2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-12477 | CRITICAL | 9.8 | 68.2% | Aug 7, 2017 | It was discovered that the bpserverd proprietary protocol in Unitrends Backup (UB) before 10.0.0, as invoked through xin... |
| CVE-2017-9855 | CRITICAL | 9.8 | 1.6% | Aug 5, 2017 | An issue was discovered in SMA Solar Technology products. A secondary authentication system is available for Installers ... |
| CVE-2017-12562 | CRITICAL | 9.8 | 4.0% | Aug 5, 2017 | Heap-based Buffer Overflow in the psf_binheader_writef function in common.c in libsndfile through 1.0.28 allows remote a... |
| CVE-2017-10818 | CRITICAL | 9.8 | 1.8% | Aug 4, 2017 | MaLion for Windows and Mac versions 3.2.1 to 5.2.1 uses a hardcoded cryptographic key which may allow an attacker to alt... |
| CVE-2017-10817 | CRITICAL | 9.8 | 3.1% | Aug 4, 2017 | MaLion for Windows and Mac 5.0.0 to 5.2.1 allows remote attackers to bypass authentication to alter settings in Relay Se... |
| CVE-2017-10816 | CRITICAL | 9.8 | 2.2% | Aug 4, 2017 | SQL injection vulnerability in the MaLion for Windows and Mac 5.0.0 to 5.2.1 allows remote attackers to execute arbitrar... |
| CVE-2017-12424 | CRITICAL | 9.8 | 2.7% | Aug 4, 2017 | In shadow before 4.5, the newusers tool could be made to manipulate internal data structures in ways unintended by the a... |
| CVE-2017-9769 | CRITICAL | 9.8 | 85.5% | Aug 2, 2017 | A specially crafted IOCTL can be issued to the rzpnk.sys driver in Razer Synapse 2.20.15.1104 that is forwarded to ZwOpe... |
| CVE-2017-9521 | CRITICAL | 9.8 | 3.3% | Jul 31, 2017 | The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421733-160420a-CMCST); Cisco DPC3939 (firm... |
| CVE-2017-3222 | CRITICAL | 9.8 | 7.4% | Jul 22, 2017 | Hard-coded credentials in AmosConnect 8 allow remote attackers to gain full administrative privileges, including the abi... |
| CVE-2017-7480 | CRITICAL | 9.8 | 2.3% | Jul 21, 2017 | rkhunter versions before 1.4.4 are vulnerable to file download over insecure channel when doing mirror update resulting ... |
| CVE-2017-6316 | CRITICAL | 9.8 | 72.6% | Jul 20, 2017 | Citrix NetScaler SD-WAN devices through v9.1.2.26.561201 allow remote attackers to execute arbitrary shell commands as r... |
| CVE-2017-7977 | CRITICAL | 9.8 | 2.4% | Jul 19, 2017 | The Screensavercc component in eLux RP before 5.5.0 allows attackers to bypass intended configuration restrictions and e... |
| CVE-2017-11436 | CRITICAL | 9.8 | 2.0% | Jul 19, 2017 | D-Link DIR-615 before v20.12PTb04 has a second admin account with a 0x1 BACKDOOR value, which might allow remote attacke... |
| CVE-2017-11435 | CRITICAL | 9.8 | 10.1% | Jul 19, 2017 | The Humax Wi-Fi Router model HG100R-* 2.0.6 is prone to an authentication bypass vulnerability via specially crafted req... |
| CVE-2017-8011 | CRITICAL | 9.8 | 14.0% | Jul 17, 2017 | EMC ViPR SRM, EMC Storage M&R, EMC VNX M&R, EMC M&R for SAS Solution Packs (EMC ViPR SRM prior to 4.1, EMC Storage M&R p... |
| CVE-2017-2349 | CRITICAL | 9.9 | 2.3% | Jul 17, 2017 | A command injection vulnerability in the IDP feature of Juniper Networks Junos OS on SRX series devices potentially allo... |
| CVE-2017-2345 | CRITICAL | 9.8 | 3.6% | Jul 17, 2017 | On Junos OS devices with SNMP enabled, a network based attacker with unfiltered access to the RE can cause the Junos OS ... |
| CVE-2017-2343 | CRITICAL | 10 | 2.7% | Jul 17, 2017 | The Integrated User Firewall (UserFW) feature was introduced in Junos OS version 12.1X47-D10 on the Juniper SRX Series d... |
| CVE-2017-2336 | CRITICAL | 9.6 | 1.2% | Jul 17, 2017 | A reflected cross site scripting vulnerability in NetScreen WebUI of Juniper Networks Juniper NetScreen Firewall+VPN run... |
| CVE-2017-11349 | CRITICAL | 9.8 | 2.0% | Jul 17, 2017 | dataTaker DT8x dEX 1.72.007 allows remote attackers to compose programs or schedules, for purposes such as sending e-mai... |
| CVE-2017-10601 | CRITICAL | 9.8 | 1.8% | Jul 17, 2017 | A specific device configuration can result in a commit failure condition. When this occurs, a user is logged in without ... |
| CVE-2017-1000081 | CRITICAL | 9.8 | 3.0% | Jul 17, 2017 | Linux foundation ONOS 1.9.0 is vulnerable to unauthenticated upload of applications (.oar) resulting in remote code exec... |
| CVE-2017-1000060 | CRITICAL | 9.8 | 3.5% | Jul 17, 2017 | EyesOfNetwork (EON) 5.1 Unauthenticated SQL Injection in eonweb leading to remote root |
| CVE-2017-1000047 | CRITICAL | 9.8 | 3.7% | Jul 17, 2017 | rbenv (all current versions) is vulnerable to Directory Traversal in the specification of Ruby version resulting in arbi... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now