2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-5727 | — | — | 0.7% | Feb 21, 2019 | Splunk Web in Splunk Enterprise 6.5.x before 6.5.5, 6.4.x before 6.4.9, 6.3.x before 6.3.12, 6.2.x before 6.2.14, 6.1.x ... |
| CVE-2019-3475 | HIGH | 7.8 | 1.0% | Feb 20, 2019 | A local privilege escalation vulnerability in the famtd component of Micro Focus Filr 3.0 allows a local attacker authen... |
| CVE-2019-3474 | MEDIUM | 6.5 | 9.0% | Feb 20, 2019 | A path traversal vulnerability in the web application component of Micro Focus Filr 3.x allows a remote attacker authent... |
| CVE-2019-1003028 | — | — | 0.7% | Feb 20, 2019 | A server-side request forgery vulnerability exists in Jenkins JMS Messaging Plugin 1.1.1 and earlier in SSLCertificateAu... |
| CVE-2019-1003027 | — | — | 1.0% | Feb 20, 2019 | A server-side request forgery vulnerability exists in Jenkins OctopusDeploy Plugin 1.8.1 and earlier in OctopusDeployPlu... |
| CVE-2019-1003026 | — | — | 0.9% | Feb 20, 2019 | A server-side request forgery vulnerability exists in Jenkins Mattermost Notification Plugin 2.6.2 and earlier in Matter... |
| CVE-2019-1003025 | HIGH | 8.8 | 1.3% | Feb 20, 2019 | A exposure of sensitive information vulnerability exists in Jenkins Cloud Foundry Plugin 2.3.1 and earlier in AbstractCl... |
| CVE-2019-1003024 | HIGH | 8.8 | 3.0% | Feb 20, 2019 | A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.52 and earlier in RejectASTTransformsCustomize... |
| CVE-2019-3924 | HIGH | 7.5 | 15.7% | Feb 20, 2019 | MikroTik RouterOS before 6.43.12 (stable) and 6.42.12 (long-term) is vulnerable to an intermediary vulnerability. The so... |
| CVE-2019-8954 | — | — | 2.7% | Feb 20, 2019 | In Indexhibit 2.1.5, remote attackers can execute arbitrary code via the v parameter (in conjunction with the id paramet... |
| CVE-2019-8953 | — | — | 52.2% | Feb 20, 2019 | The HAProxy package before 0.59_16 for pfSense has XSS via the desc (aka Description) or table_actionsaclN parameter, re... |
| CVE-2019-8331 | MEDIUM | 6.1 | 16.9% | Feb 20, 2019 | In Bootstrap before 3.4.1 and 4.3.x before 4.3.1, XSS is possible in the tooltip or popover data-template attribute. |
| CVE-2019-8950 | — | — | 2.6% | Feb 20, 2019 | The backdoor account dnsekakf2$$ in /bin/login on DASAN H665 devices with firmware 1.46p1-0028 allows an attacker to log... |
| CVE-2019-8948 | — | — | 3.9% | Feb 20, 2019 | PaperCut MF before 18.3.6 and PaperCut NG before 18.3.6 allow script injection via the user interface, aka PC-15163. |
| CVE-2019-8944 | — | — | 1.5% | Feb 20, 2019 | An Information Exposure issue in the Terraform deployment step in Octopus Deploy before 2019.1.8 (and before 2018.10.4 L... |
| CVE-2019-8943 | MEDIUM | 6.5 | 92.0% | Feb 20, 2019 | WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An attacker (who has privileges to crop an image) can ... |
| CVE-2019-8942 | — | — | 82.7% | Feb 20, 2019 | WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry ca... |
| CVE-2019-7164 | CRITICAL | 9.8 | 3.5% | Feb 20, 2019 | SQLAlchemy through 1.2.17 and 1.3.x through 1.3.0b2 allows SQL Injection via the order_by parameter. |
| CVE-2019-5783 | — | — | 1.1% | Feb 19, 2019 | Missing URI encoding of untrusted input in DevTools in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to ... |
| CVE-2019-5782 | — | — | 12.9% | Feb 19, 2019 | Incorrect optimization assumptions in V8 in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to execute arb... |
| CVE-2019-5781 | — | — | 1.5% | Feb 19, 2019 | Incorrect handling of a confusable character in Omnibox in Google Chrome prior to 72.0.3626.81 allowed a remote attacker... |
| CVE-2019-5780 | — | — | 0.3% | Feb 19, 2019 | Insufficient restrictions on what can be done with Apple Events in Google Chrome on macOS prior to 72.0.3626.81 allowed ... |
| CVE-2019-5779 | — | — | 2.6% | Feb 19, 2019 | Insufficient policy validation in ServiceWorker in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to bypa... |
| CVE-2019-5778 | — | — | 1.0% | Feb 19, 2019 | A missing case for handling special schemes in permission request checks in Extensions in Google Chrome prior to 72.0.36... |
| CVE-2019-5777 | — | — | 1.5% | Feb 19, 2019 | Incorrect handling of a confusable character in Omnibox in Google Chrome prior to 72.0.3626.81 allowed a remote attacker... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now