2019 CVE Vulnerabilities

17,624 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-20409CRITICAL9.8The way in which velocity templates were used in Atlassian Jira Server and Data Center prior to version 8.8.0 allowed re...
CVE-2019-3865MEDIUM6.1A vulnerability was found in quay-2, where a stored XSS vulnerability has been found in the super user function of quay....
CVE-2019-14894HIGH7.2A flaw was found in the CloudForms management engine version 5.10 and CloudForms management version 5.11, which triggere...
CVE-2019-14094HIGH7.8Integer overflow in diag command handler when user inputs a large value for number of tasks field in the request packet ...
CVE-2019-14092MEDIUM5.5System Services exports services without permission protect and can lead to information exposure in Snapdragon Industria...
CVE-2019-14091HIGH7.8Double free issue in NPU due to lack of resource locking mechanism to avoid race condition in Snapdragon Auto, Snapdrago...
CVE-2019-14080CRITICAL9.8Out of bound write can happen due to lack of check of array index value while parsing SDP attribute for SAR in Snapdrago...
CVE-2019-14076HIGH7.8Buffer overflow occurs while processing an subsample data length out of range due to lack of user input validation in Sn...
CVE-2019-14073CRITICAL9.8Copying RTCP messages into the output buffer without checking the destination buffer size which could lead to a remote s...
CVE-2019-14062CRITICAL9.8Buffer overflows while decoding setup message from Network due to lack of check of IE message length received from netwo...
CVE-2019-14047HIGH7.8While IPA driver processes route add rule IOCTL, there is no input validation of the rule ID prior to adding the rule to...
CVE-2019-10626MEDIUM5.5Payload size is not validated before reading memory that may cause issue of accessing invalid pointer or some garbage da...
CVE-2019-10597HIGH7.8kernel writes to user passed address without any checks can lead to arbitrary memory write in Snapdragon Auto, Snapdrago...
CVE-2019-20891HIGH8.8WooCommerce before 3.6.5, when it handles CSV imports of products, has a cross-site request forgery (CSRF) issue with re...
CVE-2019-20890MEDIUM4.3An issue was discovered in Mattermost Server before 5.7. It allows a bypass of e-mail address discovery restrictions.
CVE-2019-20889MEDIUM5.3An issue was discovered in Mattermost Server before 5.7, 5.6.3, 5.5.2, and 4.10.5. It mishandles permissions for user-ac...
CVE-2019-20888HIGH7.5An issue was discovered in Mattermost Server before 5.7, 5.6.3, 5.5.2, and 4.10.5. It allows attackers to cause a denial...
CVE-2019-20887MEDIUM4.3An issue was discovered in Mattermost Server before 5.7.1, 5.6.4, 5.5.3, and 4.10.6. It does not honor flags API permiss...
CVE-2019-20886HIGH7.5An issue was discovered in Mattermost Server before 5.8.0. The first user is sometimes inadvertently a system admin.
CVE-2019-20885HIGH7.5An issue was discovered in Mattermost Server before 5.8.0. It does not always generate a robots.txt file.
CVE-2019-20884MEDIUM5.3An issue was discovered in Mattermost Server before 5.8.0. It allows attackers to partially attach a file to more than o...
CVE-2019-20883MEDIUM4.3An issue was discovered in Mattermost Server before 5.8.0, when Town Square is set to Read-Only. Users can pin or unpin ...
CVE-2019-20882MEDIUM5.3An issue was discovered in Mattermost Server before 5.8.0. It does not honor the domain requirement when processing a jo...
CVE-2019-20881HIGH7.3An issue was discovered in Mattermost Server before 5.8.0. It mishandles brute-force attacks against MFA.
CVE-2019-20880HIGH7.5An issue was discovered in Mattermost Server before 5.8.0, 5.7.2, 5.6.5, and 4.10.7. It allows attackers to cause a deni...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now