2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-7375 | CRITICAL | 9.8 | 2.7% | Feb 19, 2018 | A flaw in libxml2 allows remote XML entity inclusion with default parser flags (i.e., when the caller did not request en... |
| CVE-2017-17101 | — | — | 1.6% | Feb 19, 2018 | An issue was discovered in Apexis APM-H803-MPC software, as used with many different models of IP Camera. An unprotected... |
| CVE-2017-16670 | — | — | 1.7% | Feb 19, 2018 | The project import functionality in SoapUI 5.3.0 allows remote attackers to execute arbitrary Java code via a crafted re... |
| CVE-2017-18191 | — | — | 3.9% | Feb 19, 2018 | An issue was discovered in OpenStack Nova 15.x through 15.1.0 and 16.x through 16.1.1. By detaching and reattaching an e... |
| CVE-2017-12609 | — | — | — | Feb 19, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2017-18095 | — | — | 1.1% | Feb 19, 2018 | The SnippetRPCServiceImpl class in Atlassian Crucible before version 4.5.1 (the fixed version 4.5.x) and before 4.6.0 al... |
| CVE-2017-18093 | — | — | 0.9% | Feb 19, 2018 | Various resources in Atlassian Fisheye and Crucible before version 4.4.3 (the fixed version for 4.4.x) and before 4.5.0 ... |
| CVE-2017-18092 | — | — | 0.7% | Feb 19, 2018 | The print snippet resource in Atlassian Crucible before version 4.4.3 (the fixed version for 4.4.x) and before 4.5.0 all... |
| CVE-2017-16756 | — | — | 0.6% | Feb 19, 2018 | An issue was discovered in Userscape HelpSpot before 4.7.2. A cross-site request forgery vulnerability exists on POST re... |
| CVE-2017-16755 | — | — | 0.9% | Feb 19, 2018 | An issue was discovered in Userscape HelpSpot before 4.7.2. A reflected cross-site scripting vulnerability exists in the... |
| CVE-2017-15712 | — | — | 2.6% | Feb 19, 2018 | Vulnerability allows a user of Apache Oozie 3.1.3-incubating to 4.3.0 and 5.0.0-beta1 to expose private files on the Ooz... |
| CVE-2017-16924 | — | — | 8.9% | Feb 19, 2018 | Remote Information Disclosure and Escalation of Privileges in ManageEngine Desktop Central MSP 10.0.137 allows attackers... |
| CVE-2017-18091 | — | — | 0.9% | Feb 16, 2018 | The admin backupprogress action in Atlassian Fisheye and Crucible before version 4.4.3 (the fixed version for 4.4.x) and... |
| CVE-2017-18090 | — | — | 0.9% | Feb 16, 2018 | Various resources in Atlassian Fisheye before version 4.5.1 (the fixed version for 4.5.x) and before version 4.6.0 allow... |
| CVE-2017-18089 | — | — | 0.7% | Feb 16, 2018 | The view review history resource in Atlassian Crucible before version 4.4.3 (the fixed version for 4.4.x) and 4.5.0 allo... |
| CVE-2017-18190 | — | — | 3.0% | Feb 16, 2018 | A localhost.localdomain whitelist entry in valid_host() in scheduler/client.c in CUPS before 2.2.2 allows remote attacke... |
| CVE-2017-14537 | MEDIUM | 6.5 | 39.5% | Feb 16, 2018 | trixbox 2.8.0.4 has path traversal via the xajaxargs array parameter to /maint/index.php?packages or the lang parameter ... |
| CVE-2017-14536 | — | — | 0.6% | Feb 16, 2018 | trixbox 2.8.0.4 has XSS via the PATH_INFO to /maint/index.php or /user/includes/language/langChooser.php. |
| CVE-2017-14535 | HIGH | 8.8 | 50.1% | Feb 16, 2018 | trixbox 2.8.0.4 has OS command injection via shell metacharacters in the lang parameter to /maint/modules/home/index.php... |
| CVE-2017-8993 | — | — | 0.8% | Feb 15, 2018 | A Remote Cross-Site Scripting vulnerability in HPE Project and Portfolio Management (PPM) version v9.30, v9.31, v9.32, v... |
| CVE-2017-8985 | — | — | 0.4% | Feb 15, 2018 | HPE XP Storage using Hitachi Global Link Manager (HGLM) has a local authenticated information disclosure vulnerability i... |
| CVE-2017-8984 | — | — | 11.3% | Feb 15, 2018 | A remote code execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0506P03 was found. |
| CVE-2017-8983 | — | — | 3.5% | Feb 15, 2018 | A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P4 was found. |
| CVE-2017-8982 | — | — | 14.5% | Feb 15, 2018 | A Remote Authentication Restriction Bypass vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E05... |
| CVE-2017-8981 | — | — | 8.9% | Feb 15, 2018 | A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0506 was found. |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now