2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-5188 | MEDIUM | 5 | 1.2% | Mar 1, 2018 | The bs_worker code in open build service before 20170320 followed relative symlinks, allowing reading of files outside o... |
| CVE-2017-14800 | MEDIUM | 5.4 | 0.8% | Mar 1, 2018 | A reflected cross site scripting attack in the NetIQ Access Manager before 4.3.3 using the "typecontainerid" parameter o... |
| CVE-2017-14799 | MEDIUM | 4.6 | 0.8% | Mar 1, 2018 | A cross site scripting attack in handling the ESP login parameter handling in NetIQ Access Manager before 4.3.3 could be... |
| CVE-2017-18195 | MEDIUM | 5.3 | 11.1% | Feb 26, 2018 | An issue was discovered in tools/conversations/view_ajax.php in Concrete5 before 8.3.0. An unauthenticated user can enum... |
| CVE-2017-14537 | MEDIUM | 6.5 | 39.5% | Feb 16, 2018 | trixbox 2.8.0.4 has path traversal via the xajaxargs array parameter to /maint/index.php?packages or the lang parameter ... |
| CVE-2017-15699 | MEDIUM | 6.5 | 3.2% | Feb 13, 2018 | A Denial of Service vulnerability was found in Apache Qpid Dispatch Router versions 0.7.0 and 0.8.0. To exploit this vul... |
| CVE-2017-14522 | MEDIUM | 6.1 | 1.2% | Jan 26, 2018 | In WonderCMS 2.3.1, the application's input fields accept arbitrary user input resulting in execution of malicious JavaS... |
| CVE-2017-18030 | MEDIUM | 4.4 | 0.4% | Jan 23, 2018 | The cirrus_invalidate_region function in hw/display/cirrus_vga.c in Qemu allows local OS guest privileged users to cause... |
| CVE-2017-12114 | MEDIUM | 6.8 | 1.4% | Jan 19, 2018 | An exploitable improper authorization vulnerability exists in admin_peers API of cpp-ethereum's JSON-RPC (commit 4e10157... |
| CVE-2017-12097 | MEDIUM | 6.1 | 1.0% | Jan 19, 2018 | An exploitable cross site scripting (XSS) vulnerability exists in the filter functionality of the delayed_job_web rails ... |
| CVE-2017-12098 | MEDIUM | 6.1 | 1.3% | Jan 19, 2018 | An exploitable cross site scripting (XSS) vulnerability exists in the add filter functionality of the rails_admin rails ... |
| CVE-2017-12308 | MEDIUM | 6.1 | 0.8% | Jan 18, 2018 | A vulnerability in the web framework of Cisco Small Business Managed Switches software could allow an unauthenticated, r... |
| CVE-2017-12307 | MEDIUM | 6.1 | 0.9% | Jan 18, 2018 | A vulnerability in the web framework of Cisco Small Business Managed Switches software could allow an unauthenticated, r... |
| CVE-2017-15129 | MEDIUM | 4.7 | 0.4% | Jan 9, 2018 | A use-after-free vulnerability was found in network namespaces code affecting the Linux kernel before 4.14.11. The funct... |
| CVE-2017-17837 | MEDIUM | 6.1 | 4.5% | Jan 4, 2018 | The Apache DeltaSpike-JSF 1.8.0 module has a XSS injection leak in the windowId handling. The default size of the window... |
| CVE-2017-5754 | MEDIUM | 5.6 | 84.2% | Jan 4, 2018 | Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized discl... |
| CVE-2017-5753 | MEDIUM | 5.6 | 93.8% | Jan 4, 2018 | Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of ... |
| CVE-2017-5715 | MEDIUM | 5.6 | 74.0% | Jan 4, 2018 | Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized discl... |
| CVE-2017-1000426 | MEDIUM | 6.1 | 0.8% | Jan 2, 2018 | MapProxy version 1.10.3 and older is vulnerable to a Cross Site Scripting attack in the demo service resulting in possib... |
| CVE-2017-1000445 | MEDIUM | 6.5 | 2.3% | Jan 2, 2018 | ImageMagick 7.0.7-1 and older version are vulnerable to null pointer dereference in the MagickCore component and might l... |
| CVE-2017-18005 | MEDIUM | 5.5 | 0.8% | Dec 31, 2017 | Exiv2 0.26 has a Null Pointer Dereference in the Exiv2::DataValue::toLong function in value.cpp, related to crafted meta... |
| CVE-2017-17933 | MEDIUM | 6.1 | 0.9% | Dec 29, 2017 | cgi/surgeftpmgr.cgi (aka the Web Manager interface on TCP port 7021 or 9021) in NetWin SurgeFTP version 23f2 has XSS via... |
| CVE-2017-17760 | MEDIUM | 6.5 | 2.2% | Dec 29, 2017 | OpenCV 3.3.1 has a Buffer Overflow in the cv::PxMDecoder::readData function in grfmt_pxm.cpp, because an incorrect size ... |
| CVE-2017-14363 | MEDIUM | 5.9 | 0.5% | Dec 21, 2017 | Cross-Site Scripting (XSS) vulnerability has been identified in Micro Focus Operations Manager i, versions 10.60, 10.61,... |
| CVE-2017-17828 | MEDIUM | 4.8 | 0.5% | Dec 21, 2017 | Bus Booking Script has XSS via the results.php datepicker parameter or the admin/new_master.php spemail parameter. |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now