2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2017-5332HIGH7.8The extract_group_icon_cursor_resource in wrestool/extract.c in icoutils before 0.31.1 can access unallocated memory, wh...
CVE-2017-5331HIGH7.8Integer overflow in the check_offset function in b/wrestool/fileread.c in icoutils before 0.31.1 allows local users to c...
CVE-2017-15725HIGH7.5An XML External Entity Injection vulnerability exists in Dzone AnswerHub.
CVE-2017-5731HIGH7.8Bounds checking in Tianocompress before November 7, 2017 may allow an authenticated user to potentially enable an escala...
CVE-2017-18638HIGH7.5send_email in graphite-web/webapp/graphite/composer/views.py in Graphite through 1.1.5 is vulnerable to SSRF. The vulner...
CVE-2017-18636HIGH7.5CDG through 2017-01-01 allows downloadDocument.jsp?command=download&pathAndName= directory traversal.
CVE-2017-18614HIGH8.1The kama-clic-counter plugin 3.4.9 for WordPress has SQL injection via the admin.php order parameter.
CVE-2017-18607HIGH8.8The avada theme before 5.1.5 for WordPress has CSRF.
CVE-2017-18604HIGH7.5The sitebuilder-dynamic-components plugin through 1.0 for WordPress has PHP object injection via an AJAX request.
CVE-2017-18602HIGH8.8The examapp plugin 1.0 for WordPress has SQL injection via the wp-admin/admin.php?page=examapp_UserResult id parameter.
CVE-2017-18597HIGH8.8The jtrt-responsive-tables plugin before 4.1.2 for WordPress has SQL Injection via the admin/class-jtrt-responsive-table...
CVE-2017-18596HIGH8.8The elementor plugin before 1.8.0 for WordPress has incorrect access control for internal functions.
CVE-2017-18595HIGH7.8An issue was discovered in the Linux kernel before 4.14.11. A double free may be caused by the function allocate_trace_b...
CVE-2017-18509HIGH7.8An issue was discovered in net/ipv6/ip6mr.c in the Linux kernel before 4.11. By setting a specific socket option, an att...
CVE-2017-18381HIGH7.2The installation process in Open edX before 2017-01-10 exposes a MongoDB instance to external connections with default c...
CVE-2017-18380HIGH7.5edx-platform before 2017-08-03 allows attackers to trigger password-reset e-mail messages in which the reset link has an...
CVE-2017-8417HIGH8.8An issue was discovered on D-Link DCS-1100 and DCS-1130 devices. The device requires that a user logging into the device...
CVE-2017-8416HIGH8.8An issue was discovered on D-Link DCS-1100 and DCS-1130 devices. The device runs a custom daemon on UDP port 5978 which ...
CVE-2017-8413HIGH8.8An issue was discovered on D-Link DCS-1100 and DCS-1130 devices. The device runs a custom daemon on UDP port 5978 which ...
CVE-2017-8412HIGH8.8An issue was discovered on D-Link DCS-1100 and DCS-1130 devices. The device has a custom binary called mp4ts under the /...
CVE-2017-8414HIGH7.8An issue was discovered on D-Link DCS-1100 and DCS-1130 devices. The binary orthrus in /sbin folder of the device handle...
CVE-2017-8409HIGH7.5An issue was discovered on D-Link DCS-1130 devices. The device requires that a user logging to the device to provide a u...
CVE-2017-8406HIGH8.8An issue was discovered on D-Link DCS-1130 devices. The device provides a crossdomain.xml file with no restrictions on w...
CVE-2017-8405HIGH7.5An issue was discovered on D-Link DCS-1130 and DCS-1100 devices. The binary rtspd in /sbin folder of the device handles ...
CVE-2017-8411HIGH8.8An issue was discovered on D-Link DCS-1130 devices. The device provides a user with the capability of setting a SMB fold...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now