2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2017-5188MEDIUM5The bs_worker code in open build service before 20170320 followed relative symlinks, allowing reading of files outside o...
CVE-2017-14800MEDIUM5.4A reflected cross site scripting attack in the NetIQ Access Manager before 4.3.3 using the "typecontainerid" parameter o...
CVE-2017-14799MEDIUM4.6A cross site scripting attack in handling the ESP login parameter handling in NetIQ Access Manager before 4.3.3 could be...
CVE-2017-18195MEDIUM5.3An issue was discovered in tools/conversations/view_ajax.php in Concrete5 before 8.3.0. An unauthenticated user can enum...
CVE-2017-14537MEDIUM6.5trixbox 2.8.0.4 has path traversal via the xajaxargs array parameter to /maint/index.php?packages or the lang parameter ...
CVE-2017-15699MEDIUM6.5A Denial of Service vulnerability was found in Apache Qpid Dispatch Router versions 0.7.0 and 0.8.0. To exploit this vul...
CVE-2017-14522MEDIUM6.1In WonderCMS 2.3.1, the application's input fields accept arbitrary user input resulting in execution of malicious JavaS...
CVE-2017-18030MEDIUM4.4The cirrus_invalidate_region function in hw/display/cirrus_vga.c in Qemu allows local OS guest privileged users to cause...
CVE-2017-12114MEDIUM6.8An exploitable improper authorization vulnerability exists in admin_peers API of cpp-ethereum's JSON-RPC (commit 4e10157...
CVE-2017-12097MEDIUM6.1An exploitable cross site scripting (XSS) vulnerability exists in the filter functionality of the delayed_job_web rails ...
CVE-2017-12098MEDIUM6.1An exploitable cross site scripting (XSS) vulnerability exists in the add filter functionality of the rails_admin rails ...
CVE-2017-12308MEDIUM6.1A vulnerability in the web framework of Cisco Small Business Managed Switches software could allow an unauthenticated, r...
CVE-2017-12307MEDIUM6.1A vulnerability in the web framework of Cisco Small Business Managed Switches software could allow an unauthenticated, r...
CVE-2017-15129MEDIUM4.7A use-after-free vulnerability was found in network namespaces code affecting the Linux kernel before 4.14.11. The funct...
CVE-2017-17837MEDIUM6.1The Apache DeltaSpike-JSF 1.8.0 module has a XSS injection leak in the windowId handling. The default size of the window...
CVE-2017-5754MEDIUM5.6Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized discl...
CVE-2017-5753MEDIUM5.6Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of ...
CVE-2017-5715MEDIUM5.6Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized discl...
CVE-2017-1000426MEDIUM6.1MapProxy version 1.10.3 and older is vulnerable to a Cross Site Scripting attack in the demo service resulting in possib...
CVE-2017-1000445MEDIUM6.5ImageMagick 7.0.7-1 and older version are vulnerable to null pointer dereference in the MagickCore component and might l...
CVE-2017-18005MEDIUM5.5Exiv2 0.26 has a Null Pointer Dereference in the Exiv2::DataValue::toLong function in value.cpp, related to crafted meta...
CVE-2017-17933MEDIUM6.1cgi/surgeftpmgr.cgi (aka the Web Manager interface on TCP port 7021 or 9021) in NetWin SurgeFTP version 23f2 has XSS via...
CVE-2017-17760MEDIUM6.5OpenCV 3.3.1 has a Buffer Overflow in the cv::PxMDecoder::readData function in grfmt_pxm.cpp, because an incorrect size ...
CVE-2017-14363MEDIUM5.9Cross-Site Scripting (XSS) vulnerability has been identified in Micro Focus Operations Manager i, versions 10.60, 10.61,...
CVE-2017-17828MEDIUM4.8Bus Booking Script has XSS via the results.php datepicker parameter or the admin/new_master.php spemail parameter.

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now