2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2017-18639MEDIUM6.1Progress Sitefinity CMS before 10.1 allows XSS via /Pages Parameter : Page Title, /Content/News Parameter : News Title, ...
CVE-2017-1002201MEDIUM6.1In haml versions prior to version 5.0.0.beta.2, when using user input to perform tasks on the server, characters like < ...
CVE-2017-18635MEDIUM6.1An XSS vulnerability was discovered in noVNC before 0.6.2 in which the remote VNC server could inject arbitrary HTML int...
CVE-2017-18615MEDIUM6.1The kama-clic-counter plugin before 3.5.0 for WordPress has XSS.
CVE-2017-18613MEDIUM6.1The trust-form plugin 2.0 for WordPress has XSS via the wp-admin/admin.php?page=trust-form-edit page parameter.
CVE-2017-18612MEDIUM6.1The wp-whois-domain plugin 1.0.0 for WordPress has XSS via the pages/func-whois.php domain parameter.
CVE-2017-18611MEDIUM6.1The magic-fields plugin before 1.7.2 for WordPress has XSS via the RCCWP_CreateCustomFieldPage.php custom-field-css para...
CVE-2017-18610MEDIUM6.1The magic-fields plugin before 1.7.2 for WordPress has XSS via the RCCWP_CreateCustomFieldPage.php custom-group-id param...
CVE-2017-18609MEDIUM6.1The magic-fields plugin before 1.7.2 for WordPress has XSS via the custom-write-panel-id parameter.
CVE-2017-18608MEDIUM6.1The spotim-comments plugin before 4.0.4 for WordPress has multiple XSS issues.
CVE-2017-18606MEDIUM6.1The avada theme before 5.1.5 for WordPress has stored XSS.
CVE-2017-18603MEDIUM6.1The postman-smtp plugin through 2017-10-04 for WordPress has XSS via the wp-admin/tools.php?page=postman_email_log page ...
CVE-2017-18601MEDIUM5.4The examapp plugin 1.0 for WordPress has XSS via exam input text fields.
CVE-2017-18600MEDIUM5.4The formcraft3 plugin before 3.4 for WordPress has stored XSS via the "New Form > Heading > Heading Text" field.
CVE-2017-18599MEDIUM6.1The Pinfinity theme before 2.0 for WordPress has XSS via the s parameter.
CVE-2017-18598MEDIUM6.1The Qards plugin through 2017-10-11 for WordPress has XSS via a remote document specified in the url parameter to html2c...
CVE-2017-18559MEDIUM6.1The cforms2 plugin before 14.13.3 for WordPress has multiple XSS issues.
CVE-2017-18540MEDIUM6.1The weblibrarian plugin before 3.4.8.7 for WordPress has XSS via front-end short codes.
CVE-2017-18539MEDIUM6.1The weblibrarian plugin before 3.4.8.6 for WordPress has XSS via front-end short codes.
CVE-2017-18538MEDIUM6.1The weblibrarian plugin before 3.4.8.5 for WordPress has XSS via front-end short codes.
CVE-2017-18551MEDIUM6.7An issue was discovered in drivers/i2c/i2c-core-smbus.c in the Linux kernel before 4.14.15. There is an out of bounds wr...
CVE-2017-18499MEDIUM6.1The simple-membership plugin before 3.5.7 for WordPress has XSS.
CVE-2017-18508MEDIUM6.1The wp-live-chat-support plugin before 7.1.03 for WordPress has XSS.
CVE-2017-1107MEDIUM4.3IBM Marketing Platform 9.1.0, 9.1.2, 10.0, and 10.1 exposes sensitive information in the headers that could be used by a...
CVE-2017-15123MEDIUM5.3A flaw was found in the CloudForms web interface, versions 5.8 - 5.10, where the RSS feed URLs are not properly restrict...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now