2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-1003058 | — | — | 1.3% | Apr 4, 2019 | A cross-site request forgery vulnerability in Jenkins FTP publisher Plugin in the FTPPublisher.DescriptorImpl#doLoginChe... |
| CVE-2019-1003057 | HIGH | 8.8 | 1.4% | Apr 4, 2019 | Jenkins Bitbucket Approve Plugin stores credentials unencrypted in its global configuration file on the Jenkins master w... |
| CVE-2019-1003056 | HIGH | 8.8 | 1.4% | Apr 4, 2019 | Jenkins WebSphere Deployer Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where the... |
| CVE-2019-1003055 | HIGH | 8.8 | 1.4% | Apr 4, 2019 | Jenkins FTP publisher Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where... |
| CVE-2019-1003054 | HIGH | 8.8 | 1.4% | Apr 4, 2019 | Jenkins Jira Issue Updater Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where the... |
| CVE-2019-1003053 | HIGH | 8.8 | 1.4% | Apr 4, 2019 | Jenkins HockeyApp Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be ... |
| CVE-2019-1003052 | HIGH | 8.8 | 1.4% | Apr 4, 2019 | Jenkins AWS Elastic Beanstalk Publisher Plugin stores credentials unencrypted in its global configuration file on the Je... |
| CVE-2019-1003051 | HIGH | 8.8 | 1.4% | Apr 4, 2019 | Jenkins IRC Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can ... |
| CVE-2019-5022 | — | — | — | Apr 4, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: this candidate is not about any specific pr... |
| CVE-2019-10844 | — | — | 1.6% | Apr 4, 2019 | nbla/logger.cpp in libnnabla.a in Sony Neural Network Libraries (aka nnabla) through v1.0.14 relies on the HOME environm... |
| CVE-2019-10842 | — | — | 4.9% | Apr 4, 2019 | Arbitrary code execution (via backdoor code) was discovered in bootstrap-sass 3.2.0.3, when downloaded from rubygems.org... |
| CVE-2019-10723 | — | — | 1.0% | Apr 3, 2019 | An issue was discovered in PoDoFo 0.9.6. The PdfPagesTreeCache class in doc/PdfPagesTreeCache.cpp has an attempted exces... |
| CVE-2019-10240 | HIGH | 8.1 | 0.4% | Apr 3, 2019 | Eclipse hawkBit versions prior to 0.3.0M2 resolved Maven build artifacts for the Vaadin based UI over HTTP instead of HT... |
| CVE-2019-10268 | — | — | — | Apr 3, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2019-5423 | — | — | 2.8% | Apr 3, 2019 | Path traversal vulnerability in http-live-simulator npm package version 1.0.5 allows arbitrary path to be accessed on th... |
| CVE-2019-5422 | — | — | 1.2% | Apr 3, 2019 | XSS in buttle npm package version 0.2.0 causes execution of attacker-provided code in the victim's browser when an attac... |
| CVE-2019-5421 | CRITICAL | 9.8 | 1.6% | Apr 3, 2019 | Plataformatec Devise version 4.5.0 and earlier, using the lockable module contains a CWE-367 vulnerability in The `Devis... |
| CVE-2019-10261 | — | — | 2.4% | Apr 3, 2019 | CentOS Web Panel (CWP) 0.9.8.789 is vulnerable to Stored/Persistent XSS for the "Name Server 1" and "Name Server 2" fiel... |
| CVE-2019-4014 | HIGH | 7.8 | 0.5% | Apr 3, 2019 | IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer ov... |
| CVE-2019-10673 | — | — | 1.8% | Apr 3, 2019 | A CSRF vulnerability in a logged-in user's profile edit form in the Ultimate Member plugin before 2.0.40 for WordPress a... |
| CVE-2019-6506 | — | — | 1.7% | Apr 2, 2019 | SuiteCRM before 7.8.28, 7.9.x and 7.10.x before 7.10.15, and 7.11.x before 7.11.3 allows SQL Injection. |
| CVE-2019-10714 | MEDIUM | 6.5 | 1.9% | Apr 2, 2019 | LocaleLowercase in MagickCore/locale.c in ImageMagick before 7.0.8-32 allows out-of-bounds access, leading to a SIGSEGV. |
| CVE-2019-6531 | HIGH | 8.1 | 1.0% | Apr 2, 2019 | An attacker could retrieve passwords from a HTTP GET request from the Kunbus PR100088 Modbus gateway versions prior to R... |
| CVE-2019-10708 | — | — | 2.6% | Apr 2, 2019 | S-CMS PHP v1.0 has SQL injection via the 4/js/scms.php?action=unlike id parameter. |
| CVE-2019-10707 | — | — | 1.5% | Apr 2, 2019 | MKCMS V5.0 has SQL injection via the bplay.php play parameter. |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now