2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-16880 | — | — | 0.8% | Nov 17, 2017 | The dump function in Util/TemplateHelper.php in filp whoops before 2.1.13 has XSS. |
| CVE-2017-1000230 | — | — | 1.0% | Nov 17, 2017 | The Snap7 Server version 1.4.1 can be crashed when the ItemCount field of the ReadVar or WriteVar functions of the S7 pr... |
| CVE-2017-1000227 | — | — | 0.6% | Nov 17, 2017 | Stored XSS in Salutation Responsive WordPress + BuddyPress Theme version 3.0.15 could allow logged-in users to do almost... |
| CVE-2017-1000190 | CRITICAL | 9.1 | 4.7% | Nov 17, 2017 | SimpleXML (latest version 2.7.1) is vulnerable to an XXE vulnerability resulting SSRF, information disclosure, DoS and s... |
| CVE-2017-1000163 | — | — | 2.1% | Nov 17, 2017 | The Phoenix Framework versions 1.0.0 through 1.0.4, 1.1.0 through 1.1.6, 1.2.0, 1.2.2 and 1.3.0-rc.0 are vulnerable to u... |
| CVE-2017-16845 | CRITICAL | 10 | 3.0% | Nov 17, 2017 | hw/input/ps2.c in Qemu does not validate 'rptr' and 'count' values during guest migration, leading to out-of-bounds acce... |
| CVE-2017-14111 | — | — | 2.2% | Nov 17, 2017 | The workstation logging function in Philips IntelliSpace Cardiovascular (ISCV) 2.3.0 and earlier and Xcelera R4.1L1 and ... |
| CVE-2017-1000215 | — | — | 6.5% | Nov 17, 2017 | ROOT xrootd version 4.6.0 and below is vulnerable to an unauthenticated shell command injection resulting in remote code... |
| CVE-2017-1000204 | — | — | — | Nov 17, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-9920. Reason: This candidate is a reservation ... |
| CVE-2017-6168 | — | — | 21.6% | Nov 17, 2017 | On BIG-IP versions 11.6.0-11.6.2 (fixed in 11.6.2 HF1), 12.0.0-12.1.2 HF1 (fixed in 12.1.2 HF2), or 13.0.0-13.0.0 HF2 (f... |
| CVE-2017-1000161 | — | — | — | Nov 17, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA d... |
| CVE-2017-13703 | — | — | 1.0% | Nov 17, 2017 | An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. A denial of service may occur. |
| CVE-2017-13702 | — | — | 0.9% | Nov 17, 2017 | An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. Cookies can be stolen, manipulated, and reused. |
| CVE-2017-13700 | — | — | 0.5% | Nov 17, 2017 | An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. There is XSS in the administration interface. |
| CVE-2017-1000233 | — | — | — | Nov 17, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-11667. Reason: This candidate is a reservation... |
| CVE-2017-1000222 | — | — | — | Nov 17, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA d... |
| CVE-2017-1000170 | HIGH | 7.5 | 57.6% | Nov 17, 2017 | jqueryFileTree 2.1.5 and older Directory Traversal |
| CVE-2017-1000169 | — | — | 4.3% | Nov 17, 2017 | QuickerBB version <= 0.7.2 is vulnerable to arbitrary file writes which can lead to remote code execution. This can lead... |
| CVE-2017-1000168 | — | — | 1.3% | Nov 17, 2017 | sodiumoxide 0.0.13 and older scalarmult() vulnerable to degenerate public keys |
| CVE-2017-16877 | — | — | 14.1% | Nov 17, 2017 | ZEIT Next.js before 2.4.1 has directory traversal under the /_next and /static request namespace, allowing attackers to ... |
| CVE-2017-16819 | — | — | 1.9% | Nov 17, 2017 | A stored cross-site scripting vulnerability in the Icon Time Systems RTC-1000 v2.5.7458 and earlier time clock allows re... |
| CVE-2017-1000192 | — | — | 0.9% | Nov 17, 2017 | Cygnux sysPass version 2.1.7 and older is vulnerable to a Local File Inclusion in the functionality of javascript files ... |
| CVE-2017-1000191 | — | — | 1.3% | Nov 17, 2017 | Jool 3.5.0-3.5.1 is vulnerable to a kernel crashing packet resulting in a DOS. |
| CVE-2017-16875 | — | — | 3.3% | Nov 17, 2017 | An issue was discovered in Teluu pjproject (pjlib and pjlib-util) in PJSIP before 2.7.1. The ioqueue component may issue... |
| CVE-2017-1000212 | — | — | 2.9% | Nov 17, 2017 | Elixir's vim plugin, alchemist.vim is vulnerable to remote code execution in the bundled alchemist-server. A malicious w... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now