2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-15542Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was...
CVE-2017-15541Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was...
CVE-2017-15540Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was...
CVE-2017-14393Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was...
CVE-2017-14392Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was...
CVE-2017-14391Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was...
CVE-2017-1000501Awstats version 7.6 and earlier is vulnerable to a path traversal flaw in the handling of the "config" and "migrate" par...
CVE-2017-1000500Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-12161. Reason: This candidate is a reservation...
CVE-2017-1000467LavaLite version 5.2.4 is vulnerable to stored cross-site scripting vulnerability, within the blog creation page, which ...
CVE-2017-1000499phpMyAdmin versions 4.7.x (prior to 4.7.6.1/4.7.7) are vulnerable to a CSRF weakness. By deceiving a user to click on a ...
CVE-2017-1000498HIGH7.8AndroidSVG version 1.2.2 is vulnerable to XXE attacks in the SVG parsing component resulting in denial of service and po...
CVE-2017-1000497CRITICAL9.8Pepperminty-Wiki version 0.15 is vulnerable to XXE attacks in the getsvgsize function resulting in denial of service and...
CVE-2017-1000496Commsy version 9.0.0 is vulnerable to XXE attacks in the configuration import functionality resulting in denial of servi...
CVE-2017-1000495QuickApps CMS version 2.0.0 is vulnerable to Stored Cross-site Scripting in the user's real name field resulting in deni...
CVE-2017-1000494Uninitialized stack variable vulnerability in NameValueParserEndElt (upnpreplyparse.c) in miniupnpd < 2.0 allows an atta...
CVE-2017-18017CRITICAL9.8The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36,...
CVE-2017-1000493Rocket.Chat Server version 0.59 and prior is vulnerable to a NoSQL injection leading to administrator account takeover
CVE-2017-1000492Leanote-desktop version v2.5 is vulnerable to a XSS which leads to code execution due to enabled node integration
CVE-2017-1000491Shiba markdown live preview app version 1.1.0 is vulnerable to XSS which leads to code execution due to enabled node int...
CVE-2017-1000466Invoice Ninja version 3.8.1 is vulnerable to stored cross-site scripting vulnerability, within the invoice creation page...
CVE-2017-1000463Leafpub version 1.2.0-beta6 is vulnerable to stored cross-site scripting vulnerability, within the edit blog post page, ...
CVE-2017-1000459Leanote version <= 2.5 is vulnerable to XSS due to not sanitized input in markdown notes
CVE-2017-1000438In OMERO 5.3.3 or earlier a user could create an OriginalFile and adjust its path such that it now points to another use...
CVE-2017-1000437Creolabs Gravity 1.0 contains a stack based buffer overflow in the operator_string_add function, resulting in remote cod...
CVE-2017-1000434Wordpress plugin Furikake version 0.1.0 is vulnerable to an Open Redirect The furikake-redirect parameter on a page allo...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now