2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-1000487 | CRITICAL | 9.8 | 6.5% | Jan 3, 2018 | Plexus-utils before 3.0.16 is vulnerable to command injection because it does not correctly process the contents of doub... |
| CVE-2017-1000486 | CRITICAL | 9.8 | 94.1% | Jan 3, 2018 | Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution |
| CVE-2017-1000497 | CRITICAL | 9.8 | 2.5% | Jan 3, 2018 | Pepperminty-Wiki version 0.15 is vulnerable to XXE attacks in the getsvgsize function resulting in denial of service and... |
| CVE-2017-18017 | CRITICAL | 9.8 | 52.2% | Jan 3, 2018 | The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36,... |
| CVE-2017-5641 | CRITICAL | 9.8 | 21.3% | Dec 28, 2017 | Previous versions of Apache Flex BlazeDS (4.7.2 and earlier) did not restrict which types were allowed for AMF(X) object... |
| CVE-2017-17643 | CRITICAL | 9.8 | 3.0% | Dec 18, 2017 | FS Lynda Clone 1.0 has SQL Injection via the keywords parameter to tutorial/. |
| CVE-2017-3195 | CRITICAL | 9.8 | 21.4% | Dec 16, 2017 | Commvault Edge Communication Service (cvd) prior to version 11 SP7 or version 11 SP6 with hotfix 590 is prone to a stack... |
| CVE-2017-17671 | CRITICAL | 9.8 | 3.0% | Dec 14, 2017 | vBulletin through 5.3.x on Windows allows remote PHP code execution because a require_once call is reachable with an una... |
| CVE-2017-17625 | CRITICAL | 9.8 | 3.0% | Dec 13, 2017 | Professional Service Script 1.0 has SQL Injection via the service-list city parameter. |
| CVE-2017-17590 | CRITICAL | 9.8 | 3.9% | Dec 13, 2017 | FS Stackoverflow Clone 1.0 has SQL Injection via the /question keywords parameter. |
| CVE-2017-17589 | CRITICAL | 9.8 | 3.0% | Dec 13, 2017 | FS Thumbtack Clone 1.0 has SQL Injection via the browse-category.php cat parameter or the browse-scategory.php sc parame... |
| CVE-2017-17588 | CRITICAL | 9.8 | 3.0% | Dec 13, 2017 | FS IMDB Clone 1.0 has SQL Injection via the movie.php f parameter, tvshow.php s parameter, or show_misc_video.php id par... |
| CVE-2017-17587 | CRITICAL | 9.8 | 3.0% | Dec 13, 2017 | FS Indiamart Clone 1.0 has SQL Injection via the catcompany.php token parameter, buyleads-details.php id parameter, or c... |
| CVE-2017-17586 | CRITICAL | 9.8 | 3.0% | Dec 13, 2017 | FS Olx Clone 1.0 has SQL Injection via the subpage.php scat parameter or the message.php pid parameter. |
| CVE-2017-17585 | CRITICAL | 9.8 | 3.0% | Dec 13, 2017 | FS Monster Clone 1.0 has SQL Injection via the Employer_Details.php id parameter. |
| CVE-2017-17584 | CRITICAL | 9.8 | 3.0% | Dec 13, 2017 | FS Makemytrip Clone 1.0 has SQL Injection via the show-flight-result.php fl_orig or fl_dest parameter. |
| CVE-2017-17583 | CRITICAL | 9.8 | 3.0% | Dec 13, 2017 | FS Shutterstock Clone 1.0 has SQL Injection via the /Category keywords parameter. |
| CVE-2017-17582 | CRITICAL | 9.8 | 3.0% | Dec 13, 2017 | FS Grubhub Clone 1.0 has SQL Injection via the /food keywords parameter. |
| CVE-2017-17581 | CRITICAL | 9.8 | 3.0% | Dec 13, 2017 | FS Quibids Clone 1.0 has SQL Injection via the itechd.php productid parameter. |
| CVE-2017-17580 | CRITICAL | 9.8 | 3.0% | Dec 13, 2017 | FS Linkedin Clone 1.0 has SQL Injection via the group.php grid parameter, profile.php fid parameter, or company_details.... |
| CVE-2017-17579 | CRITICAL | 9.8 | 3.0% | Dec 13, 2017 | FS Freelancer Clone 1.0 has SQL Injection via the profile.php u parameter. |
| CVE-2017-17578 | CRITICAL | 9.8 | 3.0% | Dec 13, 2017 | FS Crowdfunding Script 1.0 has SQL Injection via the latest_news_details.php id parameter. |
| CVE-2017-17577 | CRITICAL | 9.8 | 3.0% | Dec 13, 2017 | FS Trademe Clone 1.0 has SQL Injection via the search_item.php search parameter or the general_item_details.php id param... |
| CVE-2017-17576 | CRITICAL | 9.8 | 3.0% | Dec 13, 2017 | FS Gigs Script 1.0 has SQL Injection via the browse-category.php cat parameter, browse-scategory.php sc parameter, or se... |
| CVE-2017-17575 | CRITICAL | 9.8 | 3.0% | Dec 13, 2017 | FS Groupon Clone 1.0 has SQL Injection via the item_details.php id parameter or the vendor_details.php id parameter. |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now