2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-12630 | — | — | 1.1% | Dec 18, 2017 | In Apache Drill 1.11.0 and earlier when submitting form from Query page users are able to pass arbitrary script or HTML ... |
| CVE-2017-17651 | — | — | 3.0% | Dec 18, 2017 | Paid To Read Script 2.0.5 has SQL Injection via the admin/userview.php uid parameter, the admin/viewemcamp.php fnum para... |
| CVE-2017-17649 | — | — | 2.5% | Dec 18, 2017 | Readymade Video Sharing Script 3.2 has HTML Injection via the single-video-detail.php comment parameter. |
| CVE-2017-17645 | — | — | 3.0% | Dec 18, 2017 | Bus Booking Script 1.0 has SQL Injection via the txtname parameter to admin/index.php. |
| CVE-2017-17643 | CRITICAL | 9.8 | 3.0% | Dec 18, 2017 | FS Lynda Clone 1.0 has SQL Injection via the keywords parameter to tutorial/. |
| CVE-2017-17741 | — | — | 0.5% | Dec 18, 2017 | The KVM implementation in the Linux kernel through 4.14.7 allows attackers to obtain potentially sensitive information f... |
| CVE-2017-17740 | HIGH | 7.5 | 7.0% | Dec 18, 2017 | contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops module and the memberof overlay are ena... |
| CVE-2017-17739 | — | — | 11.9% | Dec 18, 2017 | The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) has directory traversal via the /storage.html ... |
| CVE-2017-17738 | — | — | 5.8% | Dec 18, 2017 | The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) allows renaming and modifying files via /tools... |
| CVE-2017-17737 | — | — | 2.1% | Dec 18, 2017 | The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) has XSS via the REF parameter to /network_diag... |
| CVE-2017-17735 | — | — | 1.1% | Dec 18, 2017 | CMS Made Simple (CMSMS) before 2.2.5 does not properly cache login information in cookies. |
| CVE-2017-17734 | — | — | 1.1% | Dec 18, 2017 | CMS Made Simple (CMSMS) before 2.2.5 does not properly cache login information in sessions. |
| CVE-2017-17733 | — | — | 44.1% | Dec 18, 2017 | Maccms 8.x allows remote command execution via the wd parameter in an index.php?m=vod-search request. |
| CVE-2017-17731 | — | — | 13.2% | Dec 18, 2017 | DedeCMS through 5.7 has SQL Injection via the $_FILES superglobal to plus/recommend.php. |
| CVE-2017-17730 | — | — | 1.1% | Dec 18, 2017 | DedeCMS through 5.7 has SQL Injection via the logo parameter to plus/flink_add.php. |
| CVE-2017-17727 | — | — | 1.5% | Dec 18, 2017 | DedeCMS through 5.6 allows arbitrary file upload and PHP code execution by embedding the PHP code in a .jpg file, which ... |
| CVE-2017-16997 | — | — | 2.7% | Dec 18, 2017 | elf/dl-load.c in the GNU C Library (aka glibc or libc6) 2.19 through 2.26 mishandles RPATH and RUNPATH containing $ORIGI... |
| CVE-2017-17718 | — | — | 1.3% | Dec 17, 2017 | The Net::LDAP (aka net-ldap) gem before 0.16.0 for Ruby has Missing SSL Certificate Validation. |
| CVE-2017-17717 | — | — | 0.7% | Dec 17, 2017 | Sonatype Nexus Repository Manager through 2.14.5 has weak password encryption with a hardcoded CMMDwoV value in the LDAP... |
| CVE-2017-17716 | — | — | 0.9% | Dec 17, 2017 | GitLab 9.4.x before 9.4.2 does not support LDAP SSL certificate verification, but a verify_certificates LDAP option was ... |
| CVE-2017-16950 | — | — | 0.8% | Dec 17, 2017 | Cross - site scripting (XSS) vulnerability in UrBackup Server before 2.1.20 allows remote attackers to inject arbitrary ... |
| CVE-2017-17714 | — | — | 1.2% | Dec 16, 2017 | Trape before 2017-11-05 has XSS via the /nr red parameter, the /nr vId parameter, the /register User-Agent HTTP header, ... |
| CVE-2017-17713 | — | — | 2.0% | Dec 16, 2017 | Trape before 2017-11-05 has SQL injection via the /nr red parameter, the /nr vId parameter, the /register User-Agent HTT... |
| CVE-2017-17715 | — | — | 1.7% | Dec 16, 2017 | The saveFile method in MediaController.java in the Telegram Messenger application before 2017-12-08 for Android allows d... |
| CVE-2017-14134 | — | — | 0.6% | Dec 16, 2017 | A Reflected XSS Vulnerability affects the forgotten password page of Maplesoft Maple T.A. 2016.0.6 (Customer Hosted) via... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now