2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-13678Stored XSS vulnerability in the Symantec Advanced Secure Gateway (ASG) and ProxySG management consoles. A malicious appl...
CVE-2017-13677Denial-of-service (DoS) vulnerability in the Symantec Advanced Secure Gateway (ASG) and ProxySG management consoles. A r...
CVE-2017-9839Dolibarr ERP/CRM is affected by SQL injection in versions before 5.0.4 via product/stats/card.php (type parameter).
CVE-2017-9838Dolibarr ERP/CRM is affected by multiple reflected Cross-Site Scripting (XSS) vulnerabilities in versions before 5.0.4: ...
CVE-2017-18260Dolibarr ERP/CRM is affected by multiple SQL injection vulnerabilities in versions through 7.0.0 via comm/propal/list.ph...
CVE-2017-18259Dolibarr ERP/CRM is affected by stored Cross-Site Scripting (XSS) in versions through 7.0.0.
CVE-2017-14611SSRF (Server Side Request Forgery) in Cockpit 0.13.0 allows remote attackers to read arbitrary files or send TCP traffic...
CVE-2017-14323SSRF (Server Side Request Forgery) in getRemoteImage.php in Ueditor in Onethink V1.0 and V1.1 allows remote attackers to...
CVE-2017-18101MEDIUM6.5Various administrative external system import resources in Atlassian JIRA Server (including JIRA Core) before version 7....
CVE-2017-18100The agile wallboard gadget in Atlassian Jira before version 7.8.1 allows remote attackers to inject arbitrary HTML or Ja...
CVE-2017-1081In FreeBSD before 11.0-STABLE, 11.0-RELEASE-p10, 10.3-STABLE, and 10.3-RELEASE-p19, ipfilter using "keep state" or "keep...
CVE-2017-2826An information disclosure vulnerability exists in the iConfig proxy request of Zabbix server 2.4.X. A specially crafted ...
CVE-2017-18258The xz_head function in xzlib.c in libxml2 before 2.9.6 allows remote attackers to cause a denial of service (memory con...
CVE-2017-18098The searchrequest-xml resource in Atlassian Jira before version 7.6.1 allows remote attackers to inject arbitrary HTML o...
CVE-2017-18097The Trello board importer resource in Atlassian Jira before version 7.6.1 allows remote attackers who can convince a Jir...
CVE-2017-14473CRITICAL10An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of ...
CVE-2017-14472CRITICAL10An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of ...
CVE-2017-14471CRITICAL10An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of ...
CVE-2017-14470CRITICAL10An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of ...
CVE-2017-14469CRITICAL10An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of ...
CVE-2017-14468CRITICAL9.8An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of ...
CVE-2017-14467CRITICAL9.8An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of ...
CVE-2017-14466CRITICAL9.8An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of ...
CVE-2017-14465CRITICAL9.8An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of ...
CVE-2017-14464CRITICAL9.8An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of ...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now