2019 CVE Vulnerabilities

17,624 CVEs published in 2019.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2019-19745HIGH8.8Contao 4.0 through 4.8.5 allows PHP local file inclusion. A back end user with access to the form generator can upload a...
CVE-2019-19675HIGH7.8In Ivanti Workspace Control before 10.3.180.0. a locally authenticated user with low privileges can bypass Managed Appli...
CVE-2019-19315HIGH7.1NLSSRV32.EXE in Nalpeiron Licensing Service 7.3.4.0, as used with Nitro PDF and other products, allows Elevation of Priv...
CVE-2019-16575HIGH8.8A cross-site request forgery vulnerability in Jenkins Alauda Kubernetes Suport Plugin 2.3.0 and earlier allows attackers...
CVE-2019-16573HIGH8.8A cross-site request forgery vulnerability in Jenkins Alauda DevOps Pipeline Plugin 2.3.2 and earlier allows attackers t...
CVE-2019-16570HIGH8.8A cross-site request forgery vulnerability in Jenkins RapidDeploy Plugin 4.1 and earlier allows attackers to connect to ...
CVE-2019-16565HIGH8.8A cross-site request forgery vulnerability in Jenkins Team Concert Plugin 1.3.0 and earlier allows attackers to connect ...
CVE-2019-16561HIGH7.1Jenkins WebSphere Deployer Plugin 1.6.1 and earlier allows users with Overall/Read access to disable SSL/TLS certificate...
CVE-2019-16560HIGH8.8A cross-site request forgery vulnerability in Jenkins WebSphere Deployer Plugin 1.6.1 and earlier allows attackers to pe...
CVE-2019-16558HIGH8.2Jenkins Spira Importer Plugin 3.2.3 and earlier disables SSL/TLS certificate validation for the Jenkins master JVM.
CVE-2019-16553HIGH8.8A cross-site request forgery vulnerability in Jenkins Build Failure Analyzer Plugin 1.24.1 and earlier allows attackers ...
CVE-2019-16551HIGH8.8A cross-site request forgery vulnerability in Jenkins Gerrit Trigger Plugin 2.30.1 and earlier allows attackers to conne...
CVE-2019-16550HIGH8.8A cross-site request forgery vulnerability in a connection test form method in Jenkins Maven Release Plugin 0.16.1 and e...
CVE-2019-16549HIGH8.1Jenkins Maven Release Plugin 0.16.1 and earlier does not configure the XML parser to prevent XML external entity (XXE) a...
CVE-2019-19264HIGH7.5In Simplifile RecordFusion through 2019-11-25, the logs and hist parameters allow remote attackers to access local files...
CVE-2019-18832HIGH8.1Barco ClickShare Button R9861500D01 devices before 1.9.0 have incorrect Credentials Management. The ClickShare Button im...
CVE-2019-18829HIGH7.8Barco ClickShare Button R9861500D01 devices before 1.10.0.13 have Missing Support for Integrity Check. The Barco signed ...
CVE-2019-18825HIGH7.5Barco ClickShare Huddle CS-100 devices before 1.9.0 and CSE-200 devices before 1.9.0 have incorrect Credentials Manageme...
CVE-2019-19816HIGH7.8In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image and performing some operations can cause slab-out-...
CVE-2019-19814HIGH7.8In the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can cause __remove_dirty_segment slab-out-of-bounds...
CVE-2019-18191HIGH8.8A privilege escalation vulnerability in the Trend Micro Deep Security as a Service Quick Setup cloud formation template ...
CVE-2019-14610HIGH7.8Improper access control in firmware for Intel(R) NUC(R) may allow an authenticated user to potentially enable escalation...
CVE-2019-14608HIGH7.8Improper buffer restrictions in firmware for Intel(R) NUC(R) may allow an authenticated user to potentially enable escal...
CVE-2019-14605HIGH7.8Improper permissions in the installer for the Intel(R) SCS Platform Discovery Utility, all versions, may allow an authen...
CVE-2019-14603HIGH7.8Improper permissions in the installer for the License Server software for Intel® Quartus® Prime Pro Edition before versi...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now