2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-9536 | MEDIUM | 6.8 | 0.5% | Nov 22, 2019 | Apple iPhone 3GS bootrom malloc implementation returns a non-NULL pointer when unable to allocate memory, aka 'alloc8'. ... |
| CVE-2019-17445 | MEDIUM | 5.5 | 0.3% | Nov 22, 2019 | An issue was discovered in Eracent EDA, EPA, EPM, EUA, FLW, and SUM Agent through 10.2.26. The agent executable, when in... |
| CVE-2019-15652 | MEDIUM | 6.1 | 0.9% | Nov 22, 2019 | The web interface for NSSLGlobal SatLink VSAT Modem Unit (VMU) devices before 18.1.0 doesn't properly sanitize input for... |
| CVE-2019-18790 | MEDIUM | 6.5 | 2.0% | Nov 22, 2019 | An issue was discovered in channels/chan_sip.c in Sangoma Asterisk 13.x before 13.29.2, 16.x before 16.6.2, and 17.x bef... |
| CVE-2019-4570 | MEDIUM | 5.3 | 1.0% | Nov 22, 2019 | IBM Tivoli Netcool Impact 7.1.0 through 7.1.0.16 generates an error message that includes sensitive information about it... |
| CVE-2019-4569 | MEDIUM | 5.4 | 0.6% | Nov 22, 2019 | IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.16 is vulnerable to cross-site scripting. This vulnerability allows user... |
| CVE-2019-4243 | MEDIUM | 4.4 | 0.3% | Nov 22, 2019 | IBM SmartCloud Analytics 1.3.1 through 1.3.5 allows unauthorized disclosure of information like accessing solrconfig.xml... |
| CVE-2019-4216 | MEDIUM | 4.6 | 0.6% | Nov 22, 2019 | IBM SmartCloud Analytics 1.3.1 through 1.3.5 is vulnerable to possible host header injection attack that could lead to H... |
| CVE-2019-4215 | MEDIUM | 6.1 | 0.9% | Nov 22, 2019 | IBM SmartCloud Analytics 1.3.1 through 1.3.5 could allow a remote attacker to hijack the clicking action of the victim. ... |
| CVE-2019-3428 | MEDIUM | 6.5 | 0.9% | Nov 22, 2019 | The version V6.01.03.01 of ZTE ZXCDN IAMWEB product is impacted by a configuration error vulnerability. An attacker coul... |
| CVE-2019-19227 | MEDIUM | 5.5 | 0.6% | Nov 22, 2019 | In the AppleTalk subsystem in the Linux kernel before 5.1, there is a potential NULL pointer dereference because registe... |
| CVE-2019-10206 | MEDIUM | 6.5 | 1.5% | Nov 22, 2019 | ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all 2.7.x before 2.7.13 and all 2.6.x before... |
| CVE-2019-10203 | MEDIUM | 4.3 | 1.6% | Nov 22, 2019 | PowerDNS Authoritative daemon , pdns versions 4.0.x before 4.0.9, 4.1.x before 4.1.11, exiting when encountering a seria... |
| CVE-2019-19221 | MEDIUM | 5.5 | 0.7% | Nov 21, 2019 | In Libarchive 3.4.0, archive_wstring_append_from_mbs in archive_string.c has an out-of-bounds read because of an incorre... |
| CVE-2019-18890 | MEDIUM | 6.5 | 4.3% | Nov 21, 2019 | A SQL injection vulnerability in Redmine through 3.2.9 and 3.3.x before 3.3.10 allows Redmine users to access protected ... |
| CVE-2019-18886 | MEDIUM | 5.3 | 1.6% | Nov 21, 2019 | An issue was discovered in Symfony 4.2.0 to 4.2.11 and 4.3.0 to 4.3.7. The ability to enumerate users was possible due t... |
| CVE-2019-6693 | MEDIUM | 6.5 | 5.7% | Nov 21, 2019 | Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacke... |
| CVE-2019-2336 | MEDIUM | 5.5 | 0.2% | Nov 21, 2019 | Subsequent use of the CBO listener may result in further memory corruption due to use after free issue. in Snapdragon Au... |
| CVE-2019-2318 | MEDIUM | 5.5 | 0.2% | Nov 21, 2019 | Non Secure Kernel can cause Trustzone to do an arbitrary memory read which will result into DOS in Snapdragon Auto, Snap... |
| CVE-2019-2295 | MEDIUM | 5.5 | 0.2% | Nov 21, 2019 | Information disclosure due to lack of address range check done on the SysDBG buffers in SDI code. in Snapdragon Auto, Sn... |
| CVE-2019-16547 | MEDIUM | 4.3 | 0.7% | Nov 21, 2019 | Missing permission checks in various API endpoints in Jenkins Google Compute Engine Plugin 4.1.1 and earlier allow attac... |
| CVE-2019-16546 | MEDIUM | 5.9 | 0.9% | Nov 21, 2019 | Jenkins Google Compute Engine Plugin 4.1.1 and earlier does not verify SSH host keys when connecting agents created by t... |
| CVE-2019-16545 | MEDIUM | 6.5 | 0.5% | Nov 21, 2019 | Jenkins QMetry for JIRA - Test Management Plugin transmits credentials in its configuration in plain text as part of job... |
| CVE-2019-16543 | MEDIUM | 5.5 | 0.3% | Nov 21, 2019 | Jenkins Spira Importer Plugin 3.2.2 and earlier stores credentials unencrypted in its global configuration file on the J... |
| CVE-2019-16542 | MEDIUM | 6.5 | 0.9% | Nov 21, 2019 | Jenkins Anchore Container Image Scanner Plugin 1.0.19 and earlier stores credentials unencrypted in job config.xml files... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now