2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-7560In parser/btorsmt2.c in Boolector 3.0.0, opening a specially crafted input file leads to a use after free in get_failed_...
CVE-2019-7559In btor2parser/btor2parser.c in Boolector Btor2Tools before 2019-01-15, opening a specially crafted input file leads to ...
CVE-2019-7548HIGH7.8SQLAlchemy 1.2.17 has SQL Injection when the group_by parameter can be controlled.
CVE-2019-7547An issue was discovered in SIDU 6.0. Because the database name is not strictly filtered, the attacker can insert a name ...
CVE-2019-7546An issue was discovered in SIDU 6.0. The dbs parameter of the conn.php page has a reflected Cross-site Scripting (XSS) v...
CVE-2019-7545In DbNinja 3.2.7, the Add Host function of the Manage Hosts pages has a Stored Cross-site Scripting (XSS) vulnerability ...
CVE-2019-7544An issue was discovered in MyWebSQL 3.7. The Add User function of the User Manager pages has a Stored Cross-site Scripti...
CVE-2019-7543In KindEditor 4.1.11, the php/demo.php content1 parameter has a reflected Cross-site Scripting (XSS) vulnerability.
CVE-2019-6517MEDIUM6.8BD FACSLyric Research Use Only, Windows 10 Professional Operating System, U.S. and Malaysian Releases, between November ...
CVE-2019-3825MEDIUM6.3A vulnerability was discovered in gdm before 3.31.4. When timed login is enabled in configuration, an attacker could byp...
CVE-2019-3823MEDIUM4.3libcurl versions from 7.34.0 to before 7.64.0 are vulnerable to a heap out-of-bounds read in the code handling the end-o...
CVE-2019-3822CRITICAL9.8libcurl versions from 7.36.0 to before 7.64.0 are vulnerable to a stack-based buffer overflow. The function creating an ...
CVE-2019-3820MEDIUM4.3It was discovered that the gnome-shell lock screen since version 3.15.91 did not properly restrict all contextual action...
CVE-2019-3464CRITICAL9.8Insufficient sanitization of environment variables passed to rsync can bypass the restrictions imposed by rssh, a restri...
CVE-2019-3463CRITICAL9.8Insufficient sanitization of arguments passed to rsync can bypass the restrictions imposed by rssh, a restricted shell t...
CVE-2019-1003023A cross-site scripting vulnerability exists in Jenkins Warnings Next Generation Plugin 1.0.1 and earlier in src/main/jav...
CVE-2019-1003022A denial of service vulnerability exists in Jenkins Monitoring Plugin 1.74.0 and earlier in PluginImpl.java that allows ...
CVE-2019-1003021An exposure of sensitive information vulnerability exists in Jenkins OpenId Connect Authentication Plugin 1.4 and earlie...
CVE-2019-1003020A server-side request forgery vulnerability exists in Jenkins Kanboard Plugin 1.5.10 and earlier in KanboardGlobalConfig...
CVE-2019-1003019An session fixation vulnerability exists in Jenkins GitHub Authentication Plugin 0.29 and earlier in GithubSecurityRealm...
CVE-2019-1003018An exposure of sensitive information vulnerability exists in Jenkins GitHub Authentication Plugin 0.29 and earlier in Gi...
CVE-2019-1003017A data modification vulnerability exists in Jenkins Job Import Plugin 3.0 and earlier in JobImportAction.java that allow...
CVE-2019-1003016An exposure of sensitive information vulnerability exists in Jenkins Job Import Plugin 2.1 and earlier in src/main/java/...
CVE-2019-1003015An XML external entity processing vulnerability exists in Jenkins Job Import Plugin 2.1 and earlier in src/main/java/org...
CVE-2019-1003014An cross-site scripting vulnerability exists in Jenkins Config File Provider Plugin 3.4.1 and earlier in src/main/resour...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now