2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-16568 | MEDIUM | 5.3 | 0.6% | Dec 17, 2019 | Jenkins SCTMExecutor Plugin 2.2 and earlier transmits previously configured service credentials in plain text as part of... |
| CVE-2019-16567 | MEDIUM | 4.3 | 0.6% | Dec 17, 2019 | A missing permission check in Jenkins Team Concert Plugin 1.3.0 and earlier in form-related methods allowed users with O... |
| CVE-2019-16566 | MEDIUM | 6.5 | 0.8% | Dec 17, 2019 | A missing permission check in Jenkins Team Concert Plugin 1.3.0 and earlier allows attackers with Overall/Read permissio... |
| CVE-2019-16564 | MEDIUM | 5.4 | 0.7% | Dec 17, 2019 | Jenkins Pipeline Aggregator View Plugin 1.8 and earlier does not escape information shown on its view, resulting in a st... |
| CVE-2019-16563 | MEDIUM | 5.4 | 0.7% | Dec 17, 2019 | Jenkins Mission Control Plugin 0.9.16 and earlier does not escape job display names and build names shown on its view, r... |
| CVE-2019-16562 | MEDIUM | 5.4 | 0.7% | Dec 17, 2019 | Jenkins buildgraph-view Plugin 1.8 and earlier does not escape the description of builds shown in its view, resulting in... |
| CVE-2019-16559 | MEDIUM | 5.4 | 0.7% | Dec 17, 2019 | A missing permission check in Jenkins WebSphere Deployer Plugin 1.6.1 and earlier allows attackers with Overall/Read per... |
| CVE-2019-16557 | MEDIUM | 6.5 | 0.9% | Dec 17, 2019 | Jenkins Redgate SQL Change Automation Plugin 2.0.3 and earlier stores credentials unencrypted in job config.xml files on... |
| CVE-2019-16556 | MEDIUM | 6.5 | 0.9% | Dec 17, 2019 | Jenkins Rundeck Plugin 3.6.5 and earlier stores credentials unencrypted in its global configuration file and in job conf... |
| CVE-2019-16555 | MEDIUM | 6.5 | 1.1% | Dec 17, 2019 | A user-supplied regular expression in Jenkins Build Failure Analyzer Plugin 1.24.1 and earlier was processed in a way th... |
| CVE-2019-16554 | MEDIUM | 4.3 | 0.8% | Dec 17, 2019 | A missing permission check in Jenkins Build Failure Analyzer Plugin 1.24.1 and earlier allows attackers with Overall/Rea... |
| CVE-2019-16552 | MEDIUM | 5.4 | 0.6% | Dec 17, 2019 | A missing permission check in Jenkins Gerrit Trigger Plugin 2.30.1 and earlier allows attackers with Overall/Read permis... |
| CVE-2019-19712 | MEDIUM | 5.3 | 0.9% | Dec 17, 2019 | Contao 4.0 through 4.8.5 has Insecure Permissions. Back end users can manipulate the details view URL to show pages and ... |
| CVE-2019-18833 | MEDIUM | 5.9 | 0.4% | Dec 17, 2019 | Barco ClickShare Button R9861500D01 devices before 1.9.0 allow Information exposure (issue 2 of 2).. The encryption key ... |
| CVE-2019-18824 | MEDIUM | 6.6 | 0.3% | Dec 17, 2019 | Barco ClickShare Button R9861500D01 devices before 1.10.0.13 have Missing Support for Integrity Check. The ClickShare Bu... |
| CVE-2019-19815 | MEDIUM | 5.5 | 2.1% | Dec 17, 2019 | In the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can cause a NULL pointer dereference in f2fs_recove... |
| CVE-2019-19813 | MEDIUM | 5.5 | 2.2% | Dec 17, 2019 | In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image, performing some operations, and then making a syn... |
| CVE-2019-19830 | MEDIUM | 6.5 | 1.3% | Dec 17, 2019 | _core_/plugins/medias in SPIP 3.2.x before 3.2.7 allows remote authenticated authors to inject content into the database... |
| CVE-2019-15011 | MEDIUM | 4.3 | 0.9% | Dec 17, 2019 | The ListEntityLinksServlet resource in Application Links before version 5.0.12, from version 5.1.0 before version 5.2.11... |
| CVE-2019-5259 | MEDIUM | 6.5 | 0.6% | Dec 16, 2019 | There is an information leakage vulnerability on some Huawei products(AR120-S;AR1200;AR1200-S;AR150;AR150-S;AR160;AR200;... |
| CVE-2019-12414 | MEDIUM | 5.3 | 2.7% | Dec 16, 2019 | In Apache Incubator Superset before 0.32, a user can view database names that he has no access to on a dropdown list in ... |
| CVE-2019-12413 | MEDIUM | 5.3 | 2.8% | Dec 16, 2019 | In Apache Incubator Superset before 0.31 user could query database metadata information from a database he has no access... |
| CVE-2019-19818 | MEDIUM | 5.5 | 1.2% | Dec 16, 2019 | The JBIG2Decode library in npdf.dll in Nitro Free PDF Reader 12.0.0.112 has a CAPPDAnnotHandlerUtils::PDAnnotHandlerDest... |
| CVE-2019-13182 | MEDIUM | 5.4 | 6.4% | Dec 16, 2019 | A stored cross-site scripting (XSS) vulnerability exists in the web UI of SolarWinds Serv-U FTP Server 15.1.7. |
| CVE-2019-13181 | MEDIUM | 6.5 | 3.2% | Dec 16, 2019 | A CSV injection vulnerability exists in the web UI of SolarWinds Serv-U FTP Server v15.1.7. |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now