2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-17574 | CRITICAL | 9.8 | 3.0% | Dec 13, 2017 | FS Care Clone 1.0 has SQL Injection via the searchJob.php jobType or jobFrequency parameter. |
| CVE-2017-17572 | CRITICAL | 9.8 | 3.0% | Dec 13, 2017 | FS Amazon Clone 1.0 has SQL Injection via the PATH_INFO to /VerAyari. |
| CVE-2017-17571 | CRITICAL | 9.8 | 3.0% | Dec 13, 2017 | FS Foodpanda Clone 1.0 has SQL Injection via the /food keywords parameter. |
| CVE-2017-17570 | CRITICAL | 9.8 | 3.0% | Dec 13, 2017 | FS Expedia Clone 1.0 has SQL Injection via the pages.php or content.php id parameter, or the show-flight-result.php fl_o... |
| CVE-2017-15896 | CRITICAL | 9.1 | 2.4% | Dec 11, 2017 | Node.js was affected by OpenSSL vulnerability CVE-2017-3737 in regards to the use of SSL_read() due to TLS handshake fai... |
| CVE-2017-15944 | CRITICAL | 9.8 | 98.3% | Dec 11, 2017 | Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote ... |
| CVE-2017-15708 | CRITICAL | 9.8 | 17.7% | Dec 11, 2017 | In Apache Synapse, by default no authentication is required for Java Remote Method Invocation (RMI). So Apache Synapse 3... |
| CVE-2017-17499 | CRITICAL | 9.8 | 3.3% | Dec 11, 2017 | ImageMagick before 6.9.9-24 and 7.x before 7.0.7-12 has a use-after-free in Magick::Image::read in Magick++/lib/Image.cp... |
| CVE-2017-17480 | CRITICAL | 9.8 | 5.1% | Dec 8, 2017 | In OpenJPEG 2.3.0, a stack-based buffer overflow was discovered in the pgxtovolume function in jp3d/convert.c. The vulne... |
| CVE-2017-15702 | CRITICAL | 9.8 | 6.2% | Dec 1, 2017 | In Apache Qpid Broker-J 0.18 through 0.32, if the broker is configured with different authentication providers on differ... |
| CVE-2017-11284 | CRITICAL | 9.8 | 42.7% | Dec 1, 2017 | Adobe ColdFusion has an Untrusted Data Deserialization vulnerability. This affects Update 4 and earlier versions for Col... |
| CVE-2017-11283 | CRITICAL | 9.8 | 42.7% | Dec 1, 2017 | Adobe ColdFusion has an Untrusted Data Deserialization vulnerability. This affects Update 4 and earlier versions for Col... |
| CVE-2017-8817 | CRITICAL | 9.8 | 11.2% | Nov 29, 2017 | The FTP wildcard function in curl and libcurl before 7.57.0 allows remote attackers to cause a denial of service (out-of... |
| CVE-2017-8816 | CRITICAL | 9.8 | 8.5% | Nov 29, 2017 | The NTLM authentication feature in curl and libcurl before 7.57.0 on 32-bit platforms allows attackers to cause a denial... |
| CVE-2017-14746 | CRITICAL | 9.8 | 9.9% | Nov 27, 2017 | Use-after-free vulnerability in Samba 4.x before 4.7.3 allows remote attackers to execute arbitrary code via a crafted S... |
| CVE-2017-14586 | CRITICAL | 9.8 | 3.5% | Nov 27, 2017 | The Hipchat for Mac desktop client is vulnerable to client-side remote code execution via video call link parsing. Hipch... |
| CVE-2017-15088 | CRITICAL | 9.8 | 8.4% | Nov 23, 2017 | plugins/preauth/pkinit/pkinit_crypto_openssl.c in MIT Kerberos 5 (aka krb5) through 1.15.2 mishandles Distinguished Name... |
| CVE-2017-7550 | CRITICAL | 9.8 | 3.5% | Nov 21, 2017 | A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1) passed certain parameters to the jenkin... |
| CVE-2017-16840 | CRITICAL | 9.8 | 3.3% | Nov 21, 2017 | The VC-2 Video Compression encoder in FFmpeg 3.0 and 3.4 allows remote attackers to cause a denial of service (out-of-bo... |
| CVE-2017-16566 | CRITICAL | 9.8 | 2.6% | Nov 17, 2017 | On Jooan IP Camera A5 2.3.36 devices, an insecure FTP server does not require authentication, which allows remote attack... |
| CVE-2017-1000190 | CRITICAL | 9.1 | 4.7% | Nov 17, 2017 | SimpleXML (latest version 2.7.1) is vulnerable to an XXE vulnerability resulting SSRF, information disclosure, DoS and s... |
| CVE-2017-16845 | CRITICAL | 10 | 3.0% | Nov 17, 2017 | hw/input/ps2.c in Qemu does not validate 'rptr' and 'count' values during guest migration, leading to out-of-bounds acce... |
| CVE-2017-1000158 | CRITICAL | 9.8 | 7.9% | Nov 17, 2017 | CPython (aka Python) up to 2.7.13 is vulnerable to an integer overflow in the PyString_DecodeEscape function in stringob... |
| CVE-2017-1000237 | CRITICAL | 9.8 | 1.6% | Nov 17, 2017 | I, Librarian version <=4.6 & 4.7 is vulnerable to Server-Side Request Forgery in the ajaxsupplement.php resulting in the... |
| CVE-2017-1000235 | CRITICAL | 9.8 | 3.2% | Nov 17, 2017 | I, Librarian version <=4.6 & 4.7 is vulnerable to OS Command Injection in batchimport.php resulting the web server being... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now