2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-17902 | — | — | 1.1% | Apr 22, 2018 | SQL Injection exists in Kliqqi CMS 3.5.2 via the randkey parameter of a new story at the pligg/story.php?title= URI. |
| CVE-2017-17889 | — | — | 0.5% | Apr 22, 2018 | Kliqqi CMS 3.5.2 has XSS via a crafted group name in pligg/groups.php, a crafted Homepage string in a profile, or a craf... |
| CVE-2017-15640 | — | — | 0.7% | Apr 21, 2018 | app/sections/user-menu.php in phpIPAM before 1.3.1 has XSS via the ip parameter. |
| CVE-2017-2825 | — | — | 4.4% | Apr 20, 2018 | In the trapper functionality of Zabbix Server 2.4.x, specifically crafted trapper packets can pass database logic checks... |
| CVE-2017-8315 | — | — | 1.7% | Apr 20, 2018 | Eclipse XML parser for the Eclipse IDE versions 2017.2.5 and earlier was found vulnerable to an XML External Entity atta... |
| CVE-2017-3776 | — | — | 1.1% | Apr 19, 2018 | Lenovo Help Android mobile app versions earlier than 6.1.2.0327 allowed information to be transmitted over an HTTP chann... |
| CVE-2017-3774 | — | — | 1.3% | Apr 19, 2018 | A stack overflow vulnerability was discovered within the web administration service in Integrated Management Module 2 (I... |
| CVE-2017-17313 | — | — | 0.6% | Apr 19, 2018 | The inputhub driver of HUAWEI P9 Lite mobile phones with Versions earlier than VNS-L21C02B341, Versions earlier than VNS... |
| CVE-2017-17310 | — | — | 1.3% | Apr 19, 2018 | Electronic Numbers to URI Mapping (ENUM) module in some Huawei products DP300 V500R002C00, RP200 V600R006C00, TE30 V100R... |
| CVE-2017-18261 | — | — | 0.3% | Apr 19, 2018 | The arch_timer_reg_read_stable macro in arch/arm64/include/asm/arch_timer.h in the Linux kernel before 4.13 allows local... |
| CVE-2017-12196 | MEDIUM | 4.8 | 2.0% | Apr 18, 2018 | undertow before versions 1.4.18.SP1, 2.0.2.Final, 1.4.24.Final was found vulnerable when using Digest authentication, th... |
| CVE-2017-2871 | HIGH | 8.8 | 1.1% | Apr 17, 2018 | Insufficient security checks exist in the recovery procedure used by the Foscam C1 Indoor HD Camera running application ... |
| CVE-2017-9638 | — | — | 3.6% | Apr 17, 2018 | Mitsubishi E-Designer, Version 7.52 Build 344 contains six code sections which may be exploited to overwrite the stack. ... |
| CVE-2017-9636 | — | — | 3.6% | Apr 17, 2018 | Mitsubishi E-Designer, Version 7.52 Build 344 contains five code sections which may be exploited to overwrite the heap. ... |
| CVE-2017-9634 | — | — | 3.6% | Apr 17, 2018 | Mitsubishi E-Designer, Version 7.52 Build 344 contains two code sections which may be exploited to allow an attacker to ... |
| CVE-2017-6020 | — | — | 8.7% | Apr 17, 2018 | Leao Consultoria e Desenvolvimento de Sistemas (LCDS) LTDA ME LAquis SCADA software versions prior to version 4.1.0.3237... |
| CVE-2017-12701 | — | — | 1.3% | Apr 17, 2018 | BMC Medical Luna CPAP Machines released prior to July 1, 2017, contain an improper input validation vulnerability which ... |
| CVE-2017-18102 | MEDIUM | 5.4 | 0.9% | Apr 17, 2018 | The wiki markup component of atlassian-renderer from version 8.0.0 before version 8.0.22 allows remote attackers to inje... |
| CVE-2017-6323 | — | — | 0.5% | Apr 16, 2018 | The Symantec Management Console prior to ITMS 8.1 RU1, ITMS 8.0_POST_HF6, and ITMS 7.6_POST_HF7 has an issue whereby XML... |
| CVE-2017-10140 | — | — | 0.6% | Apr 16, 2018 | Postfix before 2.11.10, 3.0.x before 3.0.10, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 might allow local users to gain ... |
| CVE-2017-0372 | — | — | 11.7% | Apr 13, 2018 | Parameters injection in the SyntaxHighlight extension of Mediawiki before 1.23.16, 1.27.3 and 1.28.2 might result in mul... |
| CVE-2017-0370 | — | — | 1.4% | Apr 13, 2018 | Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw were Spam blacklist is ineffective on encoded URLs inside fil... |
| CVE-2017-0369 | — | — | 1.2% | Apr 13, 2018 | Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw, allowing a sysops to undelete pages, although the page is pr... |
| CVE-2017-0368 | — | — | 1.5% | Apr 13, 2018 | Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw making rawHTML mode apply to system messages. |
| CVE-2017-0367 | — | — | 1.9% | Apr 13, 2018 | Mediawiki before 1.28.1 / 1.27.2 contains an unsafe use of temporary directory, where having LocalisationCache directory... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now