2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-17976 | — | — | 12.7% | Jan 26, 2018 | In Utilities.php in Perfex CRM 1.9.7, Unrestricted file upload can lead to remote code execution. |
| CVE-2017-14523 | — | — | 8.2% | Jan 26, 2018 | WonderCMS 2.3.1 is vulnerable to an HTTP Host header injection attack. It uses user-entered values to redirect pages. NO... |
| CVE-2017-14522 | MEDIUM | 6.1 | 1.2% | Jan 26, 2018 | In WonderCMS 2.3.1, the application's input fields accept arbitrary user input resulting in execution of malicious JavaS... |
| CVE-2017-14521 | — | — | 7.4% | Jan 26, 2018 | In WonderCMS 2.3.1, the upload functionality accepts random application extensions and leads to malicious File Upload. |
| CVE-2017-12380 | — | — | 5.2% | Jan 26, 2018 | ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote ... |
| CVE-2017-12379 | — | — | 12.8% | Jan 26, 2018 | ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote ... |
| CVE-2017-12378 | — | — | 2.8% | Jan 26, 2018 | ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote ... |
| CVE-2017-12377 | — | — | 11.8% | Jan 26, 2018 | ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote ... |
| CVE-2017-12376 | — | — | 6.8% | Jan 26, 2018 | ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote ... |
| CVE-2017-12375 | — | — | 5.7% | Jan 26, 2018 | The ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, rem... |
| CVE-2017-12374 | — | — | 5.1% | Jan 26, 2018 | The ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, rem... |
| CVE-2017-3768 | — | — | 1.2% | Jan 26, 2018 | An unprivileged attacker with connectivity to the IMM2 could cause a denial of service attack on the IMM2 (Versions earl... |
| CVE-2017-18076 | HIGH | 7.5 | 2.1% | Jan 26, 2018 | In strategy.rb in OmniAuth before 1.3.2, the authenticity_token value is improperly protected because POST (in addition ... |
| CVE-2017-2166 | — | — | 0.8% | Jan 26, 2018 | Open redirect vulnerability in GroupSession version 4.7.0 and earlier allows an attacker to redirect users to arbitrary ... |
| CVE-2017-14593 | — | — | 5.5% | Jan 26, 2018 | Sourcetree for Windows had several argument and command injection bugs in Mercurial and Git repository handling. An atta... |
| CVE-2017-14592 | — | — | 5.5% | Jan 26, 2018 | Sourcetree for macOS had several argument and command injection bugs in Mercurial and Git repository handling. An attack... |
| CVE-2017-1000404 | — | — | 1.0% | Jan 26, 2018 | The Jenkins Delivery Pipeline Plugin version 1.0.7 and earlier used the unescaped content of the query parameter 'fullsc... |
| CVE-2017-1000403 | — | — | 1.0% | Jan 26, 2018 | Jenkins Speaks! Plugin, all current versions, allows users with Job/Configure permission to run arbitrary Groovy code in... |
| CVE-2017-1000402 | — | — | 0.5% | Jan 26, 2018 | Jenkins Swarm Plugin Client 3.4 and earlier bundled a version of the commons-httpclient library with the vulnerability C... |
| CVE-2017-1000401 | — | — | 0.4% | Jan 26, 2018 | The Jenkins 2.73.1 and earlier, 2.83 and earlier default form control for passwords and other secrets, <f:password/>, su... |
| CVE-2017-1000400 | — | — | 0.8% | Jan 26, 2018 | The Jenkins 2.73.1 and earlier, 2.83 and earlier remote API at /job/(job-name)/api contained information about upstream ... |
| CVE-2017-1000399 | — | — | 1.0% | Jan 26, 2018 | The Jenkins 2.73.1 and earlier, 2.83 and earlier remote API at /queue/item/(ID)/api showed information about tasks in th... |
| CVE-2017-1000398 | — | — | 1.0% | Jan 26, 2018 | The remote API in Jenkins 2.73.1 and earlier, 2.83 and earlier at /computer/(agent-name)/api showed information about ta... |
| CVE-2017-1000397 | — | — | 0.5% | Jan 26, 2018 | Jenkins Maven Plugin 2.17 and earlier bundled a version of the commons-httpclient library with the vulnerability CVE-201... |
| CVE-2017-1000396 | — | — | 0.5% | Jan 26, 2018 | Jenkins 2.73.1 and earlier, 2.83 and earlier bundled a version of the commons-httpclient library with the vulnerability ... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now