2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-7466 | HIGH | 8 | 3.2% | Jun 22, 2018 | Ansible before version 2.3 has an input validation vulnerability in the handling of data sent from client systems. An at... |
| CVE-2017-3968 | HIGH | 7.5 | 1.5% | Jun 13, 2018 | Session fixation vulnerability in the web interface in McAfee Network Security Manager (NSM) before 8.2.7.42.2 and McAfe... |
| CVE-2017-3200 | HIGH | 8.1 | 6.1% | Jun 11, 2018 | The Java implementation of AMF3 deserializers used in GraniteDS, version 3.1.1.G, may allow instantiation of arbitrary c... |
| CVE-2017-3199 | HIGH | 8.1 | 6.1% | Jun 11, 2018 | The Java implementation of GraniteDS, version 3.1.1.GA, AMF3 deserializers derives class instances from java.io.External... |
| CVE-2017-12078 | HIGH | 7.2 | 2.4% | Jun 8, 2018 | Command injection vulnerability in EZ-Internet in Synology Router Manager (SRM) before 1.1.6-6931 allows remote authenti... |
| CVE-2017-12075 | HIGH | 7.2 | 1.9% | Jun 8, 2018 | Command injection vulnerability in EZ-Internet in Synology DiskStation Manager (DSM) before 6.2-23739 allows remote auth... |
| CVE-2017-16116 | HIGH | 7.5 | 1.7% | Jun 7, 2018 | The string module is a module that provides extra string operations. The string module is vulnerable to regular expressi... |
| CVE-2017-16115 | HIGH | 7.5 | 1.5% | Jun 7, 2018 | The timespan module is vulnerable to regular expression denial of service. Given 50k characters of untrusted user input ... |
| CVE-2017-1350 | HIGH | 8.4 | 0.5% | Jun 5, 2018 | IBM InfoSphere Information Server 9.1, 11.3, 11.5, and 11.7 could allow a user to escalate their privileges to administr... |
| CVE-2017-16046 | HIGH | 7.5 | 1.1% | Jun 4, 2018 | `mariadb` was a malicious module published with the intent to hijack environment variables. It has been unpublished by n... |
| CVE-2017-16014 | HIGH | 7.5 | 1.7% | Jun 4, 2018 | Http-proxy is a proxying library. Because of the way errors are handled in versions before 0.7.0, an attacker that force... |
| CVE-2017-2860 | HIGH | 7.5 | 1.4% | Jun 1, 2018 | An exploitable denial-of-service vulnerability exists in the lookup entry functionality of KeyTrees in Natus Xltek Neuro... |
| CVE-2017-2858 | HIGH | 7.5 | 1.6% | Jun 1, 2018 | An exploitable denial-of-service vulnerability exists in the traversal of lists functionality of Natus Xltek NeuroWorks ... |
| CVE-2017-2852 | HIGH | 7.5 | 1.4% | Jun 1, 2018 | An exploitable denial-of-service vulnerability exists in the unserialization of lists functionality of Natus Xltek Neuro... |
| CVE-2017-16062 | HIGH | 7.5 | 1.1% | May 29, 2018 | node-tkinter was a malicious module published with the intent to hijack environment variables. It has been unpublished b... |
| CVE-2017-2617 | HIGH | 7.6 | 1.7% | May 22, 2018 | hawtio before version 1.5.5 is vulnerable to remote code execution via file upload. An attacker could use this vulnerabi... |
| CVE-2017-2608 | HIGH | 8.8 | 6.3% | May 15, 2018 | Jenkins before versions 2.44, 2.32.2 is vulnerable to a remote code execution vulnerability involving the deserializatio... |
| CVE-2017-2815 | HIGH | 8.1 | 0.9% | May 15, 2018 | An exploitable XML entity injection vulnerability exists in OpenFire User Import Export Plugin 2.6.0. A specially crafte... |
| CVE-2017-14439 | HIGH | 7.5 | 1.7% | May 14, 2018 | Exploitable denial of service vulnerabilities exists in the Service Agent functionality of Moxa EDR-810 V4.1 build 17030... |
| CVE-2017-14438 | HIGH | 7.5 | 1.9% | May 14, 2018 | Exploitable denial of service vulnerabilities exists in the Service Agent functionality of Moxa EDR-810 V4.1 build 17030... |
| CVE-2017-14437 | HIGH | 7.5 | 2.2% | May 14, 2018 | An exploitable denial of service vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 1703031... |
| CVE-2017-14436 | HIGH | 7.5 | 2.2% | May 14, 2018 | An exploitable denial of service vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 1703031... |
| CVE-2017-14435 | HIGH | 7.5 | 2.2% | May 14, 2018 | An exploitable denial of service vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 1703031... |
| CVE-2017-14434 | HIGH | 8.8 | 4.5% | May 14, 2018 | An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 1703031... |
| CVE-2017-14433 | HIGH | 8.8 | 4.8% | May 14, 2018 | An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 1703031... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now