2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-9602 | CRITICAL | 9.8 | 4.3% | Jun 16, 2017 | KBVault Mysql Free Knowledge Base application package 0.16a comes with a FileExplorer/Explorer.aspx?id=/Uploads file-man... |
| CVE-2017-7876 | CRITICAL | 10 | 3.3% | Jun 15, 2017 | This command injection vulnerability in QTS allows attackers to run arbitrary commands in the compromised application. Q... |
| CVE-2017-8543 | CRITICAL | 9.8 | 73.8% | Jun 15, 2017 | Microsoft Windows XP SP3, Windows XP x64 XP2, Windows Server 2003 SP2, Windows Vista, Windows 7 SP1, Windows Server 2008... |
| CVE-2017-4992 | CRITICAL | 9.8 | 1.2% | Jun 13, 2017 | An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v261; UAA release 2.x versions prior to... |
| CVE-2017-9544 | CRITICAL | 9.8 | 24.1% | Jun 12, 2017 | There is a remote stack-based buffer overflow (SEH) in register.ghp in EFS Software Easy Chat Server versions 2.0 to 3.1... |
| CVE-2017-5878 | CRITICAL | 9.8 | 2.7% | Jun 8, 2017 | The AMF unmarshallers in Red5 Media Server before 1.0.8 do not restrict the classes for which it performs deserializatio... |
| CVE-2017-7312 | CRITICAL | 9.8 | 3.0% | Jun 7, 2017 | An issue was discovered in Personify360 e-Business 7.5.2 through 7.6.1. When going to the /TabId/275 URI, anyone can add... |
| CVE-2017-7494 | CRITICAL | 9.8 | 99.4% | May 30, 2017 | Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo... |
| CVE-2017-6862 | CRITICAL | 9.8 | 42.7% | May 26, 2017 | NETGEAR WNR2000v3 devices before 1.1.2.14, WNR2000v4 devices before 1.0.0.66, and WNR2000v5 devices before 1.0.0.42 allo... |
| CVE-2017-9034 | CRITICAL | 9.8 | 6.0% | May 26, 2017 | Trend Micro ServerProtect for Linux 3.0 before CP 1531 allows attackers to write to arbitrary files and consequently exe... |
| CVE-2017-9228 | CRITICAL | 9.8 | 6.3% | May 24, 2017 | An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7... |
| CVE-2017-9227 | CRITICAL | 9.8 | 6.3% | May 24, 2017 | An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7... |
| CVE-2017-9226 | CRITICAL | 9.8 | 7.5% | May 24, 2017 | An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7... |
| CVE-2017-9224 | CRITICAL | 9.8 | 6.5% | May 24, 2017 | An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7... |
| CVE-2017-2800 | CRITICAL | 9.8 | 8.5% | May 24, 2017 | A specially crafted x509 certificate can cause a single out of bounds byte overwrite in wolfSSL through 3.10.2 resulting... |
| CVE-2017-9214 | CRITICAL | 9.8 | 2.9% | May 23, 2017 | In Open vSwitch (OvS) 2.7.0, while parsing an OFPT_QUEUE_GET_CONFIG_REPLY type OFP 1.0 message, there is a buffer over-r... |
| CVE-2017-5173 | CRITICAL | 9.8 | 29.6% | May 19, 2017 | An Improper Neutralization of Special Elements (in an OS command) issue was discovered in Geutebruck IP Camera G-Cam/EFD... |
| CVE-2017-9055 | CRITICAL | 9.8 | 1.7% | May 18, 2017 | An issue, also known as DW201703-001, was discovered in libdwarf 2017-03-21. In dwarf_formsdata() a few data types were ... |
| CVE-2017-9054 | CRITICAL | 9.8 | 1.8% | May 18, 2017 | An issue, also known as DW201703-002, was discovered in libdwarf 2017-03-21. In _dwarf_decode_s_leb128_chk() a byte poin... |
| CVE-2017-9053 | CRITICAL | 9.1 | 1.7% | May 18, 2017 | An issue, also known as DW201703-005, was discovered in libdwarf 2017-03-21. A heap-based buffer over-read in _dwarf_rea... |
| CVE-2017-9052 | CRITICAL | 9.8 | 2.7% | May 18, 2017 | An issue, also known as DW201703-006, was discovered in libdwarf 2017-03-21. A heap-based buffer over-read in dwarf_form... |
| CVE-2017-6079 | CRITICAL | 9.8 | 46.8% | May 16, 2017 | The HTTP web-management application on Edgewater Networks Edgemarc appliances has a hidden page that allows for user-def... |
| CVE-2017-8923 | CRITICAL | 9.8 | 7.2% | May 12, 2017 | The zend_string_extend function in Zend/zend_string.h in PHP through 7.1.5 does not prevent changes to string objects th... |
| CVE-2017-8872 | CRITICAL | 9.1 | 2.3% | May 10, 2017 | The htmlParseTryOrFinish function in HTMLparser.c in libxml2 2.9.4 allows attackers to cause a denial of service (buffer... |
| CVE-2017-7921 | CRITICAL | 9.8 | 100.0% | May 6, 2017 | An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now