2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-10871An issue was discovered in Poppler 0.74.0. There is a heap-based buffer over-read in the function PSOutputDev::checkPage...
CVE-2019-10868MEDIUM6.5In trytond/model/modelstorage.py in Tryton 4.2 before 4.2.21, 4.4 before 4.4.19, 4.6 before 4.6.14, 4.8 before 4.8.10, a...
CVE-2019-6553CRITICAL9.8A vulnerability was found in Rockwell Automation RSLinx Classic versions 4.10.00 and prior. An input validation issue in...
CVE-2019-10867An issue was discovered in Pimcore before 5.7.1. An attacker with classes permission can send a POST request to /admin/c...
CVE-2019-10863A command injection vulnerability exists in TeemIp versions before 2.4.0. The new_config parameter of exec.php allows on...
CVE-2019-7001CRITICAL9.9A SQL injection vulnerability in the WebUI component of IP Office Contact Center could allow an authenticated attacker t...
CVE-2019-3886MEDIUM5.4An incorrect permissions check was discovered in libvirt 4.8.0 and above. The readonly permission was allowed to invoke ...
CVE-2019-1828MEDIUM5.9A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Route...
CVE-2019-1827MEDIUM6.1A vulnerability in the Online Help web service of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers coul...
CVE-2019-10856In Jupyter Notebook before 5.7.8, an open redirect can occur via an empty netloc. This issue exists because of an incomp...
CVE-2019-10299HIGH8.8Jenkins CloudCoreo DeployTime Plugin stores credentials unencrypted in its global configuration file on the Jenkins mast...
CVE-2019-10298HIGH8.8Jenkins Koji Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can...
CVE-2019-10297HIGH8.8Jenkins Sametime Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they...
CVE-2019-10296HIGH8.8Jenkins Serena SRA Deploy Plugin stores credentials unencrypted in its global configuration file on the Jenkins master w...
CVE-2019-10295HIGH8.8Jenkins crittercism-dsym Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they ...
CVE-2019-10294HIGH8.8Jenkins Kmap Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewe...
CVE-2019-10293MEDIUM6.5A missing permission check in Jenkins Kmap Plugin in KmapJenkinsBuilder.DescriptorImpl form validation methods allows at...
CVE-2019-10292A cross-site request forgery vulnerability in Jenkins Kmap Plugin in KmapJenkinsBuilder.DescriptorImpl form validation m...
CVE-2019-10291HIGH8.8Jenkins Netsparker Cloud Scan Plugin 1.1.5 and older stored credentials unencrypted in its global configuration file on ...
CVE-2019-10290MEDIUM6.5A missing permission check in Jenkins Netsparker Cloud Scan Plugin 1.1.5 and older in the NCScanBuilder.DescriptorImpl#d...
CVE-2019-10289A cross-site request forgery vulnerability in Jenkins Netsparker Cloud Scan Plugin 1.1.5 and older in the NCScanBuilder....
CVE-2019-10288HIGH8.8Jenkins Jabber Server Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where...
CVE-2019-10287HIGH8.8Jenkins youtrack-plugin Plugin 0.7.1 and older stored credentials unencrypted in its global configuration file on the Je...
CVE-2019-10286HIGH8.8Jenkins DeployHub Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be ...
CVE-2019-10285HIGH8.8Jenkins Minio Storage Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now