2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2019-14454CRITICAL9.8SuiteCRM 7.11.x and 7.10.x before 7.11.8 and 7.10.20 is vulnerable to vertical privilege escalation.
CVE-2019-13335CRITICAL9.8SalesAgility SuiteCRM 7.10.x 7.10.19 and 7.11.x before and 7.11.7 has SSRF.
CVE-2019-17067CRITICAL9.8PuTTY before 0.73 on Windows improperly opens port-forwarding listening sockets, which allows attackers to listen on the...
CVE-2019-16943CRITICAL9.8A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is ena...
CVE-2019-16942CRITICAL9.8A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is ena...
CVE-2019-10202CRITICAL9.8A series of deserialization vulnerabilities have been discovered in Codehaus 1.9.x implemented in EAP 7. This CVE fixes ...
CVE-2019-15039CRITICAL9.8An issue was discovered in JetBrains TeamCity 2018.2.4. It had a possible remote code execution issue. This was fixed in...
CVE-2019-10431CRITICAL9.9A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.64 and earlier related to the handling of default par...
CVE-2019-15940CRITICAL9.8Victure PC530 devices allow unauthenticated TELNET access as root.
CVE-2019-2294CRITICAL9.8Usage of hard-coded magic number for calculating heap guard bytes can allow users to corrupt heap blocks without heap al...
CVE-2019-2252CRITICAL9.8Classic buffer overflow vulnerability while playing the specific video whose Decode picture buffer size is more than 16 ...
CVE-2019-16932CRITICAL10A blind SSRF vulnerability exists in the Visualizer plugin before 3.3.1 for WordPress via wp-json/visualizer/v1/upload-d...
CVE-2019-10540CRITICAL9.8Buffer overflow in WLAN NAN function due to lack of check of count value received in NAN availability attribute in Snapd...
CVE-2019-10539CRITICAL9.8Possible buffer overflow issue due to lack of length check when parsing the extended cap IE header length in Snapdragon ...
CVE-2019-10538CRITICAL9.8Lack of check of address range received from firmware response allows modem to respond arbitrary pages into its address ...
CVE-2019-10509CRITICAL9.8Device record of the pairing device used after free during ACL disconnection in Snapdragon Auto, Snapdragon Compute, Sna...
CVE-2019-17040CRITICAL9.8contrib/pmdb2diag/pmdb2diag.c in Rsyslog v8.1908.0 allows out-of-bounds access because the level length is mishandled.
CVE-2019-16999CRITICAL9.8CloudBoot through 2019-03-08 allows SQL Injection via a crafted Status field in JSON data to the api/osinstall/v1/device...
CVE-2019-16676CRITICAL9.8Plataformatec Simple Form has Incorrect Access Control in file_method? in lib/simple_form/form_builder.rb, because a use...
CVE-2019-16941CRITICAL9.8NSA Ghidra through 9.0.4, when experimental mode is enabled, allows arbitrary code execution if the Read XML Files featu...
CVE-2019-3766CRITICAL9.8Dell EMC ECS versions prior to 3.4.0.0 contain an improper restriction of excessive authentication attempts vulnerabilit...
CVE-2019-16928CRITICAL9.8Exim 4.92 through 4.92.2 allows remote code execution, a different vulnerability than CVE-2019-15846. There is a heap-ba...
CVE-2019-9459CRITICAL9.8In libttspico, there is a possible OOB write due to a heap buffer overflow. This could lead to remote escalation of priv...
CVE-2019-9365CRITICAL9.8In Bluetooth, there is a possible deserialization error due to missing string validation. This could lead to remote code...
CVE-2019-9301CRITICAL9.8In libAACdec, there is a possible out of bounds write due to an integer overflow. This could lead to remote code executi...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now