2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-17976In Utilities.php in Perfex CRM 1.9.7, Unrestricted file upload can lead to remote code execution.
CVE-2017-14523WonderCMS 2.3.1 is vulnerable to an HTTP Host header injection attack. It uses user-entered values to redirect pages. NO...
CVE-2017-14522MEDIUM6.1In WonderCMS 2.3.1, the application's input fields accept arbitrary user input resulting in execution of malicious JavaS...
CVE-2017-14521In WonderCMS 2.3.1, the upload functionality accepts random application extensions and leads to malicious File Upload.
CVE-2017-12380ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote ...
CVE-2017-12379ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote ...
CVE-2017-12378ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote ...
CVE-2017-12377ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote ...
CVE-2017-12376ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote ...
CVE-2017-12375The ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, rem...
CVE-2017-12374The ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, rem...
CVE-2017-3768An unprivileged attacker with connectivity to the IMM2 could cause a denial of service attack on the IMM2 (Versions earl...
CVE-2017-18076HIGH7.5In strategy.rb in OmniAuth before 1.3.2, the authenticity_token value is improperly protected because POST (in addition ...
CVE-2017-2166Open redirect vulnerability in GroupSession version 4.7.0 and earlier allows an attacker to redirect users to arbitrary ...
CVE-2017-14593Sourcetree for Windows had several argument and command injection bugs in Mercurial and Git repository handling. An atta...
CVE-2017-14592Sourcetree for macOS had several argument and command injection bugs in Mercurial and Git repository handling. An attack...
CVE-2017-1000404The Jenkins Delivery Pipeline Plugin version 1.0.7 and earlier used the unescaped content of the query parameter 'fullsc...
CVE-2017-1000403Jenkins Speaks! Plugin, all current versions, allows users with Job/Configure permission to run arbitrary Groovy code in...
CVE-2017-1000402Jenkins Swarm Plugin Client 3.4 and earlier bundled a version of the commons-httpclient library with the vulnerability C...
CVE-2017-1000401The Jenkins 2.73.1 and earlier, 2.83 and earlier default form control for passwords and other secrets, <f:password/>, su...
CVE-2017-1000400The Jenkins 2.73.1 and earlier, 2.83 and earlier remote API at /job/(job-name)/api contained information about upstream ...
CVE-2017-1000399The Jenkins 2.73.1 and earlier, 2.83 and earlier remote API at /queue/item/(ID)/api showed information about tasks in th...
CVE-2017-1000398The remote API in Jenkins 2.73.1 and earlier, 2.83 and earlier at /computer/(agent-name)/api showed information about ta...
CVE-2017-1000397Jenkins Maven Plugin 2.17 and earlier bundled a version of the commons-httpclient library with the vulnerability CVE-201...
CVE-2017-1000396Jenkins 2.73.1 and earlier, 2.83 and earlier bundled a version of the commons-httpclient library with the vulnerability ...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now