2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-16855 | — | — | — | Nov 16, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-8638. Reason: This candidate is a reservation ... |
| CVE-2017-16853 | — | — | 1.4% | Nov 16, 2017 | The DynamicMetadataProvider class in saml/saml2/metadata/impl/DynamicMetadataProvider.cpp in OpenSAML-C in OpenSAML befo... |
| CVE-2017-16852 | — | — | 1.1% | Nov 16, 2017 | shibsp/metadata/DynamicMetadataProvider.cpp in the Dynamic MetadataProvider plugin in Shibboleth Service Provider before... |
| CVE-2017-16851 | — | — | 16.6% | Nov 16, 2017 | Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /MyPage.do widgetid parameter. |
| CVE-2017-16850 | — | — | 16.6% | Nov 16, 2017 | Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /showresource.do resourceid pa... |
| CVE-2017-16849 | — | — | 16.6% | Nov 16, 2017 | Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /MyPage.do?method=viewDashBoar... |
| CVE-2017-16848 | — | — | 15.1% | Nov 16, 2017 | Zoho ManageEngine Applications Manager 13 allows SQL injection via the /manageConfMons.do groupname parameter. |
| CVE-2017-16847 | — | — | 16.6% | Nov 16, 2017 | Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /showresource.do resourceid pa... |
| CVE-2017-16846 | — | — | 16.6% | Nov 16, 2017 | Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /manageApplications.do?method=... |
| CVE-2017-16844 | — | — | 12.5% | Nov 16, 2017 | Heap-based buffer overflow in the loadbuf function in formisc.c in formail in procmail 3.22 allows remote attackers to c... |
| CVE-2017-16777 | — | — | 1.0% | Nov 16, 2017 | If HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 5.0.3 is installed but VMware Fusion is not, a loc... |
| CVE-2017-16560 | — | — | 0.4% | Nov 16, 2017 | SanDisk Secure Access 3.01 vault decrypts and copies encrypted files to a temporary folder, where they can remain indefi... |
| CVE-2017-15864 | — | — | 1.8% | Nov 16, 2017 | In the Agent Frontend in Open Ticket Request System (OTRS) 3.3.x through 3.3.18, with a crafted URL it is possible to ga... |
| CVE-2017-5738 | — | — | 1.5% | Nov 16, 2017 | Escalation of privilege vulnerability in admin portal for Intel Unite App versions 3.1.32.12, 3.1.41.18 and 3.1.45.26 al... |
| CVE-2017-12350 | — | — | 0.3% | Nov 16, 2017 | A vulnerability in Cisco Umbrella Insights Virtual Appliances 2.1.0 and earlier could allow an authenticated, local atta... |
| CVE-2017-12337 | — | — | 6.4% | Nov 16, 2017 | A vulnerability in the upgrade mechanism of Cisco collaboration products based on the Cisco Voice Operating System softw... |
| CVE-2017-12323 | — | — | 0.9% | Nov 16, 2017 | Multiple vulnerabilities in the web interface of the Cisco Registered Envelope Service (a cloud-based service) could all... |
| CVE-2017-12322 | — | — | 0.9% | Nov 16, 2017 | Multiple vulnerabilities in the web interface of the Cisco Registered Envelope Service (a cloud-based service) could all... |
| CVE-2017-12321 | — | — | 0.9% | Nov 16, 2017 | Multiple vulnerabilities in the web interface of the Cisco Registered Envelope Service (a cloud-based service) could all... |
| CVE-2017-12320 | — | — | 0.9% | Nov 16, 2017 | Multiple vulnerabilities in the web interface of the Cisco Registered Envelope Service (a cloud-based service) could all... |
| CVE-2017-12318 | — | — | 1.6% | Nov 16, 2017 | A vulnerability in the TCP state machine of Cisco RF Gateway 1 devices could allow an unauthenticated, remote attacker t... |
| CVE-2017-12316 | — | — | 2.0% | Nov 16, 2017 | A vulnerability in the Guest Portal login page of Cisco Identity Services Engine (ISE) could allow an unauthenticated, r... |
| CVE-2017-12315 | — | — | 0.3% | Nov 16, 2017 | A vulnerability in system logging when replication is being configured with the Cisco HyperFlex System could allow an au... |
| CVE-2017-12314 | — | — | 0.4% | Nov 16, 2017 | A vulnerability in the Cisco FindIT Network Discovery Utility could allow an authenticated, local attacker to perform a ... |
| CVE-2017-12313 | — | — | 0.5% | Nov 16, 2017 | An untrusted search path (aka DLL Preload) vulnerability in the Cisco Network Academy Packet Tracer software could allow... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now