2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-6602In BIG-IP 11.5.1-11.5.8 and 11.6.1-11.6.3, the Configuration Utility login page may not follow best security practices w...
CVE-2019-0224In Apache JSPWiki 2.9.0 to 2.11.0.M2, a carefully crafted URL could execute javascript on another user's session. No inf...
CVE-2019-9167MEDIUM6.1Cross-site scripting (XSS) vulnerability in Nagios XI before 5.5.11 allows attackers to inject arbitrary web script or H...
CVE-2019-9166HIGH7.8Privilege escalation in Nagios XI before 5.5.11 allows local attackers to elevate privileges to root via write access to...
CVE-2019-9204CRITICAL9.8SQL injection vulnerability in Nagios IM (component of Nagios XI) before 2.2.7 allows attackers to execute arbitrary SQL...
CVE-2019-9203CRITICAL9.8Authorization bypass in Nagios IM (component of Nagios XI) before 2.2.7 allows closing incidents in IM via the API.
CVE-2019-9202HIGH8.8Nagios IM (component of Nagios XI) before 2.2.7 allows authenticated users to execute arbitrary code via API key issues.
CVE-2019-9165CRITICAL9.8SQL injection vulnerability in Nagios XI before 5.5.11 allows attackers to execute arbitrary SQL commands via the API wh...
CVE-2019-3710HIGH8.1Dell EMC Networking OS10 versions prior to 10.4.3 contain a cryptographic key vulnerability due to an underlying applica...
CVE-2019-1003048HIGH7.8A vulnerability in Jenkins PRQA Plugin 3.1.0 and earlier allows attackers with local file system access to the Jenkins h...
CVE-2019-1003047MEDIUM6.5A missing permission check in Jenkins Fortify on Demand Uploader Plugin 3.0.10 and earlier allows attackers with Overall...
CVE-2019-1003046A cross-site request forgery vulnerability in Jenkins Fortify on Demand Uploader Plugin 3.0.10 and earlier allows attack...
CVE-2019-1003045MEDIUM6.5A vulnerability in Jenkins ECS Publisher Plugin 1.0.0 and earlier allows attackers with Item/Extended Read permission, o...
CVE-2019-1003044A cross-site request forgery vulnerability in Jenkins Slack Notification Plugin 2.19 and earlier allows attackers to con...
CVE-2019-1003043HIGH7.5A missing permission check in Jenkins Slack Notification Plugin 2.19 and earlier allows attackers with Overall/Read perm...
CVE-2019-1003042A cross site scripting vulnerability in Jenkins Lockable Resources Plugin 2.4 and earlier allows attackers able to contr...
CVE-2019-1003041CRITICAL9.8A sandbox bypass vulnerability in Jenkins Pipeline: Groovy Plugin 2.64 and earlier allows attackers to invoke arbitrary ...
CVE-2019-1003040CRITICAL9.8A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.55 and earlier allows attackers to invoke arbitrary c...
CVE-2019-9164HIGH8.8Command injection in Nagios XI before 5.5.11 allows an authenticated users to execute arbitrary remote commands via a ne...
CVE-2019-7251An Integer Signedness issue (for a return code) in the res_pjsip_sdp_rtp module in Digium Asterisk versions 15.7.1 and e...
CVE-2019-5739HIGH7.5Keep-alive HTTP and HTTPS connections can remain open and inactive for up to 2 minutes in Node.js 6.16.0 and earlier. No...
CVE-2019-5737HIGH7.5In Node.js including 6.x before 6.17.0, 8.x before 8.15.1, 10.x before 10.15.2, and 11.x before 11.10.1, an attacker can...
CVE-2019-10260Total.js CMS 12.0.0 has XSS related to themes/admin/views/index.html (item.message) and themes/admin/public/ui.js (colum...
CVE-2019-10255An Open Redirect vulnerability for all browsers in Jupyter Notebook before 5.7.7 and some browsers (Chrome, Firefox) in ...
CVE-2019-5028Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now