2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-3934 | — | — | 1.0% | Oct 31, 2017 | Missing HTTP Strict Transport Security state information vulnerability in the server in McAfee Network Data Loss Prevent... |
| CVE-2017-3933 | — | — | 0.6% | Oct 31, 2017 | Embedding Script (XSS) in HTTP Headers vulnerability in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote a... |
| CVE-2017-15950 | — | — | 5.5% | Oct 31, 2017 | Flexense SyncBreeze Enterprise version 10.1.16 is vulnerable to a buffer overflow that can be exploited for arbitrary co... |
| CVE-2017-15993 | — | — | 2.7% | Oct 31, 2017 | Zomato Clone Script allows SQL Injection via the restaurant-menu.php resid parameter. |
| CVE-2017-15992 | — | — | 2.7% | Oct 31, 2017 | Website Broker Script allows SQL Injection via the 'status_id' Parameter to status_list.php. |
| CVE-2017-15991 | — | — | 2.7% | Oct 31, 2017 | Vastal I-Tech Agent Zone (aka The Real Estate Script) allows SQL Injection in searchCommercial.php via the property_type... |
| CVE-2017-15990 | CRITICAL | 9.8 | 7.7% | Oct 31, 2017 | Php Inventory & Invoice Management System allows Arbitrary File Upload via dashboard/edit_myaccountdetail/. |
| CVE-2017-15989 | — | — | 2.7% | Oct 31, 2017 | Online Exam Test Application allows SQL Injection via the resources.php sort parameter in a category action. |
| CVE-2017-15988 | — | — | 2.7% | Oct 31, 2017 | Nice PHP FAQ Script allows SQL Injection via the index.php nice_theme parameter, a different vulnerability than CVE-2008... |
| CVE-2017-15987 | — | — | 2.0% | Oct 31, 2017 | Fake Magazine Cover Script allows SQL Injection via the rate.php value parameter or the content.php id parameter. |
| CVE-2017-15986 | — | — | 2.7% | Oct 31, 2017 | CPA Lead Reward Script allows SQL Injection via the username parameter. |
| CVE-2017-15985 | — | — | 2.7% | Oct 31, 2017 | Basic B2B Script allows SQL Injection via the product_view1.php pid or id parameter. |
| CVE-2017-15984 | — | — | 2.7% | Oct 31, 2017 | Creative Management System (CMS) Lite 1.4 allows SQL Injection via the S parameter to index.php. |
| CVE-2017-15983 | — | — | 2.7% | Oct 31, 2017 | MyMagazine Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing... |
| CVE-2017-15982 | CRITICAL | 9.8 | 2.6% | Oct 31, 2017 | Dynamic News Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editi... |
| CVE-2017-15981 | CRITICAL | 9.8 | 2.6% | Oct 31, 2017 | Responsive Newspaper Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for fo... |
| CVE-2017-15980 | — | — | 2.7% | Oct 31, 2017 | US Zip Codes Database Script 1.0 allows SQL Injection via the state parameter. |
| CVE-2017-15979 | — | — | 2.7% | Oct 31, 2017 | Shareet - Photo Sharing Social Network 1.0 allows SQL Injection via the photo parameter. |
| CVE-2017-15978 | — | — | 2.7% | Oct 31, 2017 | AROX School ERP PHP Script 1.0 allows SQL Injection via the office_admin/ id parameter. |
| CVE-2017-15977 | — | — | 2.7% | Oct 31, 2017 | Protected Links - Expiring Download Links 1.0 allows SQL Injection via the username parameter. |
| CVE-2017-14373 | — | — | 1.2% | Oct 31, 2017 | EMC RSA Authentication Manager 8.2 SP1 P4 and earlier contains a reflected cross-site scripting vulnerability that could... |
| CVE-2017-10151 | — | — | 3.9% | Oct 30, 2017 | Vulnerability in the Oracle Identity Manager component of Oracle Fusion Middleware (subcomponent: Default Account). Supp... |
| CVE-2017-1000255 | — | — | 0.4% | Oct 30, 2017 | On Linux running on PowerPC hardware (Power8 or later) a user process can craft a signal frame and then do a sigreturn s... |
| CVE-2017-16230 | — | — | 0.5% | Oct 30, 2017 | In admin/write-post.php in Typecho through 1.1, one can log in to the background page, write a new article, and add payl... |
| CVE-2017-14919 | HIGH | 7.5 | 8.1% | Oct 30, 2017 | Node.js before 4.8.5, 6.x before 6.11.5, and 8.x before 8.8.0 allows remote attackers to cause a denial of service (unca... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now