2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-17951PHP Scripts Mall PHP Multivendor Ecommerce has SQL Injection via the shopping-cart.php cusid parameter.
CVE-2017-17950Cells Blog 3.5 has SQL Injection via the pub_readpost.php ptid parameter.
CVE-2017-17949Cells Blog 3.5 has XSS via the pub_readpost.php fmid parameter.
CVE-2017-17948Cells Blog 3.5 has XSS via the jfdname parameter in an act=showpic request.
CVE-2017-15667In Flexense SysGauge Server 3.6.18, the Control Protocol suffers from a denial of service. The attack vector is a crafte...
CVE-2017-5641CRITICAL9.8Previous versions of Apache Flex BlazeDS (4.7.2 and earlier) did not restrict which types were allowed for AMF(X) object...
CVE-2017-15892Multiple cross-site scripting (XSS) vulnerabilities in Slash Command Creator in Synology Chat before 2.0.0-1124 allow re...
CVE-2017-15886Server-side request forgery (SSRF) vulnerability in Link Preview in Synology Chat before 2.0.0-1124 allows remote authen...
CVE-2017-15711Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ...
CVE-2017-17942In LibTIFF 4.0.9, there is a heap-based buffer over-read in the function PackBitsEncode in tif_packbits.c.
CVE-2017-17941PHP Scripts Mall Single Theater Booking has SQL Injection via the admin/movieview.php movieid parameter.
CVE-2017-17940PHP Scripts Mall Single Theater Booking has XSS via the title parameter to admin/sitesettings.php.
CVE-2017-17939PHP Scripts Mall Single Theater Booking has CSRF via admin/sitesettings.php.
CVE-2017-17938PHP Scripts Mall Single Theater Booking has XSS via the admin/viewtheatre.php theatreid parameter.
CVE-2017-17937Vanguard Marketplace Digital Products PHP has XSS via the phps_query parameter to /search.
CVE-2017-17936Vanguard Marketplace Digital Products PHP has CSRF via /search.
CVE-2017-17932A buffer overflow vulnerability exists in MediaServer.exe in ALLPlayer ALLMediaServer 0.95 and earlier that could allow ...
CVE-2017-10910MQTT.js 2.x.x prior to 2.15.0 issue in handling PUBLISH tickets may lead to an attacker causing a denial-of-service cond...
CVE-2017-9608The dnxhd decoder in FFmpeg before 3.2.6, and 3.3.x before 3.3.3 allows remote attackers to cause a denial of service (N...
CVE-2017-11698Heap-based buffer overflow in the __get_page function in lib/dbm/src/h_page.c in Mozilla Network Security Services (NSS)...
CVE-2017-11697The __hash_open function in hash.c:229 in Mozilla Network Security Services (NSS) allows context-dependent attackers to ...
CVE-2017-11696Heap-based buffer overflow in the __hash_open function in lib/dbm/src/hash.c in Mozilla Network Security Services (NSS) ...
CVE-2017-11695Heap-based buffer overflow in the alloc_segs function in lib/dbm/src/hash.c in Mozilla Network Security Services (NSS) a...
CVE-2017-16768Cross-site scripting (XSS) vulnerability in User Policy editor in Synology MailPlus Server before 1.4.0-0415 allows remo...
CVE-2017-13056The launchURL function in PDF-XChange Viewer 2.5 (Build 314.0) might allow remote attackers to execute arbitrary code vi...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now