2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-8303 | CRITICAL | 9.8 | 24.2% | May 5, 2017 | An issue was discovered on Accellion FTA devices before FTA_9_12_180. seos/1000/find.api allows Remote Code Execution wi... |
| CVE-2017-8775 | CRITICAL | 9.8 | 1.2% | May 4, 2017 | Quick Heal Internet Security 10.1.0.316, Quick Heal Total Security 10.1.0.316, and Quick Heal AntiVirus Pro 10.1.0.316 a... |
| CVE-2017-8774 | CRITICAL | 9.8 | 1.2% | May 4, 2017 | Quick Heal Internet Security 10.1.0.316, Quick Heal Total Security 10.1.0.316, and Quick Heal AntiVirus Pro 10.1.0.316 a... |
| CVE-2017-8773 | CRITICAL | 9.8 | 2.3% | May 4, 2017 | Quick Heal Internet Security 10.1.0.316, Quick Heal Total Security 10.1.0.316, and Quick Heal AntiVirus Pro 10.1.0.316 a... |
| CVE-2017-5689 | CRITICAL | 9.8 | 92.2% | May 2, 2017 | An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Mana... |
| CVE-2017-6519 | CRITICAL | 9.1 | 3.1% | May 1, 2017 | avahi-daemon in Avahi through 0.6.32 and 0.7 inadvertently responds to IPv6 unicast queries with source addresses that a... |
| CVE-2017-2096 | CRITICAL | 9.8 | 6.2% | Apr 28, 2017 | smalruby-editor v0.4.0 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors. |
| CVE-2017-7895 | CRITICAL | 9.8 | 10.8% | Apr 28, 2017 | The NFSv2 and NFSv3 server implementations in the Linux kernel through 4.10.13 lack certain checks for the end of a buff... |
| CVE-2017-3066 | CRITICAL | 9.8 | 90.6% | Apr 27, 2017 | Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier hav... |
| CVE-2017-8110 | CRITICAL | 10 | 1.1% | Apr 25, 2017 | www.modified-shop.org modified eCommerce Shopsoftware 2.0.2.2 rev 10690 has XXE in api/it-recht-kanzlei/api-it-recht-kan... |
| CVE-2017-5158 | CRITICAL | 9.8 | 2.4% | Apr 20, 2017 | An Information Exposure issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 an... |
| CVE-2017-5645 | CRITICAL | 9.8 | 89.0% | Apr 17, 2017 | In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events... |
| CVE-2017-7858 | CRITICAL | 9.8 | 3.4% | Apr 14, 2017 | FreeType 2 before 2017-03-07 has an out-of-bounds write related to the TT_Get_MM_Var function in truetype/ttgxvar.c and ... |
| CVE-2017-7857 | CRITICAL | 9.8 | 3.6% | Apr 14, 2017 | FreeType 2 before 2017-03-08 has an out-of-bounds write caused by a heap-based buffer overflow related to the TT_Get_MM_... |
| CVE-2017-7689 | CRITICAL | 9.8 | 5.5% | Apr 11, 2017 | A Command Injection vulnerability in Schneider Electric homeLYnk Controller exists in all versions before 1.5.0. |
| CVE-2017-7576 | CRITICAL | 9.8 | 1.3% | Apr 6, 2017 | DragonWave Horizon 1.01.03 wireless radios have hardcoded login credentials (such as the username of energetic and passw... |
| CVE-2017-7575 | CRITICAL | 9.8 | 4.0% | Apr 6, 2017 | Schneider Electric Modicon TM221CE16R 1.3.3.3 devices allow remote attackers to discover the application-protection pass... |
| CVE-2017-7574 | CRITICAL | 9.8 | 1.2% | Apr 6, 2017 | Schneider Electric SoMachine Basic 1.4 SP1 and Schneider Electric Modicon TM221CE16R 1.3.3.3 devices have a hardcoded-ke... |
| CVE-2017-3834 | CRITICAL | 9.8 | 4.5% | Apr 6, 2017 | A vulnerability in Cisco Aironet 1830 Series and Cisco Aironet 1850 Series Access Points running Cisco Mobility Express ... |
| CVE-2017-7410 | CRITICAL | 9.8 | 2.9% | Apr 3, 2017 | Multiple SQL injection vulnerabilities in account/signup.php and account/signup2.php in WebsiteBaker 2.10.0 and earlier ... |
| CVE-2017-7324 | CRITICAL | 9.8 | 2.1% | Mar 30, 2017 | setup/templates/findcore.php in MODX Revolution 2.5.4-pl and earlier allows remote attackers to execute arbitrary PHP co... |
| CVE-2017-7321 | CRITICAL | 9.8 | 2.1% | Mar 30, 2017 | setup/controllers/welcome.php in MODX Revolution 2.5.4-pl and earlier allows remote attackers to execute arbitrary PHP c... |
| CVE-2017-7269 | CRITICAL | 9.8 | 99.8% | Mar 27, 2017 | Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in... |
| CVE-2017-5511 | CRITICAL | 9.8 | 5.5% | Mar 24, 2017 | coders/psd.c in ImageMagick allows remote attackers to have unspecified impact by leveraging an improper cast, which tri... |
| CVE-2017-5897 | CRITICAL | 9.8 | 5.0% | Mar 23, 2017 | The ip6gre_err function in net/ipv6/ip6_gre.c in the Linux kernel allows remote attackers to have unspecified impact via... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now