A cross-site request forgery vulnerability in Jenkins GitLab Plugin 1.5.11 and earlier in the GitLabConnectionConfig#doT...
CVE-2019-1841MEDIUM6.5A vulnerability in the Software Image Management feature of Cisco DNA Center could allow an authenticated, remote attack...
CVE-2019-1840HIGH8.6A vulnerability in the DHCPv6 input packet processor of Cisco Prime Network Registrar could allow an unauthenticated, re...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now