2019 CVE Vulnerabilities
17,621 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-2315 | HIGH | 7.8 | 0.2% | Nov 21, 2019 | While invoking the API to copy from fd or local buffer to the secure buffer, Parameters being populated are from non sec... |
| CVE-2019-2303 | CRITICAL | 9.8 | 0.7% | Nov 21, 2019 | SNDCP module may access array out side its boundary when it receives malformed XID message. in Snapdragon Auto, Snapdrag... |
| CVE-2019-2297 | HIGH | 7.8 | 0.2% | Nov 21, 2019 | Buffer overflow can occur while processing non-standard NAN message from user space. in Snapdragon Auto, Snapdragon Cons... |
| CVE-2019-2295 | MEDIUM | 5.5 | 0.2% | Nov 21, 2019 | Information disclosure due to lack of address range check done on the SysDBG buffers in SDI code. in Snapdragon Auto, Sn... |
| CVE-2019-2289 | CRITICAL | 9.8 | 0.6% | Nov 21, 2019 | Lack of integrity check allows MODEM to accept any NAS messages which can result into authentication bypass of NAS in Sn... |
| CVE-2019-2271 | CRITICAL | 9.8 | 1.1% | Nov 21, 2019 | Buffer over read can happen while parsing downlink session management OTA messages if network sends un-intended values i... |
| CVE-2019-2268 | CRITICAL | 9.8 | 0.7% | Nov 21, 2019 | Possible OOB read issue in P2P action frames while handling WLAN management frame in Snapdragon Auto, Snapdragon Consume... |
| CVE-2019-2266 | HIGH | 7.8 | 0.2% | Nov 21, 2019 | Possible double free issue in kernel while handling the camera sensor and its sub modules power sequence in Snapdragon A... |
| CVE-2019-2251 | HIGH | 7.8 | 0.2% | Nov 21, 2019 | If a bitmap file is loaded from any un-authenticated source, there is a possibility that the bitmap can potentially caus... |
| CVE-2019-18958 | HIGH | 7.8 | 0.5% | Nov 21, 2019 | Nitro Pro before 13.2 creates a debug.log file in the directory where a .pdf file is located, if the .pdf document was p... |
| CVE-2019-17421 | HIGH | 7.8 | 0.6% | Nov 21, 2019 | Incorrect file permissions on the packaged Nipper executable file in Zoho ManageEngine OpManager 12.4.072 and Firewall A... |
| CVE-2019-16548 | HIGH | 8.8 | 0.7% | Nov 21, 2019 | A cross-site request forgery vulnerability in Jenkins Google Compute Engine Plugin 4.1.1 and earlier in ComputeEngineClo... |
| CVE-2019-16547 | MEDIUM | 4.3 | 0.7% | Nov 21, 2019 | Missing permission checks in various API endpoints in Jenkins Google Compute Engine Plugin 4.1.1 and earlier allow attac... |
| CVE-2019-16546 | MEDIUM | 5.9 | 0.9% | Nov 21, 2019 | Jenkins Google Compute Engine Plugin 4.1.1 and earlier does not verify SSH host keys when connecting agents created by t... |
| CVE-2019-16545 | MEDIUM | 6.5 | 0.5% | Nov 21, 2019 | Jenkins QMetry for JIRA - Test Management Plugin transmits credentials in its configuration in plain text as part of job... |
| CVE-2019-16544 | HIGH | 8.8 | 0.8% | Nov 21, 2019 | Jenkins QMetry for JIRA - Test Management Plugin 1.12 and earlier stores credentials unencrypted in job config.xml files... |
| CVE-2019-16543 | MEDIUM | 5.5 | 0.3% | Nov 21, 2019 | Jenkins Spira Importer Plugin 3.2.2 and earlier stores credentials unencrypted in its global configuration file on the J... |
| CVE-2019-16542 | MEDIUM | 6.5 | 0.9% | Nov 21, 2019 | Jenkins Anchore Container Image Scanner Plugin 1.0.19 and earlier stores credentials unencrypted in job config.xml files... |
| CVE-2019-16541 | CRITICAL | 9.9 | 1.6% | Nov 21, 2019 | Jenkins JIRA Plugin 3.0.10 and earlier does not declare the correct (folder) scope for per-folder Jira site definitions,... |
| CVE-2019-16540 | MEDIUM | 6.5 | 1.6% | Nov 21, 2019 | A path traversal vulnerability in Jenkins Support Core Plugin 2.63 and earlier allows attackers with Overall/Read permis... |
| CVE-2019-16539 | MEDIUM | 6.5 | 0.7% | Nov 21, 2019 | A missing permission check in Jenkins Support Core Plugin 2.63 and earlier allows attackers with Overall/Read permission... |
| CVE-2019-16538 | HIGH | 8.8 | 1.4% | Nov 21, 2019 | A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.67 and earlier related to the handling of default par... |
| CVE-2019-16340 | CRITICAL | 9.8 | 19.3% | Nov 21, 2019 | Belkin Linksys Velop 1.1.8.192419 devices allows remote attackers to discover the recovery key via a direct request for ... |
| CVE-2019-15704 | MEDIUM | 5.5 | 0.2% | Nov 21, 2019 | A clear text storage of sensitive information vulnerability in FortiClient for Mac may allow a local attacker to read se... |
| CVE-2019-10627 | CRITICAL | 9.8 | 1.4% | Nov 21, 2019 | Integer overflow to buffer overflow vulnerability in PostScript image handling code used by the PostScript- and PDF-comp... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now