2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2017-1000487CRITICAL9.8Plexus-utils before 3.0.16 is vulnerable to command injection because it does not correctly process the contents of doub...
CVE-2017-1000486CRITICAL9.8Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution
CVE-2017-1000497CRITICAL9.8Pepperminty-Wiki version 0.15 is vulnerable to XXE attacks in the getsvgsize function resulting in denial of service and...
CVE-2017-18017CRITICAL9.8The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36,...
CVE-2017-5641CRITICAL9.8Previous versions of Apache Flex BlazeDS (4.7.2 and earlier) did not restrict which types were allowed for AMF(X) object...
CVE-2017-17643CRITICAL9.8FS Lynda Clone 1.0 has SQL Injection via the keywords parameter to tutorial/.
CVE-2017-3195CRITICAL9.8Commvault Edge Communication Service (cvd) prior to version 11 SP7 or version 11 SP6 with hotfix 590 is prone to a stack...
CVE-2017-17671CRITICAL9.8vBulletin through 5.3.x on Windows allows remote PHP code execution because a require_once call is reachable with an una...
CVE-2017-17625CRITICAL9.8Professional Service Script 1.0 has SQL Injection via the service-list city parameter.
CVE-2017-17590CRITICAL9.8FS Stackoverflow Clone 1.0 has SQL Injection via the /question keywords parameter.
CVE-2017-17589CRITICAL9.8FS Thumbtack Clone 1.0 has SQL Injection via the browse-category.php cat parameter or the browse-scategory.php sc parame...
CVE-2017-17588CRITICAL9.8FS IMDB Clone 1.0 has SQL Injection via the movie.php f parameter, tvshow.php s parameter, or show_misc_video.php id par...
CVE-2017-17587CRITICAL9.8FS Indiamart Clone 1.0 has SQL Injection via the catcompany.php token parameter, buyleads-details.php id parameter, or c...
CVE-2017-17586CRITICAL9.8FS Olx Clone 1.0 has SQL Injection via the subpage.php scat parameter or the message.php pid parameter.
CVE-2017-17585CRITICAL9.8FS Monster Clone 1.0 has SQL Injection via the Employer_Details.php id parameter.
CVE-2017-17584CRITICAL9.8FS Makemytrip Clone 1.0 has SQL Injection via the show-flight-result.php fl_orig or fl_dest parameter.
CVE-2017-17583CRITICAL9.8FS Shutterstock Clone 1.0 has SQL Injection via the /Category keywords parameter.
CVE-2017-17582CRITICAL9.8FS Grubhub Clone 1.0 has SQL Injection via the /food keywords parameter.
CVE-2017-17581CRITICAL9.8FS Quibids Clone 1.0 has SQL Injection via the itechd.php productid parameter.
CVE-2017-17580CRITICAL9.8FS Linkedin Clone 1.0 has SQL Injection via the group.php grid parameter, profile.php fid parameter, or company_details....
CVE-2017-17579CRITICAL9.8FS Freelancer Clone 1.0 has SQL Injection via the profile.php u parameter.
CVE-2017-17578CRITICAL9.8FS Crowdfunding Script 1.0 has SQL Injection via the latest_news_details.php id parameter.
CVE-2017-17577CRITICAL9.8FS Trademe Clone 1.0 has SQL Injection via the search_item.php search parameter or the general_item_details.php id param...
CVE-2017-17576CRITICAL9.8FS Gigs Script 1.0 has SQL Injection via the browse-category.php cat parameter, browse-scategory.php sc parameter, or se...
CVE-2017-17575CRITICAL9.8FS Groupon Clone 1.0 has SQL Injection via the item_details.php id parameter or the vendor_details.php id parameter.

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now