2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-15885 | — | — | 0.6% | Oct 25, 2017 | Reflected XSS in the web administration portal on the Axis 2100 Network Camera 2.03 allows an attacker to execute arbitr... |
| CVE-2017-15881 | MEDIUM | 4.8 | 1.2% | Oct 24, 2017 | Cross-Site Scripting vulnerability in KeystoneJS before 4.0.0-beta.7 allows remote authenticated administrators to injec... |
| CVE-2017-15880 | — | — | 1.9% | Oct 24, 2017 | SQL injection vulnerability vulnerability in the EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote authentica... |
| CVE-2017-15879 | — | — | 7.2% | Oct 24, 2017 | CSV Injection (aka Excel Macro Injection or Formula Injection) exists in admin/server/api/download.js and lib/list/getCS... |
| CVE-2017-15878 | — | — | 3.4% | Oct 24, 2017 | A cross-site scripting (XSS) vulnerability exists in fields/types/markdown/MarkdownType.js in KeystoneJS before 4.0.0-be... |
| CVE-2017-1583 | — | — | 3.2% | Oct 24, 2017 | IBM WebSphere Application Server (IBM Liberty for Java for Bluemix 3.13)could allow a remote attacker to obtain sensitiv... |
| CVE-2017-1523 | — | — | 2.1% | Oct 24, 2017 | IBM InfoSphere Master Data Management - Collaborative Edition 11.5 could allow an unauthorized user to download reports ... |
| CVE-2017-1375 | — | — | 1.0% | Oct 24, 2017 | IBM System Storage Storwize V7000 Unified (V7000U) 1.5 and 1.6 uses weaker than expected cryptographic algorithms that c... |
| CVE-2017-1212 | — | — | 1.0% | Oct 24, 2017 | IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 and 5.0.2 is vulnerable to a denial of service when viewing o... |
| CVE-2017-1211 | — | — | 0.3% | Oct 24, 2017 | IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 and 5.0.2 could disclose sensitive information to a local use... |
| CVE-2017-1210 | — | — | 1.4% | Oct 24, 2017 | IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 and 5.0.2 could allow an unauthenticated attacker to inject d... |
| CVE-2017-1209 | — | — | 0.5% | Oct 24, 2017 | IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 and 5.0.2 is vulnerable to cross-site scripting. This vulnera... |
| CVE-2017-15874 | MEDIUM | 5 | 0.9% | Oct 24, 2017 | archival/libarchive/decompress_unlzma.c in BusyBox 1.27.2 has an Integer Underflow that leads to a read access violation... |
| CVE-2017-15873 | MEDIUM | 5.5 | 1.3% | Oct 24, 2017 | The get_next_block function in archival/libarchive/decompress_bunzip2.c in BusyBox 1.27.2 has an Integer Overflow that m... |
| CVE-2017-15872 | — | — | 0.5% | Oct 24, 2017 | phpwcms 1.8.9 has XSS in include/inc_tmpl/admin.edituser.tmpl.php and include/inc_tmpl/admin.newuser.tmpl.php via the us... |
| CVE-2017-15871 | HIGH | 7.5 | 1.1% | Oct 24, 2017 | The deserialize function in serialize-to-js through 1.1.1 allows attackers to cause a denial of service via vectors invo... |
| CVE-2017-15867 | — | — | 1.0% | Oct 24, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in the user-login-history plugin through 1.5.2 for WordPress allow r... |
| CVE-2017-15863 | — | — | 1.0% | Oct 24, 2017 | Cross Site Scripting (XSS) exists in the wp-noexternallinks plugin before 3.5.19 for WordPress via the date1 or date2 pa... |
| CVE-2017-15223 | — | — | 4.5% | Oct 24, 2017 | Denial-of-service vulnerability in ArGoSoft Mini Mail Server 1.0.0.2 and earlier allows remote attackers to waste CPU re... |
| CVE-2017-15222 | CRITICAL | 9.8 | 60.3% | Oct 24, 2017 | Buffer Overflow vulnerability in Ayukov NFTPD 2.0 and earlier allows remote attackers to execute arbitrary code. |
| CVE-2017-15186 | — | — | 1.7% | Oct 24, 2017 | Double free vulnerability in FFmpeg 3.3.4 and earlier allows remote attackers to cause a denial of service via a crafted... |
| CVE-2017-14696 | — | — | 2.7% | Oct 24, 2017 | SaltStack Salt before 2016.3.8, 2016.11.x before 2016.11.8, and 2017.7.x before 2017.7.2 allows remote attackers to caus... |
| CVE-2017-14695 | — | — | 2.6% | Oct 24, 2017 | Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.3.8, 2016.11.x before 2016.11.8,... |
| CVE-2017-15081 | — | — | 2.4% | Oct 24, 2017 | In PHPSUGAR PHP Melody CMS 2.6.1, SQL Injection exists via the playlist parameter to playlists.php. |
| CVE-2017-12618 | — | — | 0.6% | Oct 24, 2017 | Apache Portable Runtime Utility (APR-util) 1.6.0 and prior fail to validate the integrity of SDBM database files used by... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now