2019 CVE Vulnerabilities

17,621 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-2315HIGH7.8While invoking the API to copy from fd or local buffer to the secure buffer, Parameters being populated are from non sec...
CVE-2019-2303CRITICAL9.8SNDCP module may access array out side its boundary when it receives malformed XID message. in Snapdragon Auto, Snapdrag...
CVE-2019-2297HIGH7.8Buffer overflow can occur while processing non-standard NAN message from user space. in Snapdragon Auto, Snapdragon Cons...
CVE-2019-2295MEDIUM5.5Information disclosure due to lack of address range check done on the SysDBG buffers in SDI code. in Snapdragon Auto, Sn...
CVE-2019-2289CRITICAL9.8Lack of integrity check allows MODEM to accept any NAS messages which can result into authentication bypass of NAS in Sn...
CVE-2019-2271CRITICAL9.8Buffer over read can happen while parsing downlink session management OTA messages if network sends un-intended values i...
CVE-2019-2268CRITICAL9.8Possible OOB read issue in P2P action frames while handling WLAN management frame in Snapdragon Auto, Snapdragon Consume...
CVE-2019-2266HIGH7.8Possible double free issue in kernel while handling the camera sensor and its sub modules power sequence in Snapdragon A...
CVE-2019-2251HIGH7.8If a bitmap file is loaded from any un-authenticated source, there is a possibility that the bitmap can potentially caus...
CVE-2019-18958HIGH7.8Nitro Pro before 13.2 creates a debug.log file in the directory where a .pdf file is located, if the .pdf document was p...
CVE-2019-17421HIGH7.8Incorrect file permissions on the packaged Nipper executable file in Zoho ManageEngine OpManager 12.4.072 and Firewall A...
CVE-2019-16548HIGH8.8A cross-site request forgery vulnerability in Jenkins Google Compute Engine Plugin 4.1.1 and earlier in ComputeEngineClo...
CVE-2019-16547MEDIUM4.3Missing permission checks in various API endpoints in Jenkins Google Compute Engine Plugin 4.1.1 and earlier allow attac...
CVE-2019-16546MEDIUM5.9Jenkins Google Compute Engine Plugin 4.1.1 and earlier does not verify SSH host keys when connecting agents created by t...
CVE-2019-16545MEDIUM6.5Jenkins QMetry for JIRA - Test Management Plugin transmits credentials in its configuration in plain text as part of job...
CVE-2019-16544HIGH8.8Jenkins QMetry for JIRA - Test Management Plugin 1.12 and earlier stores credentials unencrypted in job config.xml files...
CVE-2019-16543MEDIUM5.5Jenkins Spira Importer Plugin 3.2.2 and earlier stores credentials unencrypted in its global configuration file on the J...
CVE-2019-16542MEDIUM6.5Jenkins Anchore Container Image Scanner Plugin 1.0.19 and earlier stores credentials unencrypted in job config.xml files...
CVE-2019-16541CRITICAL9.9Jenkins JIRA Plugin 3.0.10 and earlier does not declare the correct (folder) scope for per-folder Jira site definitions,...
CVE-2019-16540MEDIUM6.5A path traversal vulnerability in Jenkins Support Core Plugin 2.63 and earlier allows attackers with Overall/Read permis...
CVE-2019-16539MEDIUM6.5A missing permission check in Jenkins Support Core Plugin 2.63 and earlier allows attackers with Overall/Read permission...
CVE-2019-16538HIGH8.8A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.67 and earlier related to the handling of default par...
CVE-2019-16340CRITICAL9.8Belkin Linksys Velop 1.1.8.192419 devices allows remote attackers to discover the recovery key via a direct request for ...
CVE-2019-15704MEDIUM5.5A clear text storage of sensitive information vulnerability in FortiClient for Mac may allow a local attacker to read se...
CVE-2019-10627CRITICAL9.8Integer overflow to buffer overflow vulnerability in PostScript image handling code used by the PostScript- and PDF-comp...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now