2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-16021 | MEDIUM | 6.5 | 1.3% | Jun 4, 2018 | uri-js is a module that tries to fully implement RFC 3986. One of these features is validating whether or not a supplied... |
| CVE-2017-16009 | MEDIUM | 6.1 | 1.2% | Jun 4, 2018 | ag-grid is an advanced data grid that is library agnostic. ag-grid is vulnerable to Cross-site Scripting (XSS) via Angul... |
| CVE-2017-0931 | MEDIUM | 6.1 | 1.1% | Jun 4, 2018 | html-janitor node module suffers from a Cross-Site Scripting (XSS) vulnerability via clean() accepting user-controlled v... |
| CVE-2017-1748 | MEDIUM | 6.8 | 0.9% | Jun 4, 2018 | IBM Connections 5.0, 5.5, and 6.0 could allow a remote attacker to conduct phishing attacks, using an open redirect atta... |
| CVE-2017-1768 | MEDIUM | 4.3 | 1.4% | May 29, 2018 | IBM Security Guardium Big Data Intelligence (SonarG) 3.1 generates an error message that includes sensitive information ... |
| CVE-2017-2598 | MEDIUM | 4.3 | 1.1% | May 23, 2018 | Jenkins before versions 2.44, 2.32.2 uses AES ECB block cipher mode without IV for encrypting secrets which makes Jenkin... |
| CVE-2017-2609 | MEDIUM | 4.3 | 1.8% | May 22, 2018 | jenkins before versions 2.44, 2.32.2 is vulnerable to an information disclosure vulnerability in search suggestions (SEC... |
| CVE-2017-2607 | MEDIUM | 4.2 | 1.1% | May 21, 2018 | jenkins before versions 2.44, 2.32.2 is vulnerable to a persisted cross-site scripting vulnerability in console notes (S... |
| CVE-2017-18268 | MEDIUM | 5.9 | 1.6% | May 17, 2018 | Symantec IntelligenceCenter 3.3 is vulnerable to the Return of the Bleichenbacher Oracle Threat (ROBOT) attack. A remote... |
| CVE-2017-2613 | MEDIUM | 5.4 | 1.7% | May 15, 2018 | jenkins before versions 2.44, 2.32.2 is vulnerable to a user creation CSRF using GET by admins. While this user record w... |
| CVE-2017-2610 | MEDIUM | 5.4 | 1.5% | May 15, 2018 | jenkins before versions 2.44, 2.32.2 is vulnerable to a persisted cross-site scripting in search suggestions due to impr... |
| CVE-2017-2604 | MEDIUM | 4.3 | 1.4% | May 15, 2018 | In Jenkins before versions 2.44, 2.32.2 low privilege users were able to act on administrative monitors due to them not ... |
| CVE-2017-2612 | MEDIUM | 5.4 | 1.6% | May 15, 2018 | In Jenkins before versions 2.44, 2.32.2 low privilege users were able to override JDK download credentials (SECURITY-392... |
| CVE-2017-2600 | MEDIUM | 4.3 | 1.1% | May 15, 2018 | In jenkins before versions 2.44, 2.32.2 node monitor data could be viewed by low privilege users via the remote API. The... |
| CVE-2017-12127 | MEDIUM | 4.4 | 0.4% | May 14, 2018 | A password storage vulnerability exists in the operating system functionality of Moxa EDR-810 V4.1 build 17030317. An at... |
| CVE-2017-12124 | MEDIUM | 6.5 | 1.9% | May 14, 2018 | An exploitable denial of service vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 1703031... |
| CVE-2017-2601 | MEDIUM | 5.4 | 2.1% | May 10, 2018 | Jenkins before versions 2.44, 2.32.2 is vulnerable to a persisted cross-site scripting in parameter names and descriptio... |
| CVE-2017-2606 | MEDIUM | 4.3 | 1.9% | May 8, 2018 | Jenkins before versions 2.44, 2.32.2 is vulnerable to an information exposure in the internal API that allows access to ... |
| CVE-2017-2611 | MEDIUM | 4.3 | 2.1% | May 8, 2018 | Jenkins before versions 2.44, 2.32.2 is vulnerable to an insufficient permission check for periodic processes (SECURITY-... |
| CVE-2017-2594 | MEDIUM | 5.4 | 2.0% | May 8, 2018 | hawtio before versions 2.0-beta-1, 2.0-beta-2 2.0-m1, 2.0-m2, 2.0-m3, and 1.5 is vulnerable to a path traversal that lea... |
| CVE-2017-2592 | MEDIUM | 5.9 | 0.5% | May 8, 2018 | python-oslo-middleware before versions 3.8.1, 3.19.1, 3.23.1 is vulnerable to an information disclosure. Software using ... |
| CVE-2017-5536 | MEDIUM | 6.3 | 0.7% | May 1, 2018 | The GridServer Broker, and GridServer Director components of TIBCO Software Inc. TIBCO DataSynapse GridServer Manager co... |
| CVE-2017-5535 | MEDIUM | 6.8 | 0.2% | May 1, 2018 | The GridServer Broker, GridServer Driver, and GridServer Engine components of TIBCO Software Inc. TIBCO DataSynapse Grid... |
| CVE-2017-9284 | MEDIUM | 4.8 | 1.3% | Apr 26, 2018 | IDM 4.6 Identity Applications prior to 4.6.2.1 may expose sensitive information. |
| CVE-2017-6888 | MEDIUM | 5.5 | 1.4% | Apr 25, 2018 | An error in the "read_metadata_vorbiscomment_()" function (src/libFLAC/stream_decoder.c) in FLAC version 1.3.2 can be ex... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now