2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-10871 | — | — | 2.5% | Apr 5, 2019 | An issue was discovered in Poppler 0.74.0. There is a heap-based buffer over-read in the function PSOutputDev::checkPage... |
| CVE-2019-10868 | MEDIUM | 6.5 | 1.3% | Apr 5, 2019 | In trytond/model/modelstorage.py in Tryton 4.2 before 4.2.21, 4.4 before 4.4.19, 4.6 before 4.6.14, 4.8 before 4.8.10, a... |
| CVE-2019-6553 | CRITICAL | 9.8 | 50.0% | Apr 4, 2019 | A vulnerability was found in Rockwell Automation RSLinx Classic versions 4.10.00 and prior. An input validation issue in... |
| CVE-2019-10867 | — | — | 69.4% | Apr 4, 2019 | An issue was discovered in Pimcore before 5.7.1. An attacker with classes permission can send a POST request to /admin/c... |
| CVE-2019-10863 | — | — | 13.4% | Apr 4, 2019 | A command injection vulnerability exists in TeemIp versions before 2.4.0. The new_config parameter of exec.php allows on... |
| CVE-2019-7001 | CRITICAL | 9.9 | 1.2% | Apr 4, 2019 | A SQL injection vulnerability in the WebUI component of IP Office Contact Center could allow an authenticated attacker t... |
| CVE-2019-3886 | MEDIUM | 5.4 | 1.1% | Apr 4, 2019 | An incorrect permissions check was discovered in libvirt 4.8.0 and above. The readonly permission was allowed to invoke ... |
| CVE-2019-1828 | MEDIUM | 5.9 | 0.7% | Apr 4, 2019 | A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Route... |
| CVE-2019-1827 | MEDIUM | 6.1 | 1.3% | Apr 4, 2019 | A vulnerability in the Online Help web service of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers coul... |
| CVE-2019-10856 | — | — | 1.3% | Apr 4, 2019 | In Jupyter Notebook before 5.7.8, an open redirect can occur via an empty netloc. This issue exists because of an incomp... |
| CVE-2019-10299 | HIGH | 8.8 | 1.8% | Apr 4, 2019 | Jenkins CloudCoreo DeployTime Plugin stores credentials unencrypted in its global configuration file on the Jenkins mast... |
| CVE-2019-10298 | HIGH | 8.8 | 1.8% | Apr 4, 2019 | Jenkins Koji Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can... |
| CVE-2019-10297 | HIGH | 8.8 | 1.8% | Apr 4, 2019 | Jenkins Sametime Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they... |
| CVE-2019-10296 | HIGH | 8.8 | 1.8% | Apr 4, 2019 | Jenkins Serena SRA Deploy Plugin stores credentials unencrypted in its global configuration file on the Jenkins master w... |
| CVE-2019-10295 | HIGH | 8.8 | 1.8% | Apr 4, 2019 | Jenkins crittercism-dsym Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they ... |
| CVE-2019-10294 | HIGH | 8.8 | 1.8% | Apr 4, 2019 | Jenkins Kmap Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewe... |
| CVE-2019-10293 | MEDIUM | 6.5 | 1.5% | Apr 4, 2019 | A missing permission check in Jenkins Kmap Plugin in KmapJenkinsBuilder.DescriptorImpl form validation methods allows at... |
| CVE-2019-10292 | — | — | 1.3% | Apr 4, 2019 | A cross-site request forgery vulnerability in Jenkins Kmap Plugin in KmapJenkinsBuilder.DescriptorImpl form validation m... |
| CVE-2019-10291 | HIGH | 8.8 | 1.8% | Apr 4, 2019 | Jenkins Netsparker Cloud Scan Plugin 1.1.5 and older stored credentials unencrypted in its global configuration file on ... |
| CVE-2019-10290 | MEDIUM | 6.5 | 1.5% | Apr 4, 2019 | A missing permission check in Jenkins Netsparker Cloud Scan Plugin 1.1.5 and older in the NCScanBuilder.DescriptorImpl#d... |
| CVE-2019-10289 | — | — | 1.3% | Apr 4, 2019 | A cross-site request forgery vulnerability in Jenkins Netsparker Cloud Scan Plugin 1.1.5 and older in the NCScanBuilder.... |
| CVE-2019-10288 | HIGH | 8.8 | 1.8% | Apr 4, 2019 | Jenkins Jabber Server Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where... |
| CVE-2019-10287 | HIGH | 8.8 | 1.8% | Apr 4, 2019 | Jenkins youtrack-plugin Plugin 0.7.1 and older stored credentials unencrypted in its global configuration file on the Je... |
| CVE-2019-10286 | HIGH | 8.8 | 1.8% | Apr 4, 2019 | Jenkins DeployHub Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be ... |
| CVE-2019-10285 | HIGH | 8.8 | 1.8% | Apr 4, 2019 | Jenkins Minio Storage Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now