2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-13123 | HIGH | 7.5 | 1.3% | Sep 30, 2019 | Foxit Reader 9.6.0.25114 and earlier has two unique RecursiveCall bugs involving 3 functions exhausting available stack ... |
| CVE-2019-17050 | HIGH | 7.2 | 1.3% | Sep 30, 2019 | An issue was discovered in the Voyager package through 1.2.7 for Laravel. An attacker with admin privileges and Compass ... |
| CVE-2019-17049 | HIGH | 7.5 | 1.1% | Sep 30, 2019 | NETGEAR SRX5308 4.3.5-3 devices allow SQL Injection, as exploited in the wild in September 2019 to add a new user accoun... |
| CVE-2019-16276 | HIGH | 7.5 | 5.2% | Sep 30, 2019 | Go before 1.12.10 and 1.13.x before 1.13.1 allow HTTP Request Smuggling. |
| CVE-2019-13466 | HIGH | 7.5 | 0.7% | Sep 30, 2019 | Western Digital SSD Dashboard before 2.5.1.0 and SanDisk SSD Dashboard before 2.5.1.0 have Incorrect Access Control. The... |
| CVE-2019-2341 | HIGH | 7.8 | 0.2% | Sep 30, 2019 | Buffer overflow when the audio buffer size provided by user is larger than the maximum allowable audio buffer size. in S... |
| CVE-2019-2333 | HIGH | 7.8 | 0.2% | Sep 30, 2019 | Buffer overflow due to improper validation of buffer size while IPA driver processing to perform read operation in Snapd... |
| CVE-2019-2284 | HIGH | 7 | 0.1% | Sep 30, 2019 | Possible use-after-free issue due to a race condition while calling camera ioctl concurrently in Snapdragon Compute, Sna... |
| CVE-2019-10510 | HIGH | 8.2 | 0.7% | Sep 30, 2019 | BT process died and BT toggled due to null pointer dereference when invalid vendor pass through command sent from remote... |
| CVE-2019-10508 | HIGH | 7.8 | 0.2% | Sep 30, 2019 | Lack of input validation for data received from user space can lead to OOB access in WLAN in Snapdragon Auto, Snapdragon... |
| CVE-2019-10507 | HIGH | 7.8 | 0.2% | Sep 30, 2019 | Lack of check of extscan change results received from firmware can lead to an out of buffer read in Snapdragon Auto, Sna... |
| CVE-2019-10506 | HIGH | 7.8 | 0.2% | Sep 30, 2019 | While processing QCA_NL80211_VENDOR_SUBCMD_AVOID_FREQUENCY vendor command, driver does not validate the data obtained fr... |
| CVE-2019-10501 | HIGH | 7.8 | 0.2% | Sep 30, 2019 | Possible use after free issue due to improper input validation in volume listener library in Snapdragon Auto, Snapdragon... |
| CVE-2019-10499 | HIGH | 7.8 | 0.2% | Sep 30, 2019 | Improper validation of read and write index of tx and rx fifo`s before using for data copy from fifo can lead to out-of-... |
| CVE-2019-10498 | HIGH | 7.8 | 0.2% | Sep 30, 2019 | Buffer overflow scenario if the client sends more than 5 io_vec requests to the server in Snapdragon Auto, Snapdragon Co... |
| CVE-2019-10497 | HIGH | 7.8 | 0.2% | Sep 30, 2019 | Use after free issue occurs If another instance of open for voice_svc node has been called from application without clos... |
| CVE-2019-10492 | HIGH | 7.8 | 0.1% | Sep 30, 2019 | Boot image not getting verified by AVB in Snapdragon Auto, Snapdragon Mobile, Snapdragon Wearables in MDM9607, MSM8909W,... |
| CVE-2019-10489 | HIGH | 7.5 | 0.8% | Sep 30, 2019 | Possible null-pointer dereference can occur while parsing avi clip during copy in Snapdragon Auto, Snapdragon Compute, S... |
| CVE-2019-17046 | HIGH | 7.2 | 4.4% | Sep 30, 2019 | Ilch 2.1.22 allows remote code execution because php is listed under "Allowed files" on the index.php/admin/media/settin... |
| CVE-2019-16997 | HIGH | 7.2 | 49.4% | Sep 30, 2019 | In Metinfo 7.0.0beta, a SQL Injection was discovered in app/system/language/admin/language_general.class.php via the adm... |
| CVE-2019-16996 | HIGH | 7.2 | 12.4% | Sep 30, 2019 | In Metinfo 7.0.0beta, a SQL Injection was discovered in app/system/product/admin/product_admin.class.php via the admin/?... |
| CVE-2019-16995 | HIGH | 7.5 | 3.5% | Sep 30, 2019 | In the Linux kernel before 5.0.3, a memory leak exits in hsr_dev_finalize() in net/hsr/hsr_device.c if hsr_add_port fail... |
| CVE-2019-16745 | HIGH | 8.8 | 1.7% | Sep 30, 2019 | eBrigade before 5.0 has evenement_choice.php chxCal SQL Injection. |
| CVE-2019-16744 | HIGH | 8.8 | 1.7% | Sep 30, 2019 | eBrigade before 5.0 has evenements.php cid SQL Injection. |
| CVE-2019-16743 | HIGH | 8.8 | 1.7% | Sep 30, 2019 | eBrigade before 5.0 has evenement_ical.php evenement SQL Injection. |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now