2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-1000164 | — | — | 0.8% | Nov 17, 2017 | Tine 2.0 version 2017.02.4 is vulnerable to XSS in the Addressbook resulting code execution and privilege escalation |
| CVE-2017-1000160 | — | — | 0.5% | Nov 17, 2017 | EllisLab ExpressionEngine 3.4.2 is vulnerable to cross-site scripting resulting in PHP code injection |
| CVE-2017-1000158 | CRITICAL | 9.8 | 7.9% | Nov 17, 2017 | CPython (aka Python) up to 2.7.13 is vulnerable to an integer overflow in the PyString_DecodeEscape function in stringob... |
| CVE-2017-1000129 | — | — | 1.1% | Nov 17, 2017 | Serendipity 2.0.3 is vulnerable to a SQL injection in the blog component resulting in information disclosure |
| CVE-2017-1000125 | — | — | 0.9% | Nov 17, 2017 | Codiad(full version) is vulnerable to write anything to configure file in the installation resulting upload a webshell. |
| CVE-2017-1000248 | — | — | 2.0% | Nov 17, 2017 | Redis-store <=v1.3.0 allows unsafe objects to be loaded from redis |
| CVE-2017-1000247 | — | — | 0.9% | Nov 17, 2017 | British Columbia Institute of Technology CodeIgniter 3.1.3 is vulnerable to HTTP Header Injection in the set_status_head... |
| CVE-2017-1000246 | — | — | 0.9% | Nov 17, 2017 | Python package pysaml2 version 4.4.0 and earlier reuses the initialization vector across encryptions in the IDP server, ... |
| CVE-2017-1000237 | CRITICAL | 9.8 | 1.6% | Nov 17, 2017 | I, Librarian version <=4.6 & 4.7 is vulnerable to Server-Side Request Forgery in the ajaxsupplement.php resulting in the... |
| CVE-2017-1000236 | MEDIUM | 6.1 | 0.8% | Nov 17, 2017 | I, Librarian version <=4.6 & 4.7 is vulnerable to Reflected Cross-Site Scripting in the temp.php resulting in an attacke... |
| CVE-2017-1000235 | CRITICAL | 9.8 | 3.2% | Nov 17, 2017 | I, Librarian version <=4.6 & 4.7 is vulnerable to OS Command Injection in batchimport.php resulting the web server being... |
| CVE-2017-1000234 | MEDIUM | 5.3 | 1.2% | Nov 17, 2017 | I, Librarian version <=4.6 & 4.7 is vulnerable to Directory Enumeration in the jqueryFileTree.php resulting in attacker ... |
| CVE-2017-1000232 | — | — | 2.3% | Nov 17, 2017 | A double-free vulnerability in str2host.c in ldns 1.7.0 have unspecified impact and attack vectors. |
| CVE-2017-1000231 | — | — | 2.7% | Nov 17, 2017 | A double-free vulnerability in parse.c in ldns 1.7.0 have unspecified impact and attack vectors. |
| CVE-2017-1000241 | — | — | 0.7% | Nov 17, 2017 | The application OpenEMR version 5.0.0, 5.0.1-dev and prior is affected by vertical privilege escalation vulnerability. T... |
| CVE-2017-1000240 | — | — | 0.7% | Nov 17, 2017 | The application OpenEMR is affected by multiple reflected & stored Cross-Site Scripting (XSS) vulnerabilities affecting ... |
| CVE-2017-1000239 | — | — | 0.5% | Nov 17, 2017 | InvoicePlane version 1.4.10 is vulnerable to a Stored Cross Site Scripting resulting in allowing an authenticated user t... |
| CVE-2017-1000238 | — | — | 1.1% | Nov 17, 2017 | InvoicePlane version 1.4.10 is vulnerable to a Arbitrary File Upload resulting in an authenticated user can upload a mal... |
| CVE-2017-1000228 | — | — | 6.3% | Nov 17, 2017 | nodejs ejs versions older than 2.5.3 is vulnerable to remote code execution due to weak input validation in ejs.renderFi... |
| CVE-2017-1000189 | — | — | 2.3% | Nov 17, 2017 | nodejs ejs version older than 2.5.5 is vulnerable to a denial-of-service due to weak input validation in the ejs.renderF... |
| CVE-2017-1000188 | — | — | 1.2% | Nov 17, 2017 | nodejs ejs version older than 2.5.5 is vulnerable to a Cross-site-scripting in the ejs.renderFile() resulting in code in... |
| CVE-2017-1000173 | — | — | 2.5% | Nov 17, 2017 | Creolabs Gravity Version: 1.0 Heap Overflow Potential Code Execution. By creating a large loop whiling pushing data to a... |
| CVE-2017-1000172 | — | — | 2.4% | Nov 17, 2017 | Creolabs Gravity Version: 1.0 Use-After-Free Possible code execution. An example of a Heap-Use-After-Free after the 'sub... |
| CVE-2017-1000209 | — | — | 0.7% | Nov 17, 2017 | The Java WebSocket client nv-websocket-client does not verify that the server hostname matches a domain name in the subj... |
| CVE-2017-1000208 | — | — | 1.7% | Nov 17, 2017 | A vulnerability in Swagger-Parser's (version <= 1.0.30) yaml parsing functionality results in arbitrary code being execu... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now