2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-15542 | — | — | — | Jan 3, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was... |
| CVE-2017-15541 | — | — | — | Jan 3, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was... |
| CVE-2017-15540 | — | — | — | Jan 3, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was... |
| CVE-2017-14393 | — | — | — | Jan 3, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was... |
| CVE-2017-14392 | — | — | — | Jan 3, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was... |
| CVE-2017-14391 | — | — | — | Jan 3, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was... |
| CVE-2017-1000501 | — | — | 4.4% | Jan 3, 2018 | Awstats version 7.6 and earlier is vulnerable to a path traversal flaw in the handling of the "config" and "migrate" par... |
| CVE-2017-1000500 | — | — | — | Jan 3, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-12161. Reason: This candidate is a reservation... |
| CVE-2017-1000467 | — | — | 0.7% | Jan 3, 2018 | LavaLite version 5.2.4 is vulnerable to stored cross-site scripting vulnerability, within the blog creation page, which ... |
| CVE-2017-1000499 | — | — | 8.5% | Jan 3, 2018 | phpMyAdmin versions 4.7.x (prior to 4.7.6.1/4.7.7) are vulnerable to a CSRF weakness. By deceiving a user to click on a ... |
| CVE-2017-1000498 | HIGH | 7.8 | 1.6% | Jan 3, 2018 | AndroidSVG version 1.2.2 is vulnerable to XXE attacks in the SVG parsing component resulting in denial of service and po... |
| CVE-2017-1000497 | CRITICAL | 9.8 | 2.5% | Jan 3, 2018 | Pepperminty-Wiki version 0.15 is vulnerable to XXE attacks in the getsvgsize function resulting in denial of service and... |
| CVE-2017-1000496 | — | — | 1.7% | Jan 3, 2018 | Commsy version 9.0.0 is vulnerable to XXE attacks in the configuration import functionality resulting in denial of servi... |
| CVE-2017-1000495 | — | — | 0.6% | Jan 3, 2018 | QuickApps CMS version 2.0.0 is vulnerable to Stored Cross-site Scripting in the user's real name field resulting in deni... |
| CVE-2017-1000494 | — | — | 0.5% | Jan 3, 2018 | Uninitialized stack variable vulnerability in NameValueParserEndElt (upnpreplyparse.c) in miniupnpd < 2.0 allows an atta... |
| CVE-2017-18017 | CRITICAL | 9.8 | 52.2% | Jan 3, 2018 | The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36,... |
| CVE-2017-1000493 | — | — | 1.7% | Jan 3, 2018 | Rocket.Chat Server version 0.59 and prior is vulnerable to a NoSQL injection leading to administrator account takeover |
| CVE-2017-1000492 | — | — | 1.0% | Jan 3, 2018 | Leanote-desktop version v2.5 is vulnerable to a XSS which leads to code execution due to enabled node integration |
| CVE-2017-1000491 | — | — | 1.1% | Jan 3, 2018 | Shiba markdown live preview app version 1.1.0 is vulnerable to XSS which leads to code execution due to enabled node int... |
| CVE-2017-1000466 | — | — | 0.8% | Jan 3, 2018 | Invoice Ninja version 3.8.1 is vulnerable to stored cross-site scripting vulnerability, within the invoice creation page... |
| CVE-2017-1000463 | — | — | 0.7% | Jan 3, 2018 | Leafpub version 1.2.0-beta6 is vulnerable to stored cross-site scripting vulnerability, within the edit blog post page, ... |
| CVE-2017-1000459 | — | — | 0.8% | Jan 3, 2018 | Leanote version <= 2.5 is vulnerable to XSS due to not sanitized input in markdown notes |
| CVE-2017-1000438 | — | — | 0.9% | Jan 2, 2018 | In OMERO 5.3.3 or earlier a user could create an OriginalFile and adjust its path such that it now points to another use... |
| CVE-2017-1000437 | — | — | 3.8% | Jan 2, 2018 | Creolabs Gravity 1.0 contains a stack based buffer overflow in the operator_string_add function, resulting in remote cod... |
| CVE-2017-1000434 | — | — | 0.9% | Jan 2, 2018 | Wordpress plugin Furikake version 0.1.0 is vulnerable to an Open Redirect The furikake-redirect parameter on a page allo... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now