Skip to main content

Year archive

CVEs published in 2019

Archive summary

17,305 CVEs published in 2019 — 2,593 Critical, 7,142 High, 7,228 Medium, 342 Low, 0 Unrated.

CVE-2018-1000424

Published Jan 9, 2019

An insufficiently protected credentials vulnerability exists in Jenkins Artifactory Plugin 2.16.1 and earlier in ArtifactoryBuilder.java, CredentialsConfig.java that allows attack…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1000423

Published Jan 9, 2019

An insufficiently protected credentials vulnerability exists in Jenkins Crowd 2 Integration Plugin 2.0.0 and earlier in CrowdSecurityRealm.java, CrowdConfigurationService.java tha…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1000422

Published Jan 9, 2019

An improper authorization vulnerability exists in Jenkins Crowd 2 Integration Plugin 2.0.0 and earlier in CrowdSecurityRealm.java that allows attackers to have Jenkins perform a c…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000421

Published Jan 9, 2019

An improper authorization vulnerability exists in Jenkins Mesos Plugin 0.17.1 and earlier in MesosCloud.java that allows attackers with Overall/Read access to initiate a test conn…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000420

Published Jan 9, 2019

An improper authorization vulnerability exists in Jenkins Mesos Plugin 0.17.1 and earlier in MesosCloud.java that allows attackers with Overall/Read access to obtain credentials I…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000419

Published Jan 9, 2019

An improper authorization vulnerability exists in Jenkins HipChat Plugin 2.2.0 and earlier in HipChatNotifier.java that allows attackers with Overall/Read access to obtain credent…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000418

Published Jan 9, 2019

An improper authorization vulnerability exists in Jenkins HipChat Plugin 2.2.0 and earlier in HipChatNotifier.java that allows attackers with Overall/Read access to send test noti…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1000417

Published Jan 9, 2019

A cross-site request forgery vulnerability exists in Jenkins Email Extension Template Plugin 1.0 and earlier in ExtEmailTemplateManagement.java that allows creating or removing te…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1000415

Published Jan 9, 2019

A cross-site scripting vulnerability exists in Jenkins Rebuilder Plugin 1.28 and earlier in RebuildAction/BooleanParameterValue.jelly, RebuildAction/ExtendedChoiceParameterValue.j…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000414

Published Jan 9, 2019

A cross-site request forgery vulnerability exists in Jenkins Config File Provider Plugin 3.1 and earlier in ConfigFilesManagement.java, FolderConfigFileAction.java that allows cre…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1000413

Published Jan 9, 2019

A cross-site scripting vulnerability exists in Jenkins Config File Provider Plugin 3.1 and earlier in configfiles.jelly, providerlist.jelly that allows users with the ability to c…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000412

Published Jan 9, 2019

An improper authorization vulnerability exists in Jenkins Jira Plugin 3.0.1 and earlier in JiraSite.java that allows attackers with Overall/Read access to have Jenkins connect to…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1000411

Published Jan 9, 2019

A cross-site request forgery vulnerability exists in Jenkins JUnit Plugin 1.25 and earlier in TestObject.java that allows setting the description of a test result.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000410

Published Jan 9, 2019

An information exposure vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier, and the Stapler framework used by these releases, in core/src/main/java/org/koh…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1000409

Published Jan 9, 2019

A session fixation vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/hudson/security/HudsonPrivateSecurityRealm.java that prevented…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000408

Published Jan 9, 2019

A denial of service vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/hudson/security/HudsonPrivateSecurityRealm.java that allows at…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000407

Published Jan 9, 2019

A cross-site scripting vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/hudson/model/Api.java that allows attackers to specify URLs…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000406

Published Jan 9, 2019

A path traversal vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/hudson/model/FileParameterValue.java that allows attackers with J…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-0705

Published Jan 9, 2019

Directory traversal vulnerability in Cybozu Dezie 8.0.2 to 8.1.2 allows remote attackers to read arbitrary files via HTTP requests.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-0704

Published Jan 9, 2019

Directory traversal vulnerability in Cybozu Office 10.0.0 to 10.8.1 allows remote attackers to delete arbitrary files via Keitai Screen.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-0703

Published Jan 9, 2019

Directory traversal vulnerability in Cybozu Office 10.0.0 to 10.8.1 allows remote attackers to delete arbitrary files via HTTP requests.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-0702

Published Jan 9, 2019

Directory traversal vulnerability in Cybozu Mailwise 5.0.0 to 5.4.5 allows remote attackers to delete arbitrary files via unspecified vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-0698

Published Jan 9, 2019

Cross-site scripting vulnerability in GROWI v3.2.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 16,976-17,000 of 17,305 CVEsPage 680 of 693