2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-6602 | — | — | 1.8% | Mar 28, 2019 | In BIG-IP 11.5.1-11.5.8 and 11.6.1-11.6.3, the Configuration Utility login page may not follow best security practices w... |
| CVE-2019-0224 | — | — | 5.1% | Mar 28, 2019 | In Apache JSPWiki 2.9.0 to 2.11.0.M2, a carefully crafted URL could execute javascript on another user's session. No inf... |
| CVE-2019-9167 | MEDIUM | 6.1 | 21.7% | Mar 28, 2019 | Cross-site scripting (XSS) vulnerability in Nagios XI before 5.5.11 allows attackers to inject arbitrary web script or H... |
| CVE-2019-9166 | HIGH | 7.8 | 1.2% | Mar 28, 2019 | Privilege escalation in Nagios XI before 5.5.11 allows local attackers to elevate privileges to root via write access to... |
| CVE-2019-9204 | CRITICAL | 9.8 | 19.7% | Mar 28, 2019 | SQL injection vulnerability in Nagios IM (component of Nagios XI) before 2.2.7 allows attackers to execute arbitrary SQL... |
| CVE-2019-9203 | CRITICAL | 9.8 | 20.4% | Mar 28, 2019 | Authorization bypass in Nagios IM (component of Nagios XI) before 2.2.7 allows closing incidents in IM via the API. |
| CVE-2019-9202 | HIGH | 8.8 | 24.2% | Mar 28, 2019 | Nagios IM (component of Nagios XI) before 2.2.7 allows authenticated users to execute arbitrary code via API key issues. |
| CVE-2019-9165 | CRITICAL | 9.8 | 5.3% | Mar 28, 2019 | SQL injection vulnerability in Nagios XI before 5.5.11 allows attackers to execute arbitrary SQL commands via the API wh... |
| CVE-2019-3710 | HIGH | 8.1 | 0.8% | Mar 28, 2019 | Dell EMC Networking OS10 versions prior to 10.4.3 contain a cryptographic key vulnerability due to an underlying applica... |
| CVE-2019-1003048 | HIGH | 7.8 | 0.3% | Mar 28, 2019 | A vulnerability in Jenkins PRQA Plugin 3.1.0 and earlier allows attackers with local file system access to the Jenkins h... |
| CVE-2019-1003047 | MEDIUM | 6.5 | 1.5% | Mar 28, 2019 | A missing permission check in Jenkins Fortify on Demand Uploader Plugin 3.0.10 and earlier allows attackers with Overall... |
| CVE-2019-1003046 | — | — | 1.3% | Mar 28, 2019 | A cross-site request forgery vulnerability in Jenkins Fortify on Demand Uploader Plugin 3.0.10 and earlier allows attack... |
| CVE-2019-1003045 | MEDIUM | 6.5 | 1.6% | Mar 28, 2019 | A vulnerability in Jenkins ECS Publisher Plugin 1.0.0 and earlier allows attackers with Item/Extended Read permission, o... |
| CVE-2019-1003044 | — | — | 1.1% | Mar 28, 2019 | A cross-site request forgery vulnerability in Jenkins Slack Notification Plugin 2.19 and earlier allows attackers to con... |
| CVE-2019-1003043 | HIGH | 7.5 | 1.5% | Mar 28, 2019 | A missing permission check in Jenkins Slack Notification Plugin 2.19 and earlier allows attackers with Overall/Read perm... |
| CVE-2019-1003042 | — | — | 1.4% | Mar 28, 2019 | A cross site scripting vulnerability in Jenkins Lockable Resources Plugin 2.4 and earlier allows attackers able to contr... |
| CVE-2019-1003041 | CRITICAL | 9.8 | 3.3% | Mar 28, 2019 | A sandbox bypass vulnerability in Jenkins Pipeline: Groovy Plugin 2.64 and earlier allows attackers to invoke arbitrary ... |
| CVE-2019-1003040 | CRITICAL | 9.8 | 3.3% | Mar 28, 2019 | A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.55 and earlier allows attackers to invoke arbitrary c... |
| CVE-2019-9164 | HIGH | 8.8 | 46.0% | Mar 28, 2019 | Command injection in Nagios XI before 5.5.11 allows an authenticated users to execute arbitrary remote commands via a ne... |
| CVE-2019-7251 | — | — | 3.8% | Mar 28, 2019 | An Integer Signedness issue (for a return code) in the res_pjsip_sdp_rtp module in Digium Asterisk versions 15.7.1 and e... |
| CVE-2019-5739 | HIGH | 7.5 | 5.1% | Mar 28, 2019 | Keep-alive HTTP and HTTPS connections can remain open and inactive for up to 2 minutes in Node.js 6.16.0 and earlier. No... |
| CVE-2019-5737 | HIGH | 7.5 | 16.2% | Mar 28, 2019 | In Node.js including 6.x before 6.17.0, 8.x before 8.15.1, 10.x before 10.15.2, and 11.x before 11.10.1, an attacker can... |
| CVE-2019-10260 | — | — | 0.9% | Mar 28, 2019 | Total.js CMS 12.0.0 has XSS related to themes/admin/views/index.html (item.message) and themes/admin/public/ui.js (colum... |
| CVE-2019-10255 | — | — | 1.7% | Mar 28, 2019 | An Open Redirect vulnerability for all browsers in Jupyter Notebook before 5.7.7 and some browsers (Chrome, Firefox) in ... |
| CVE-2019-5028 | — | — | — | Mar 28, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now