2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2017-7466HIGH8Ansible before version 2.3 has an input validation vulnerability in the handling of data sent from client systems. An at...
CVE-2017-3968HIGH7.5Session fixation vulnerability in the web interface in McAfee Network Security Manager (NSM) before 8.2.7.42.2 and McAfe...
CVE-2017-3200HIGH8.1The Java implementation of AMF3 deserializers used in GraniteDS, version 3.1.1.G, may allow instantiation of arbitrary c...
CVE-2017-3199HIGH8.1The Java implementation of GraniteDS, version 3.1.1.GA, AMF3 deserializers derives class instances from java.io.External...
CVE-2017-12078HIGH7.2Command injection vulnerability in EZ-Internet in Synology Router Manager (SRM) before 1.1.6-6931 allows remote authenti...
CVE-2017-12075HIGH7.2Command injection vulnerability in EZ-Internet in Synology DiskStation Manager (DSM) before 6.2-23739 allows remote auth...
CVE-2017-16116HIGH7.5The string module is a module that provides extra string operations. The string module is vulnerable to regular expressi...
CVE-2017-16115HIGH7.5The timespan module is vulnerable to regular expression denial of service. Given 50k characters of untrusted user input ...
CVE-2017-1350HIGH8.4IBM InfoSphere Information Server 9.1, 11.3, 11.5, and 11.7 could allow a user to escalate their privileges to administr...
CVE-2017-16046HIGH7.5`mariadb` was a malicious module published with the intent to hijack environment variables. It has been unpublished by n...
CVE-2017-16014HIGH7.5Http-proxy is a proxying library. Because of the way errors are handled in versions before 0.7.0, an attacker that force...
CVE-2017-2860HIGH7.5An exploitable denial-of-service vulnerability exists in the lookup entry functionality of KeyTrees in Natus Xltek Neuro...
CVE-2017-2858HIGH7.5An exploitable denial-of-service vulnerability exists in the traversal of lists functionality of Natus Xltek NeuroWorks ...
CVE-2017-2852HIGH7.5An exploitable denial-of-service vulnerability exists in the unserialization of lists functionality of Natus Xltek Neuro...
CVE-2017-16062HIGH7.5node-tkinter was a malicious module published with the intent to hijack environment variables. It has been unpublished b...
CVE-2017-2617HIGH7.6hawtio before version 1.5.5 is vulnerable to remote code execution via file upload. An attacker could use this vulnerabi...
CVE-2017-2608HIGH8.8Jenkins before versions 2.44, 2.32.2 is vulnerable to a remote code execution vulnerability involving the deserializatio...
CVE-2017-2815HIGH8.1An exploitable XML entity injection vulnerability exists in OpenFire User Import Export Plugin 2.6.0. A specially crafte...
CVE-2017-14439HIGH7.5Exploitable denial of service vulnerabilities exists in the Service Agent functionality of Moxa EDR-810 V4.1 build 17030...
CVE-2017-14438HIGH7.5Exploitable denial of service vulnerabilities exists in the Service Agent functionality of Moxa EDR-810 V4.1 build 17030...
CVE-2017-14437HIGH7.5An exploitable denial of service vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 1703031...
CVE-2017-14436HIGH7.5An exploitable denial of service vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 1703031...
CVE-2017-14435HIGH7.5An exploitable denial of service vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 1703031...
CVE-2017-14434HIGH8.8An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 1703031...
CVE-2017-14433HIGH8.8An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 1703031...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now