2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-16855Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-8638. Reason: This candidate is a reservation ...
CVE-2017-16853The DynamicMetadataProvider class in saml/saml2/metadata/impl/DynamicMetadataProvider.cpp in OpenSAML-C in OpenSAML befo...
CVE-2017-16852shibsp/metadata/DynamicMetadataProvider.cpp in the Dynamic MetadataProvider plugin in Shibboleth Service Provider before...
CVE-2017-16851Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /MyPage.do widgetid parameter.
CVE-2017-16850Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /showresource.do resourceid pa...
CVE-2017-16849Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /MyPage.do?method=viewDashBoar...
CVE-2017-16848Zoho ManageEngine Applications Manager 13 allows SQL injection via the /manageConfMons.do groupname parameter.
CVE-2017-16847Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /showresource.do resourceid pa...
CVE-2017-16846Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /manageApplications.do?method=...
CVE-2017-16844Heap-based buffer overflow in the loadbuf function in formisc.c in formail in procmail 3.22 allows remote attackers to c...
CVE-2017-16777If HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 5.0.3 is installed but VMware Fusion is not, a loc...
CVE-2017-16560SanDisk Secure Access 3.01 vault decrypts and copies encrypted files to a temporary folder, where they can remain indefi...
CVE-2017-15864In the Agent Frontend in Open Ticket Request System (OTRS) 3.3.x through 3.3.18, with a crafted URL it is possible to ga...
CVE-2017-5738Escalation of privilege vulnerability in admin portal for Intel Unite App versions 3.1.32.12, 3.1.41.18 and 3.1.45.26 al...
CVE-2017-12350A vulnerability in Cisco Umbrella Insights Virtual Appliances 2.1.0 and earlier could allow an authenticated, local atta...
CVE-2017-12337A vulnerability in the upgrade mechanism of Cisco collaboration products based on the Cisco Voice Operating System softw...
CVE-2017-12323Multiple vulnerabilities in the web interface of the Cisco Registered Envelope Service (a cloud-based service) could all...
CVE-2017-12322Multiple vulnerabilities in the web interface of the Cisco Registered Envelope Service (a cloud-based service) could all...
CVE-2017-12321Multiple vulnerabilities in the web interface of the Cisco Registered Envelope Service (a cloud-based service) could all...
CVE-2017-12320Multiple vulnerabilities in the web interface of the Cisco Registered Envelope Service (a cloud-based service) could all...
CVE-2017-12318A vulnerability in the TCP state machine of Cisco RF Gateway 1 devices could allow an unauthenticated, remote attacker t...
CVE-2017-12316A vulnerability in the Guest Portal login page of Cisco Identity Services Engine (ISE) could allow an unauthenticated, r...
CVE-2017-12315A vulnerability in system logging when replication is being configured with the Cisco HyperFlex System could allow an au...
CVE-2017-12314A vulnerability in the Cisco FindIT Network Discovery Utility could allow an authenticated, local attacker to perform a ...
CVE-2017-12313An untrusted search path (aka DLL Preload) vulnerability in the Cisco Network Academy Packet Tracer software could allow...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now