2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-14454 | CRITICAL | 9.8 | 1.5% | Oct 2, 2019 | SuiteCRM 7.11.x and 7.10.x before 7.11.8 and 7.10.20 is vulnerable to vertical privilege escalation. |
| CVE-2019-13335 | CRITICAL | 9.8 | 1.3% | Oct 2, 2019 | SalesAgility SuiteCRM 7.10.x 7.10.19 and 7.11.x before and 7.11.7 has SSRF. |
| CVE-2019-17067 | CRITICAL | 9.8 | 1.6% | Oct 1, 2019 | PuTTY before 0.73 on Windows improperly opens port-forwarding listening sockets, which allows attackers to listen on the... |
| CVE-2019-16943 | CRITICAL | 9.8 | 4.9% | Oct 1, 2019 | A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is ena... |
| CVE-2019-16942 | CRITICAL | 9.8 | 5.7% | Oct 1, 2019 | A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is ena... |
| CVE-2019-10202 | CRITICAL | 9.8 | 5.2% | Oct 1, 2019 | A series of deserialization vulnerabilities have been discovered in Codehaus 1.9.x implemented in EAP 7. This CVE fixes ... |
| CVE-2019-15039 | CRITICAL | 9.8 | 12.9% | Oct 1, 2019 | An issue was discovered in JetBrains TeamCity 2018.2.4. It had a possible remote code execution issue. This was fixed in... |
| CVE-2019-10431 | CRITICAL | 9.9 | 2.7% | Oct 1, 2019 | A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.64 and earlier related to the handling of default par... |
| CVE-2019-15940 | CRITICAL | 9.8 | 2.1% | Oct 1, 2019 | Victure PC530 devices allow unauthenticated TELNET access as root. |
| CVE-2019-2294 | CRITICAL | 9.8 | 0.9% | Sep 30, 2019 | Usage of hard-coded magic number for calculating heap guard bytes can allow users to corrupt heap blocks without heap al... |
| CVE-2019-2252 | CRITICAL | 9.8 | 1.2% | Sep 30, 2019 | Classic buffer overflow vulnerability while playing the specific video whose Decode picture buffer size is more than 16 ... |
| CVE-2019-16932 | CRITICAL | 10 | 39.1% | Sep 30, 2019 | A blind SSRF vulnerability exists in the Visualizer plugin before 3.3.1 for WordPress via wp-json/visualizer/v1/upload-d... |
| CVE-2019-10540 | CRITICAL | 9.8 | 1.1% | Sep 30, 2019 | Buffer overflow in WLAN NAN function due to lack of check of count value received in NAN availability attribute in Snapd... |
| CVE-2019-10539 | CRITICAL | 9.8 | 0.9% | Sep 30, 2019 | Possible buffer overflow issue due to lack of length check when parsing the extended cap IE header length in Snapdragon ... |
| CVE-2019-10538 | CRITICAL | 9.8 | 1.1% | Sep 30, 2019 | Lack of check of address range received from firmware response allows modem to respond arbitrary pages into its address ... |
| CVE-2019-10509 | CRITICAL | 9.8 | 0.9% | Sep 30, 2019 | Device record of the pairing device used after free during ACL disconnection in Snapdragon Auto, Snapdragon Compute, Sna... |
| CVE-2019-17040 | CRITICAL | 9.8 | 2.4% | Sep 30, 2019 | contrib/pmdb2diag/pmdb2diag.c in Rsyslog v8.1908.0 allows out-of-bounds access because the level length is mishandled. |
| CVE-2019-16999 | CRITICAL | 9.8 | 1.5% | Sep 30, 2019 | CloudBoot through 2019-03-08 allows SQL Injection via a crafted Status field in JSON data to the api/osinstall/v1/device... |
| CVE-2019-16676 | CRITICAL | 9.8 | 3.4% | Sep 30, 2019 | Plataformatec Simple Form has Incorrect Access Control in file_method? in lib/simple_form/form_builder.rb, because a use... |
| CVE-2019-16941 | CRITICAL | 9.8 | 5.1% | Sep 28, 2019 | NSA Ghidra through 9.0.4, when experimental mode is enabled, allows arbitrary code execution if the Read XML Files featu... |
| CVE-2019-3766 | CRITICAL | 9.8 | 1.9% | Sep 27, 2019 | Dell EMC ECS versions prior to 3.4.0.0 contain an improper restriction of excessive authentication attempts vulnerabilit... |
| CVE-2019-16928 | CRITICAL | 9.8 | 42.5% | Sep 27, 2019 | Exim 4.92 through 4.92.2 allows remote code execution, a different vulnerability than CVE-2019-15846. There is a heap-ba... |
| CVE-2019-9459 | CRITICAL | 9.8 | 1.1% | Sep 27, 2019 | In libttspico, there is a possible OOB write due to a heap buffer overflow. This could lead to remote escalation of priv... |
| CVE-2019-9365 | CRITICAL | 9.8 | 1.0% | Sep 27, 2019 | In Bluetooth, there is a possible deserialization error due to missing string validation. This could lead to remote code... |
| CVE-2019-9301 | CRITICAL | 9.8 | 0.8% | Sep 27, 2019 | In libAACdec, there is a possible out of bounds write due to an integer overflow. This could lead to remote code executi... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now