2017 CVE Vulnerabilities

17,102 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-20257HIGH8.8Joomla! Component Quiz Deluxe 3.7.4 contains an SQL injection vulnerability that allows unauthenticated attackers to exe...
CVE-2017-20256HIGH8.8Joomla Survey Force Deluxe 3.2.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execut...
CVE-2017-20255HIGH8.8Joomla! Component JB Visa 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute a...
CVE-2017-20254HIGH8.8Joomla! Component User Bench 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execut...
CVE-2017-20253HIGH8.8Joomla! Component My Projects 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execu...
CVE-2017-20252HIGH8.8Joomla NextGen Editor 2.1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arb...
CVE-2017-20240MEDIUM5.9Crypt::PBKDF2 versions before 0.261630 for Perl are vulnerable to timing attacks. These versions use Perl's built-in eq...
CVE-2017-20251CRITICAL9.3WordPress Insert PHP plugin versions before 3.3.1 contain a PHP code injection vulnerability that allows unauthenticated...
CVE-2017-20250HIGH8.7Mac Photo Gallery 3.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrar...
CVE-2017-20249HIGH8.8Apptha Slider Gallery 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbit...
CVE-2017-20248HIGH8.7Apptha Slider Gallery 1.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbi...
CVE-2017-20247HIGH8.8WordPress Plugin PICA Photo Gallery 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to...
CVE-2017-20246HIGH8.8KittyCatfish 2.2 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers to r...
CVE-2017-20245HIGH8.8Wow Viral Signups 2.1 WordPress plugin contains an SQL injection vulnerability that allows unauthenticated attackers to ...
CVE-2017-20244HIGH8.8Wow Forms WordPress Plugin version 2.1 contains an SQL injection vulnerability that allows unauthenticated attackers to ...
CVE-2017-20243HIGH8.8WordPress Car Park Booking Plugin version 13 October 17 contains a time-based SQL injection vulnerability that allows un...
CVE-2017-20230CRITICAL10Storable versions before 3.05 for Perl has a stack overflow. The retrieve_hook function stored the length of the class ...
CVE-2017-20239MEDIUM5.1MDwiki contains a cross-site scripting vulnerability that allows remote attackers to execute arbitrary JavaScript by inj...
CVE-2017-20238HIGH7.1Hirschmann Industrial HiVision versions 06.0.00 and 07.0.00 prior to 06.0.06 and 07.0.01 contains an improper authorizat...
CVE-2017-20236CRITICAL9.3ProSoft Technology ICX35-HWC versions 1.3 and prior cellular gateways contain an input validation vulnerability in the w...
CVE-2017-20235CRITICAL9.3ProSoft Technology ICX35-HWC version 1.3 and prior cellular gateways contain an authentication bypass vulnerability in t...
CVE-2017-20234CRITICAL9.3GarrettCom Magnum 6K and 10K managed switches contain an authentication bypass vulnerability that allows unauthenticated...
CVE-2017-20233MEDIUM5.3Hirschmann HiLCOS products OpenBAT, BAT450, WLC, BAT867 contains a firewall filtering vulnerability that fails to correc...
CVE-2017-20237CRITICAL9.3Hirschmann Industrial HiVision versions prior to 06.0.07 and 07.0.03 contains an authentication bypass vulnerability in ...
CVE-2017-20229CRITICAL9.3MAWK 1.3.3-17 and prior contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary ...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now