2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2017-16021MEDIUM6.5uri-js is a module that tries to fully implement RFC 3986. One of these features is validating whether or not a supplied...
CVE-2017-16009MEDIUM6.1ag-grid is an advanced data grid that is library agnostic. ag-grid is vulnerable to Cross-site Scripting (XSS) via Angul...
CVE-2017-0931MEDIUM6.1html-janitor node module suffers from a Cross-Site Scripting (XSS) vulnerability via clean() accepting user-controlled v...
CVE-2017-1748MEDIUM6.8IBM Connections 5.0, 5.5, and 6.0 could allow a remote attacker to conduct phishing attacks, using an open redirect atta...
CVE-2017-1768MEDIUM4.3IBM Security Guardium Big Data Intelligence (SonarG) 3.1 generates an error message that includes sensitive information ...
CVE-2017-2598MEDIUM4.3Jenkins before versions 2.44, 2.32.2 uses AES ECB block cipher mode without IV for encrypting secrets which makes Jenkin...
CVE-2017-2609MEDIUM4.3jenkins before versions 2.44, 2.32.2 is vulnerable to an information disclosure vulnerability in search suggestions (SEC...
CVE-2017-2607MEDIUM4.2jenkins before versions 2.44, 2.32.2 is vulnerable to a persisted cross-site scripting vulnerability in console notes (S...
CVE-2017-18268MEDIUM5.9Symantec IntelligenceCenter 3.3 is vulnerable to the Return of the Bleichenbacher Oracle Threat (ROBOT) attack. A remote...
CVE-2017-2613MEDIUM5.4jenkins before versions 2.44, 2.32.2 is vulnerable to a user creation CSRF using GET by admins. While this user record w...
CVE-2017-2610MEDIUM5.4jenkins before versions 2.44, 2.32.2 is vulnerable to a persisted cross-site scripting in search suggestions due to impr...
CVE-2017-2604MEDIUM4.3In Jenkins before versions 2.44, 2.32.2 low privilege users were able to act on administrative monitors due to them not ...
CVE-2017-2612MEDIUM5.4In Jenkins before versions 2.44, 2.32.2 low privilege users were able to override JDK download credentials (SECURITY-392...
CVE-2017-2600MEDIUM4.3In jenkins before versions 2.44, 2.32.2 node monitor data could be viewed by low privilege users via the remote API. The...
CVE-2017-12127MEDIUM4.4A password storage vulnerability exists in the operating system functionality of Moxa EDR-810 V4.1 build 17030317. An at...
CVE-2017-12124MEDIUM6.5An exploitable denial of service vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 1703031...
CVE-2017-2601MEDIUM5.4Jenkins before versions 2.44, 2.32.2 is vulnerable to a persisted cross-site scripting in parameter names and descriptio...
CVE-2017-2606MEDIUM4.3Jenkins before versions 2.44, 2.32.2 is vulnerable to an information exposure in the internal API that allows access to ...
CVE-2017-2611MEDIUM4.3Jenkins before versions 2.44, 2.32.2 is vulnerable to an insufficient permission check for periodic processes (SECURITY-...
CVE-2017-2594MEDIUM5.4hawtio before versions 2.0-beta-1, 2.0-beta-2 2.0-m1, 2.0-m2, 2.0-m3, and 1.5 is vulnerable to a path traversal that lea...
CVE-2017-2592MEDIUM5.9python-oslo-middleware before versions 3.8.1, 3.19.1, 3.23.1 is vulnerable to an information disclosure. Software using ...
CVE-2017-5536MEDIUM6.3The GridServer Broker, and GridServer Director components of TIBCO Software Inc. TIBCO DataSynapse GridServer Manager co...
CVE-2017-5535MEDIUM6.8The GridServer Broker, GridServer Driver, and GridServer Engine components of TIBCO Software Inc. TIBCO DataSynapse Grid...
CVE-2017-9284MEDIUM4.8IDM 4.6 Identity Applications prior to 4.6.2.1 may expose sensitive information.
CVE-2017-6888MEDIUM5.5An error in the "read_metadata_vorbiscomment_()" function (src/libFLAC/stream_decoder.c) in FLAC version 1.3.2 can be ex...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now