2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-20259HIGH8.8Joomla OSDownloads 1.7.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitr...
CVE-2017-20258HIGH8.8Joomla! Component RPC Responsive Portfolio 1.6.1 contains an SQL injection vulnerability that allows unauthenticated att...
CVE-2017-20257HIGH8.8Joomla! Component Quiz Deluxe 3.7.4 contains an SQL injection vulnerability that allows unauthenticated attackers to exe...
CVE-2017-20256HIGH8.8Joomla Survey Force Deluxe 3.2.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execut...
CVE-2017-20255HIGH8.8Joomla! Component JB Visa 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute a...
CVE-2017-20254HIGH8.8Joomla! Component User Bench 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execut...
CVE-2017-20253HIGH8.8Joomla! Component My Projects 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execu...
CVE-2017-20252HIGH8.8Joomla NextGen Editor 2.1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arb...
CVE-2017-20240MEDIUM5.9Crypt::PBKDF2 versions before 0.261630 for Perl are vulnerable to timing attacks. These versions use Perl's built-in eq...
CVE-2017-20251CRITICAL9.8WordPress Insert PHP plugin versions before 3.3.1 contain a PHP code injection vulnerability that allows unauthenticated...
CVE-2017-20250HIGH8.7Mac Photo Gallery 3.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrar...
CVE-2017-20249HIGH8.8Apptha Slider Gallery 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbit...
CVE-2017-20248HIGH8.7Apptha Slider Gallery 1.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbi...
CVE-2017-20247HIGH8.8WordPress Plugin PICA Photo Gallery 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to...
CVE-2017-20246HIGH8.8KittyCatfish 2.2 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers to r...
CVE-2017-20245HIGH8.8Wow Viral Signups 2.1 WordPress plugin contains an SQL injection vulnerability that allows unauthenticated attackers to ...
CVE-2017-20244HIGH8.8Wow Forms WordPress Plugin version 2.1 contains an SQL injection vulnerability that allows unauthenticated attackers to ...
CVE-2017-20243HIGH8.8WordPress Car Park Booking Plugin version 13 October 17 contains a time-based SQL injection vulnerability that allows un...
CVE-2017-20230CRITICAL10Storable versions before 3.05 for Perl has a stack overflow. The retrieve_hook function stored the length of the class ...
CVE-2017-20239MEDIUM6.1MDwiki contains a cross-site scripting vulnerability that allows remote attackers to execute arbitrary JavaScript by inj...
CVE-2017-20238HIGH7.1Hirschmann Industrial HiVision versions 06.0.00 and 07.0.00 prior to 06.0.06 and 07.0.01 contains an improper authorizat...
CVE-2017-20236CRITICAL9.8ProSoft Technology ICX35-HWC versions 1.3 and prior cellular gateways contain an input validation vulnerability in the w...
CVE-2017-20235CRITICAL9.8ProSoft Technology ICX35-HWC version 1.3 and prior cellular gateways contain an authentication bypass vulnerability in t...
CVE-2017-20234CRITICAL9.8GarrettCom Magnum 6K and 10K managed switches contain an authentication bypass vulnerability that allows unauthenticated...
CVE-2017-20233MEDIUM5.4Hirschmann HiLCOS products OpenBAT, BAT450, WLC, BAT867 contains a firewall filtering vulnerability that fails to correc...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now