2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-1655 | MEDIUM | 5.4 | 1.0% | Mar 23, 2018 | IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) is vulnerable to cross-site scripting.... |
| CVE-2017-1629 | MEDIUM | 5.4 | 1.0% | Mar 23, 2018 | IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) is vulnerable to cross-site scripting.... |
| CVE-2017-1602 | MEDIUM | 4.3 | 1.2% | Mar 23, 2018 | IBM RSA DM (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) could allow an authenticated user to access set... |
| CVE-2017-1524 | MEDIUM | 4.3 | 1.9% | Mar 23, 2018 | IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) could allow an authenticated user to o... |
| CVE-2017-15326 | — | — | 0.4% | Mar 23, 2018 | DBS3900 TDD LTE V100R003C00, V100R004C10 have a weak encryption algorithm security vulnerability. DBS3900 TDD LTE suppor... |
| CVE-2017-15325 | — | — | 1.0% | Mar 23, 2018 | The Bdat driver of Prague smart phones with software versions earlier than Prague-AL00AC00B211, versions earlier than Pr... |
| CVE-2017-17736 | — | — | 69.4% | Mar 23, 2018 | Kentico 9.0 before 9.0.51 and 10.0 before 10.0.48 allows remote attackers to obtain Global Administrator access by visit... |
| CVE-2017-18244 | — | — | 1.0% | Mar 22, 2018 | The stereo_processing function in libavcodec/aacps.c in Libav 12.2 allows remote attackers to cause a denial of service ... |
| CVE-2017-18243 | — | — | 1.0% | Mar 22, 2018 | The unpack_parse_unit function in libavcodec/dirac_parser.c in Libav 12.2 allows remote attackers to cause a denial of s... |
| CVE-2017-18242 | — | — | 1.2% | Mar 22, 2018 | The apply_dependent_coupling function in libavcodec/aacdec.c in Libav 12.2 allows remote attackers to cause a denial of ... |
| CVE-2017-16242 | — | — | 0.5% | Mar 22, 2018 | An issue was discovered on MECO USB Memory Stick with Fingerprint MECOZiolsamDE601 devices. The fingerprint authenticati... |
| CVE-2017-0920 | — | — | 0.9% | Mar 22, 2018 | GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass iss... |
| CVE-2017-16772 | — | — | 3.2% | Mar 22, 2018 | Improper input validation vulnerability in SYNOPHOTO_Flickr_MultiUpload in Synology Photo Station before 6.8.3-3463 and ... |
| CVE-2017-16771 | — | — | 1.3% | Mar 22, 2018 | Cross-site scripting (XSS) vulnerability in Log Viewer in Synology Photo Station before 6.8.3-3463 and before 6.3-2971 a... |
| CVE-2017-0935 | HIGH | 8.8 | 1.3% | Mar 22, 2018 | Ubiquiti Networks EdgeOS version 1.9.1.1 and prior suffer from an Improper Privilege Management vulnerability due to the... |
| CVE-2017-0934 | — | — | 1.3% | Mar 22, 2018 | Ubiquiti Networks EdgeOS version 1.9.1 and prior suffer from an Improper Privilege Management vulnerability due to the l... |
| CVE-2017-0933 | — | — | 0.6% | Mar 22, 2018 | Ubiquiti Networks EdgeOS version 1.9.1 and prior suffer from a Cross-Site Request Forgery (CSRF) vulnerability. An attac... |
| CVE-2017-0932 | — | — | 1.3% | Mar 22, 2018 | Ubiquiti Networks EdgeOS version 1.9.1.1 and prior suffer from an Improper Privilege Management vulnerability due to the... |
| CVE-2017-18094 | — | — | 0.6% | Mar 22, 2018 | Various resources in Atlassian Fisheye and Crucible before version 4.4.3 (the fixed version for 4.4.x) and 4.5.0 allow r... |
| CVE-2017-1789 | CRITICAL | 9.8 | 3.2% | Mar 22, 2018 | IBM Tivoli Monitoring V6 6.2.3 and 6.3.0 could allow an unauthenticated user to remotely execute code through unspecifie... |
| CVE-2017-1788 | MEDIUM | 5.3 | 2.4% | Mar 22, 2018 | IBM WebSphere Application Server 9 installations using Form Login could allow a remote attacker to conduct spoofing atta... |
| CVE-2017-1677 | HIGH | 7.4 | 0.7% | Mar 22, 2018 | IBM Data Server Driver for JDBC and SQLJ (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) deserializes th... |
| CVE-2017-1571 | MEDIUM | 5.1 | 0.3% | Mar 22, 2018 | IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 uses weaker than expected cr... |
| CVE-2017-17743 | — | — | 1.1% | Mar 22, 2018 | Improper input sanitization within the restricted administration shell on UCOPIA Wireless Appliance devices before 4.4.2... |
| CVE-2017-0927 | — | — | 0.8% | Mar 21, 2018 | Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the deployment keys component ... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now