2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-5261 | — | — | 8.9% | Dec 20, 2017 | In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, the 'ping' and 'traceroute' functions of the web ad... |
| CVE-2017-5260 | — | — | 8.1% | Dec 20, 2017 | In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, although the option to access the configuration fil... |
| CVE-2017-5259 | — | — | 39.2% | Dec 20, 2017 | In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, an undocumented, root-privilege administration web ... |
| CVE-2017-5258 | — | — | 0.5% | Dec 20, 2017 | In version 3.5 and prior of Cambium Networks ePMP firmware, an attacker who knows or can guess the RW community string c... |
| CVE-2017-5257 | — | — | 0.5% | Dec 20, 2017 | In version 3.5 and prior of Cambium Networks ePMP firmware, an attacker who knows (or guesses) the SNMP read/write (RW) ... |
| CVE-2017-5256 | — | — | 0.5% | Dec 20, 2017 | In version 3.5 and prior of Cambium Networks ePMP firmware, all authenticated users have the ability to update the Devic... |
| CVE-2017-5255 | — | — | 74.6% | Dec 20, 2017 | In version 3.5 and prior of Cambium Networks ePMP firmware, a lack of input sanitation for certain parameters on the web... |
| CVE-2017-5254 | — | — | 53.7% | Dec 20, 2017 | In version 3.5 and prior of Cambium Networks ePMP firmware, the non-administrative users 'installer' and 'home' have the... |
| CVE-2017-6094 | — | — | 1.2% | Dec 20, 2017 | CPEs used by subscribers on the access network receive their individual configuration settings from a central GAPS insta... |
| CVE-2017-17747 | — | — | 0.7% | Dec 20, 2017 | Weak access controls in the Device Logout functionality on the TP-Link TL-SG108E v1.0.0 allow remote attackers to call t... |
| CVE-2017-17746 | — | — | 2.0% | Dec 20, 2017 | Weak access control methods on the TP-Link TL-SG108E 1.0.0 allow any user on a NAT network with an authenticated adminis... |
| CVE-2017-17745 | — | — | 0.6% | Dec 20, 2017 | Cross-site scripting (XSS) vulnerability in system_name_set.cgi in TP-Link TL-SG108E 1.0.0 allows authenticated remote a... |
| CVE-2017-16735 | — | — | 1.0% | Dec 20, 2017 | A SQL Injection issue was discovered in Ecava IntegraXor v 6.1.1030.1 and prior. The SQL Injection vulnerability has bee... |
| CVE-2017-16733 | — | — | 0.9% | Dec 20, 2017 | A SQL Injection issue was discovered in Ecava IntegraXor v 6.1.1030.1 and prior. The SQL Injection vulnerability has bee... |
| CVE-2017-16731 | — | — | 0.7% | Dec 20, 2017 | An Unprotected Transport of Credentials issue was discovered in ABB Ellipse 8.3 through Ellipse 8.9 released prior to De... |
| CVE-2017-16725 | — | — | 9.2% | Dec 20, 2017 | A Stack-based Buffer Overflow issue was discovered in Xiongmai Technology IP Cameras and DVRs using the NetSurveillance ... |
| CVE-2017-16717 | — | — | 1.9% | Dec 20, 2017 | A Heap-based Buffer Overflow issue was discovered in WECON LeviStudio HMI. The heap-based buffer overflow vulnerability ... |
| CVE-2017-1757 | — | — | 1.6% | Dec 20, 2017 | IBM Security Guardium 10.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements... |
| CVE-2017-1751 | — | — | 0.7% | Dec 20, 2017 | IBM Robotic Process Automation with Automation Anywhere 10.0.0 is vulnerable to cross-site scripting. This vulnerability... |
| CVE-2017-1746 | — | — | 0.5% | Dec 20, 2017 | IBM Jazz for Service Management (IBM Tivoli Components 1.1.3) is vulnerable to cross-site request forgery which could al... |
| CVE-2017-1696 | — | — | 2.7% | Dec 20, 2017 | IBM QRadar 7.2 and 7.3 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sendi... |
| CVE-2017-1694 | — | — | 0.8% | Dec 20, 2017 | IBM Integration Bus 9.0 and 10.0 transmits user credentials in plain in clear text which can be read by an attacker usin... |
| CVE-2017-1631 | — | — | 0.5% | Dec 20, 2017 | IBM Jazz for Service Management (IBM Tivoli Components 1.1.3) is vulnerable to cross-site request forgery which could al... |
| CVE-2017-1600 | — | — | 0.5% | Dec 20, 2017 | IBM Security Guardium 10.0 Database Activity Monitor is vulnerable to cross-site scripting. This vulnerability allows us... |
| CVE-2017-1598 | — | — | 0.8% | Dec 20, 2017 | IBM Security Guardium 10.0 Database Activity Monitor uses weaker than expected cryptographic algorithms that could allow... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now