2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-17951 | — | — | 1.2% | Dec 28, 2017 | PHP Scripts Mall PHP Multivendor Ecommerce has SQL Injection via the shopping-cart.php cusid parameter. |
| CVE-2017-17950 | — | — | 1.0% | Dec 28, 2017 | Cells Blog 3.5 has SQL Injection via the pub_readpost.php ptid parameter. |
| CVE-2017-17949 | — | — | 0.7% | Dec 28, 2017 | Cells Blog 3.5 has XSS via the pub_readpost.php fmid parameter. |
| CVE-2017-17948 | — | — | 0.7% | Dec 28, 2017 | Cells Blog 3.5 has XSS via the jfdname parameter in an act=showpic request. |
| CVE-2017-15667 | — | — | 3.8% | Dec 28, 2017 | In Flexense SysGauge Server 3.6.18, the Control Protocol suffers from a denial of service. The attack vector is a crafte... |
| CVE-2017-5641 | CRITICAL | 9.8 | 21.3% | Dec 28, 2017 | Previous versions of Apache Flex BlazeDS (4.7.2 and earlier) did not restrict which types were allowed for AMF(X) object... |
| CVE-2017-15892 | — | — | 1.0% | Dec 28, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in Slash Command Creator in Synology Chat before 2.0.0-1124 allow re... |
| CVE-2017-15886 | — | — | 1.6% | Dec 28, 2017 | Server-side request forgery (SSRF) vulnerability in Link Preview in Synology Chat before 2.0.0-1124 allows remote authen... |
| CVE-2017-15711 | — | — | — | Dec 28, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2017-17942 | — | — | 2.4% | Dec 28, 2017 | In LibTIFF 4.0.9, there is a heap-based buffer over-read in the function PackBitsEncode in tif_packbits.c. |
| CVE-2017-17941 | — | — | 0.9% | Dec 28, 2017 | PHP Scripts Mall Single Theater Booking has SQL Injection via the admin/movieview.php movieid parameter. |
| CVE-2017-17940 | — | — | 0.5% | Dec 28, 2017 | PHP Scripts Mall Single Theater Booking has XSS via the title parameter to admin/sitesettings.php. |
| CVE-2017-17939 | — | — | 0.5% | Dec 28, 2017 | PHP Scripts Mall Single Theater Booking has CSRF via admin/sitesettings.php. |
| CVE-2017-17938 | — | — | 0.5% | Dec 28, 2017 | PHP Scripts Mall Single Theater Booking has XSS via the admin/viewtheatre.php theatreid parameter. |
| CVE-2017-17937 | — | — | 0.6% | Dec 28, 2017 | Vanguard Marketplace Digital Products PHP has XSS via the phps_query parameter to /search. |
| CVE-2017-17936 | — | — | 0.5% | Dec 28, 2017 | Vanguard Marketplace Digital Products PHP has CSRF via /search. |
| CVE-2017-17932 | — | — | 53.3% | Dec 28, 2017 | A buffer overflow vulnerability exists in MediaServer.exe in ALLPlayer ALLMediaServer 0.95 and earlier that could allow ... |
| CVE-2017-10910 | — | — | 2.2% | Dec 28, 2017 | MQTT.js 2.x.x prior to 2.15.0 issue in handling PUBLISH tickets may lead to an attacker causing a denial-of-service cond... |
| CVE-2017-9608 | — | — | 4.5% | Dec 27, 2017 | The dnxhd decoder in FFmpeg before 3.2.6, and 3.3.x before 3.3.3 allows remote attackers to cause a denial of service (N... |
| CVE-2017-11698 | — | — | 0.7% | Dec 27, 2017 | Heap-based buffer overflow in the __get_page function in lib/dbm/src/h_page.c in Mozilla Network Security Services (NSS)... |
| CVE-2017-11697 | — | — | 0.5% | Dec 27, 2017 | The __hash_open function in hash.c:229 in Mozilla Network Security Services (NSS) allows context-dependent attackers to ... |
| CVE-2017-11696 | — | — | 0.7% | Dec 27, 2017 | Heap-based buffer overflow in the __hash_open function in lib/dbm/src/hash.c in Mozilla Network Security Services (NSS) ... |
| CVE-2017-11695 | — | — | 0.7% | Dec 27, 2017 | Heap-based buffer overflow in the alloc_segs function in lib/dbm/src/hash.c in Mozilla Network Security Services (NSS) a... |
| CVE-2017-16768 | — | — | 1.0% | Dec 27, 2017 | Cross-site scripting (XSS) vulnerability in User Policy editor in Synology MailPlus Server before 1.4.0-0415 allows remo... |
| CVE-2017-13056 | — | — | 5.6% | Dec 27, 2017 | The launchURL function in PDF-XChange Viewer 2.5 (Build 314.0) might allow remote attackers to execute arbitrary code vi... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now