2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2017-8303CRITICAL9.8An issue was discovered on Accellion FTA devices before FTA_9_12_180. seos/1000/find.api allows Remote Code Execution wi...
CVE-2017-8775CRITICAL9.8Quick Heal Internet Security 10.1.0.316, Quick Heal Total Security 10.1.0.316, and Quick Heal AntiVirus Pro 10.1.0.316 a...
CVE-2017-8774CRITICAL9.8Quick Heal Internet Security 10.1.0.316, Quick Heal Total Security 10.1.0.316, and Quick Heal AntiVirus Pro 10.1.0.316 a...
CVE-2017-8773CRITICAL9.8Quick Heal Internet Security 10.1.0.316, Quick Heal Total Security 10.1.0.316, and Quick Heal AntiVirus Pro 10.1.0.316 a...
CVE-2017-5689CRITICAL9.8An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Mana...
CVE-2017-6519CRITICAL9.1avahi-daemon in Avahi through 0.6.32 and 0.7 inadvertently responds to IPv6 unicast queries with source addresses that a...
CVE-2017-2096CRITICAL9.8smalruby-editor v0.4.0 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.
CVE-2017-7895CRITICAL9.8The NFSv2 and NFSv3 server implementations in the Linux kernel through 4.10.13 lack certain checks for the end of a buff...
CVE-2017-3066CRITICAL9.8Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier hav...
CVE-2017-8110CRITICAL10www.modified-shop.org modified eCommerce Shopsoftware 2.0.2.2 rev 10690 has XXE in api/it-recht-kanzlei/api-it-recht-kan...
CVE-2017-5158CRITICAL9.8An Information Exposure issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 an...
CVE-2017-5645CRITICAL9.8In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events...
CVE-2017-7858CRITICAL9.8FreeType 2 before 2017-03-07 has an out-of-bounds write related to the TT_Get_MM_Var function in truetype/ttgxvar.c and ...
CVE-2017-7857CRITICAL9.8FreeType 2 before 2017-03-08 has an out-of-bounds write caused by a heap-based buffer overflow related to the TT_Get_MM_...
CVE-2017-7689CRITICAL9.8A Command Injection vulnerability in Schneider Electric homeLYnk Controller exists in all versions before 1.5.0.
CVE-2017-7576CRITICAL9.8DragonWave Horizon 1.01.03 wireless radios have hardcoded login credentials (such as the username of energetic and passw...
CVE-2017-7575CRITICAL9.8Schneider Electric Modicon TM221CE16R 1.3.3.3 devices allow remote attackers to discover the application-protection pass...
CVE-2017-7574CRITICAL9.8Schneider Electric SoMachine Basic 1.4 SP1 and Schneider Electric Modicon TM221CE16R 1.3.3.3 devices have a hardcoded-ke...
CVE-2017-3834CRITICAL9.8A vulnerability in Cisco Aironet 1830 Series and Cisco Aironet 1850 Series Access Points running Cisco Mobility Express ...
CVE-2017-7410CRITICAL9.8Multiple SQL injection vulnerabilities in account/signup.php and account/signup2.php in WebsiteBaker 2.10.0 and earlier ...
CVE-2017-7324CRITICAL9.8setup/templates/findcore.php in MODX Revolution 2.5.4-pl and earlier allows remote attackers to execute arbitrary PHP co...
CVE-2017-7321CRITICAL9.8setup/controllers/welcome.php in MODX Revolution 2.5.4-pl and earlier allows remote attackers to execute arbitrary PHP c...
CVE-2017-7269CRITICAL9.8Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in...
CVE-2017-5511CRITICAL9.8coders/psd.c in ImageMagick allows remote attackers to have unspecified impact by leveraging an improper cast, which tri...
CVE-2017-5897CRITICAL9.8The ip6gre_err function in net/ipv6/ip6_gre.c in the Linux kernel allows remote attackers to have unspecified impact via...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now