2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-1003058A cross-site request forgery vulnerability in Jenkins FTP publisher Plugin in the FTPPublisher.DescriptorImpl#doLoginChe...
CVE-2019-1003057HIGH8.8Jenkins Bitbucket Approve Plugin stores credentials unencrypted in its global configuration file on the Jenkins master w...
CVE-2019-1003056HIGH8.8Jenkins WebSphere Deployer Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where the...
CVE-2019-1003055HIGH8.8Jenkins FTP publisher Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where...
CVE-2019-1003054HIGH8.8Jenkins Jira Issue Updater Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where the...
CVE-2019-1003053HIGH8.8Jenkins HockeyApp Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be ...
CVE-2019-1003052HIGH8.8Jenkins AWS Elastic Beanstalk Publisher Plugin stores credentials unencrypted in its global configuration file on the Je...
CVE-2019-1003051HIGH8.8Jenkins IRC Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can ...
CVE-2019-5022Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: this candidate is not about any specific pr...
CVE-2019-10844nbla/logger.cpp in libnnabla.a in Sony Neural Network Libraries (aka nnabla) through v1.0.14 relies on the HOME environm...
CVE-2019-10842Arbitrary code execution (via backdoor code) was discovered in bootstrap-sass 3.2.0.3, when downloaded from rubygems.org...
CVE-2019-10723An issue was discovered in PoDoFo 0.9.6. The PdfPagesTreeCache class in doc/PdfPagesTreeCache.cpp has an attempted exces...
CVE-2019-10240HIGH8.1Eclipse hawkBit versions prior to 0.3.0M2 resolved Maven build artifacts for the Vaadin based UI over HTTP instead of HT...
CVE-2019-10268Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2019-5423Path traversal vulnerability in http-live-simulator npm package version 1.0.5 allows arbitrary path to be accessed on th...
CVE-2019-5422XSS in buttle npm package version 0.2.0 causes execution of attacker-provided code in the victim's browser when an attac...
CVE-2019-5421CRITICAL9.8Plataformatec Devise version 4.5.0 and earlier, using the lockable module contains a CWE-367 vulnerability in The `Devis...
CVE-2019-10261CentOS Web Panel (CWP) 0.9.8.789 is vulnerable to Stored/Persistent XSS for the "Name Server 1" and "Name Server 2" fiel...
CVE-2019-4014HIGH7.8IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer ov...
CVE-2019-10673A CSRF vulnerability in a logged-in user's profile edit form in the Ultimate Member plugin before 2.0.40 for WordPress a...
CVE-2019-6506SuiteCRM before 7.8.28, 7.9.x and 7.10.x before 7.10.15, and 7.11.x before 7.11.3 allows SQL Injection.
CVE-2019-10714MEDIUM6.5LocaleLowercase in MagickCore/locale.c in ImageMagick before 7.0.8-32 allows out-of-bounds access, leading to a SIGSEGV.
CVE-2019-6531HIGH8.1An attacker could retrieve passwords from a HTTP GET request from the Kunbus PR100088 Modbus gateway versions prior to R...
CVE-2019-10708S-CMS PHP v1.0 has SQL injection via the 4/js/scms.php?action=unlike id parameter.
CVE-2019-10707MKCMS V5.0 has SQL injection via the bplay.php play parameter.

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now