2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-1003035MEDIUM4.3An information exposure vulnerability exists in Jenkins Azure VM Agents Plugin 0.8.0 and earlier in src/main/java/com/mi...
CVE-2019-1003034CRITICAL9.9A sandbox bypass vulnerability exists in Jenkins Job DSL Plugin 1.71 and earlier in job-dsl-core/src/main/groovy/javapos...
CVE-2019-1003033HIGH8.8A sandbox bypass vulnerability exists in Jenkins Groovy Plugin 2.1 and earlier in pom.xml, src/main/java/hudson/plugins/...
CVE-2019-1003032CRITICAL9.9A sandbox bypass vulnerability exists in Jenkins Email Extension Plugin 2.64 and earlier in pom.xml, src/main/java/hudso...
CVE-2019-1003031CRITICAL9.9A sandbox bypass vulnerability exists in Jenkins Matrix Project Plugin 1.13 and earlier in pom.xml, src/main/java/hudson...
CVE-2019-1003030CRITICAL9.9A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/...
CVE-2019-1003029CRITICAL9.9A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.53 and earlier in src/main/java/org/jenkinsci/...
CVE-2019-5015HIGH7.8A local privilege escalation vulnerability exists in the Mac OS X version of Pixar Renderman 22.3.0's Install Helper hel...
CVE-2019-1609MEDIUM6.7A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary com...
CVE-2019-1608MEDIUM6.7A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary com...
CVE-2019-1607MEDIUM6.7A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary com...
CVE-2019-1606HIGH7.8A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary com...
CVE-2019-1605HIGH7.8A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, local attacker to execute ar...
CVE-2019-9627HIGH7A buffer overflow in the kernel driver CybKernelTracker.sys in CyberArk Endpoint Privilege Manager versions prior to 10....
CVE-2019-1604HIGH7.8A vulnerability in the user account management interface of Cisco NX-OS Software could allow an authenticated, local att...
CVE-2019-1603HIGH7.8A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to escalate lower-level ...
CVE-2019-1602HIGH7.8A vulnerability in the filesystem permissions of Cisco NX-OS Software could allow an authenticated, local attacker to ac...
CVE-2019-1601HIGH7.8A vulnerability in the filesystem permissions of Cisco NX-OS Software could allow an authenticated, local attacker to ga...
CVE-2019-3780HIGH8.8Cloud Foundry Container Runtime, versions prior to 0.28.0, deploys K8s worker nodes that contains a configuration file w...
CVE-2019-3779HIGH8.8Cloud Foundry Container Runtime, versions prior to 0.29.0, deploys Kubernetes clusters utilize the same CA (Certificate ...
CVE-2019-9634HIGH7.8Go through 1.12 on Windows misuses certain LoadLibrary functionality, leading to DLL injection.
CVE-2019-9633gio/gsocketclient.c in GNOME GLib 2.59.2 does not ensure that a parent GTask remains alive during the execution of a con...
CVE-2019-9632ESAFENET CDG V3 and V5 has an arbitrary file download vulnerability via the fileName parameter in download.jsp because t...
CVE-2019-9631Poppler 0.74.0 has a heap-based buffer over-read in the CairoRescaleBox.cc downsample_row_box_filter function.
CVE-2019-9598An issue was discovered in Cscms 4.1.0. There is an admin.php/pay CSRF vulnerability that can change the payment account...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now