2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2017-17574CRITICAL9.8FS Care Clone 1.0 has SQL Injection via the searchJob.php jobType or jobFrequency parameter.
CVE-2017-17572CRITICAL9.8FS Amazon Clone 1.0 has SQL Injection via the PATH_INFO to /VerAyari.
CVE-2017-17571CRITICAL9.8FS Foodpanda Clone 1.0 has SQL Injection via the /food keywords parameter.
CVE-2017-17570CRITICAL9.8FS Expedia Clone 1.0 has SQL Injection via the pages.php or content.php id parameter, or the show-flight-result.php fl_o...
CVE-2017-15896CRITICAL9.1Node.js was affected by OpenSSL vulnerability CVE-2017-3737 in regards to the use of SSL_read() due to TLS handshake fai...
CVE-2017-15944CRITICAL9.8Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote ...
CVE-2017-15708CRITICAL9.8In Apache Synapse, by default no authentication is required for Java Remote Method Invocation (RMI). So Apache Synapse 3...
CVE-2017-17499CRITICAL9.8ImageMagick before 6.9.9-24 and 7.x before 7.0.7-12 has a use-after-free in Magick::Image::read in Magick++/lib/Image.cp...
CVE-2017-17480CRITICAL9.8In OpenJPEG 2.3.0, a stack-based buffer overflow was discovered in the pgxtovolume function in jp3d/convert.c. The vulne...
CVE-2017-15702CRITICAL9.8In Apache Qpid Broker-J 0.18 through 0.32, if the broker is configured with different authentication providers on differ...
CVE-2017-11284CRITICAL9.8Adobe ColdFusion has an Untrusted Data Deserialization vulnerability. This affects Update 4 and earlier versions for Col...
CVE-2017-11283CRITICAL9.8Adobe ColdFusion has an Untrusted Data Deserialization vulnerability. This affects Update 4 and earlier versions for Col...
CVE-2017-8817CRITICAL9.8The FTP wildcard function in curl and libcurl before 7.57.0 allows remote attackers to cause a denial of service (out-of...
CVE-2017-8816CRITICAL9.8The NTLM authentication feature in curl and libcurl before 7.57.0 on 32-bit platforms allows attackers to cause a denial...
CVE-2017-14746CRITICAL9.8Use-after-free vulnerability in Samba 4.x before 4.7.3 allows remote attackers to execute arbitrary code via a crafted S...
CVE-2017-14586CRITICAL9.8The Hipchat for Mac desktop client is vulnerable to client-side remote code execution via video call link parsing. Hipch...
CVE-2017-15088CRITICAL9.8plugins/preauth/pkinit/pkinit_crypto_openssl.c in MIT Kerberos 5 (aka krb5) through 1.15.2 mishandles Distinguished Name...
CVE-2017-7550CRITICAL9.8A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1) passed certain parameters to the jenkin...
CVE-2017-16840CRITICAL9.8The VC-2 Video Compression encoder in FFmpeg 3.0 and 3.4 allows remote attackers to cause a denial of service (out-of-bo...
CVE-2017-16566CRITICAL9.8On Jooan IP Camera A5 2.3.36 devices, an insecure FTP server does not require authentication, which allows remote attack...
CVE-2017-1000190CRITICAL9.1SimpleXML (latest version 2.7.1) is vulnerable to an XXE vulnerability resulting SSRF, information disclosure, DoS and s...
CVE-2017-16845CRITICAL10hw/input/ps2.c in Qemu does not validate 'rptr' and 'count' values during guest migration, leading to out-of-bounds acce...
CVE-2017-1000158CRITICAL9.8CPython (aka Python) up to 2.7.13 is vulnerable to an integer overflow in the PyString_DecodeEscape function in stringob...
CVE-2017-1000237CRITICAL9.8I, Librarian version <=4.6 & 4.7 is vulnerable to Server-Side Request Forgery in the ajaxsupplement.php resulting in the...
CVE-2017-1000235CRITICAL9.8I, Librarian version <=4.6 & 4.7 is vulnerable to OS Command Injection in batchimport.php resulting the web server being...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now