2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-17584CRITICAL9.8FS Makemytrip Clone 1.0 has SQL Injection via the show-flight-result.php fl_orig or fl_dest parameter.
CVE-2017-17583CRITICAL9.8FS Shutterstock Clone 1.0 has SQL Injection via the /Category keywords parameter.
CVE-2017-17582CRITICAL9.8FS Grubhub Clone 1.0 has SQL Injection via the /food keywords parameter.
CVE-2017-17581CRITICAL9.8FS Quibids Clone 1.0 has SQL Injection via the itechd.php productid parameter.
CVE-2017-17580CRITICAL9.8FS Linkedin Clone 1.0 has SQL Injection via the group.php grid parameter, profile.php fid parameter, or company_details....
CVE-2017-17579CRITICAL9.8FS Freelancer Clone 1.0 has SQL Injection via the profile.php u parameter.
CVE-2017-17578CRITICAL9.8FS Crowdfunding Script 1.0 has SQL Injection via the latest_news_details.php id parameter.
CVE-2017-17577CRITICAL9.8FS Trademe Clone 1.0 has SQL Injection via the search_item.php search parameter or the general_item_details.php id param...
CVE-2017-17576CRITICAL9.8FS Gigs Script 1.0 has SQL Injection via the browse-category.php cat parameter, browse-scategory.php sc parameter, or se...
CVE-2017-17575CRITICAL9.8FS Groupon Clone 1.0 has SQL Injection via the item_details.php id parameter or the vendor_details.php id parameter.
CVE-2017-17574CRITICAL9.8FS Care Clone 1.0 has SQL Injection via the searchJob.php jobType or jobFrequency parameter.
CVE-2017-17573FS Ebay Clone 1.0 has SQL Injection via the product.php id parameter, or the search.php category_id or sub_category_id p...
CVE-2017-17572CRITICAL9.8FS Amazon Clone 1.0 has SQL Injection via the PATH_INFO to /VerAyari.
CVE-2017-17571CRITICAL9.8FS Foodpanda Clone 1.0 has SQL Injection via the /food keywords parameter.
CVE-2017-17570CRITICAL9.8FS Expedia Clone 1.0 has SQL Injection via the pages.php or content.php id parameter, or the show-flight-result.php fl_o...
CVE-2017-17569Scubez Posty Readymade Classifieds has XSS via the admin/user_activate_submit.php ID parameter.
CVE-2017-17568Scubez Posty Readymade Classifieds has Incorrect Access Control for visiting admin/user_activate_submit.php (aka the bac...
CVE-2017-17567Scubez Posty Readymade Classifieds has SQL Injection via the admin/user_activate_submit.php ID parameter.
CVE-2017-17538MikroTik v6.40.5 devices allow remote attackers to cause a denial of service via a flood of ICMP packets.
CVE-2017-5534HIGH8.8The tibbr user profiles components of tibbr Community, and tibbr Enterprise expose a weakness in an improperly sandboxed...
CVE-2017-5530HIGH8.1The tibbr web server components of tibbr Community, and tibbr Enterprise contain SAML protocol handling errors which may...
CVE-2017-4942MEDIUM4.9VMware AirWatch Console (AWC) contains a Broken Access Control vulnerability. Successful exploitation of this issue coul...
CVE-2017-14362HIGH7.3Cross-Site Request Forgery vulnerability in Micro Focus Project and Portfolio Management Center, version 9.32. This vuln...
CVE-2017-14361HIGH7.4Man-In-The-Middle vulnerability in Micro Focus Project and Portfolio Management Center, version 9.32. This vulnerability...
CVE-2017-13099HIGH7.5wolfSSL prior to version 3.12.2 provides a weak Bleichenbacher oracle when any TLS cipher suite using RSA key exchange i...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now