2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-18639 | MEDIUM | 6.1 | 0.9% | Nov 6, 2019 | Progress Sitefinity CMS before 10.1 allows XSS via /Pages Parameter : Page Title, /Content/News Parameter : News Title, ... |
| CVE-2017-1002201 | MEDIUM | 6.1 | 1.5% | Oct 15, 2019 | In haml versions prior to version 5.0.0.beta.2, when using user input to perform tasks on the server, characters like < ... |
| CVE-2017-18635 | MEDIUM | 6.1 | 4.8% | Sep 25, 2019 | An XSS vulnerability was discovered in noVNC before 0.6.2 in which the remote VNC server could inject arbitrary HTML int... |
| CVE-2017-18615 | MEDIUM | 6.1 | 0.9% | Sep 13, 2019 | The kama-clic-counter plugin before 3.5.0 for WordPress has XSS. |
| CVE-2017-18613 | MEDIUM | 6.1 | 1.0% | Sep 13, 2019 | The trust-form plugin 2.0 for WordPress has XSS via the wp-admin/admin.php?page=trust-form-edit page parameter. |
| CVE-2017-18612 | MEDIUM | 6.1 | 1.0% | Sep 13, 2019 | The wp-whois-domain plugin 1.0.0 for WordPress has XSS via the pages/func-whois.php domain parameter. |
| CVE-2017-18611 | MEDIUM | 6.1 | 1.2% | Sep 10, 2019 | The magic-fields plugin before 1.7.2 for WordPress has XSS via the RCCWP_CreateCustomFieldPage.php custom-field-css para... |
| CVE-2017-18610 | MEDIUM | 6.1 | 1.2% | Sep 10, 2019 | The magic-fields plugin before 1.7.2 for WordPress has XSS via the RCCWP_CreateCustomFieldPage.php custom-group-id param... |
| CVE-2017-18609 | MEDIUM | 6.1 | 1.2% | Sep 10, 2019 | The magic-fields plugin before 1.7.2 for WordPress has XSS via the custom-write-panel-id parameter. |
| CVE-2017-18608 | MEDIUM | 6.1 | 1.0% | Sep 10, 2019 | The spotim-comments plugin before 4.0.4 for WordPress has multiple XSS issues. |
| CVE-2017-18606 | MEDIUM | 6.1 | 0.9% | Sep 10, 2019 | The avada theme before 5.1.5 for WordPress has stored XSS. |
| CVE-2017-18603 | MEDIUM | 6.1 | 1.0% | Sep 10, 2019 | The postman-smtp plugin through 2017-10-04 for WordPress has XSS via the wp-admin/tools.php?page=postman_email_log page ... |
| CVE-2017-18601 | MEDIUM | 5.4 | 0.7% | Sep 10, 2019 | The examapp plugin 1.0 for WordPress has XSS via exam input text fields. |
| CVE-2017-18600 | MEDIUM | 5.4 | 0.7% | Sep 10, 2019 | The formcraft3 plugin before 3.4 for WordPress has stored XSS via the "New Form > Heading > Heading Text" field. |
| CVE-2017-18599 | MEDIUM | 6.1 | 0.9% | Sep 10, 2019 | The Pinfinity theme before 2.0 for WordPress has XSS via the s parameter. |
| CVE-2017-18598 | MEDIUM | 6.1 | 1.9% | Sep 10, 2019 | The Qards plugin through 2017-10-11 for WordPress has XSS via a remote document specified in the url parameter to html2c... |
| CVE-2017-18559 | MEDIUM | 6.1 | 0.9% | Aug 21, 2019 | The cforms2 plugin before 14.13.3 for WordPress has multiple XSS issues. |
| CVE-2017-18540 | MEDIUM | 6.1 | 0.9% | Aug 21, 2019 | The weblibrarian plugin before 3.4.8.7 for WordPress has XSS via front-end short codes. |
| CVE-2017-18539 | MEDIUM | 6.1 | 0.9% | Aug 21, 2019 | The weblibrarian plugin before 3.4.8.6 for WordPress has XSS via front-end short codes. |
| CVE-2017-18538 | MEDIUM | 6.1 | 0.9% | Aug 21, 2019 | The weblibrarian plugin before 3.4.8.5 for WordPress has XSS via front-end short codes. |
| CVE-2017-18551 | MEDIUM | 6.7 | 0.4% | Aug 19, 2019 | An issue was discovered in drivers/i2c/i2c-core-smbus.c in the Linux kernel before 4.14.15. There is an out of bounds wr... |
| CVE-2017-18499 | MEDIUM | 6.1 | 0.9% | Aug 12, 2019 | The simple-membership plugin before 3.5.7 for WordPress has XSS. |
| CVE-2017-18508 | MEDIUM | 6.1 | 0.9% | Aug 12, 2019 | The wp-live-chat-support plugin before 7.1.03 for WordPress has XSS. |
| CVE-2017-1107 | MEDIUM | 4.3 | 1.4% | Jun 19, 2019 | IBM Marketing Platform 9.1.0, 9.1.2, 10.0, and 10.1 exposes sensitive information in the headers that could be used by a... |
| CVE-2017-15123 | MEDIUM | 5.3 | 1.4% | Jun 12, 2019 | A flaw was found in the CloudForms web interface, versions 5.8 - 5.10, where the RSS feed URLs are not properly restrict... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now