2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-12613 | HIGH | 7.1 | 1.7% | Oct 24, 2017 | When apr_time_exp*() or apr_os_exp_time*() functions are invoked with an invalid month field value in Apache Portable Ru... |
| CVE-2017-13683 | — | — | 0.3% | Oct 23, 2017 | In Symantec Endpoint Encryption before SEE 11.1.3HF3, a kernel memory leak is a type of resource leak that can occur whe... |
| CVE-2017-13682 | — | — | 0.3% | Oct 23, 2017 | In Symantec Encryption Desktop before SED 10.4.1 MP2HF1, a kernel memory leak is a type of resource leak that can occur ... |
| CVE-2017-13772 | — | — | 52.6% | Oct 23, 2017 | Multiple stack-based buffer overflows in TP-Link WR940N WiFi routers with hardware version 4 allow remote authenticated ... |
| CVE-2017-15812 | — | — | 0.7% | Oct 23, 2017 | The Easy Appointments plugin before 1.12.0 for WordPress has XSS via a Settings values in the admin panel. |
| CVE-2017-15811 | — | — | 1.0% | Oct 23, 2017 | The Pootle Button plugin before 1.2.0 for WordPress has XSS via the assets_url parameter in assets/dialog.php, exploitab... |
| CVE-2017-15810 | — | — | 1.4% | Oct 23, 2017 | The PopCash.Net Code Integration Tool plugin before 1.1 for WordPress has XSS via the tab parameter to wp-admin/admin.ph... |
| CVE-2017-15809 | — | — | 0.6% | Oct 23, 2017 | In phpMyFaq before 2.9.9, there is XSS in admin/tags.main.php via a crafted tag. |
| CVE-2017-15808 | — | — | 1.2% | Oct 23, 2017 | In phpMyFaq before 2.9.9, there is CSRF in admin/ajax.config.php. |
| CVE-2017-9947 | MEDIUM | 5.3 | 7.3% | Oct 23, 2017 | A vulnerability has been identified in Siemens APOGEE PXC and TALON TC BACnet Automation Controllers in all versions <V3... |
| CVE-2017-9946 | HIGH | 7.5 | 24.8% | Oct 23, 2017 | A vulnerability has been identified in Siemens APOGEE PXC and TALON TC BACnet Automation Controllers in all versions <V3... |
| CVE-2017-15805 | — | — | 2.2% | Oct 23, 2017 | Cisco Small Business SA520 and SA540 devices with firmware 2.1.71 and 2.2.0.7 allow ../ directory traversal in scgi-bin/... |
| CVE-2017-15687 | — | — | 1.5% | Oct 23, 2017 | DOM Based Cross Site Scripting (XSS) exists in Logitech Media Server 7.7.1, 7.7.2, 7.7.3, 7.7.5, 7.7.6, 7.9.0, and 7.9.1... |
| CVE-2017-15580 | — | — | 16.0% | Oct 23, 2017 | osTicket 1.10.1 provides a functionality to upload 'html' files with associated formats. However, it does not properly v... |
| CVE-2017-15567 | — | — | 0.3% | Oct 23, 2017 | The certificate import component in IDEMIA (formerly Morpho) MorphoSmart 1300 Series (aka MSO 1300 Series) devices allow... |
| CVE-2017-15381 | — | — | 1.5% | Oct 23, 2017 | SQL Injection exists in E-Sic 1.0 via the f parameter to esiclivre/restrito/inc/buscacep.php (aka the zip code search sc... |
| CVE-2017-15380 | — | — | 0.8% | Oct 23, 2017 | XSS exists in the E-Sic 1.0 /cadastro/index.php URI (aka the requester's registration area) via the nome parameter. |
| CVE-2017-15379 | — | — | 2.7% | Oct 23, 2017 | An authentication bypass exists in the E-Sic 1.0 /index (aka login) URI via '=''or' values for the username and password... |
| CVE-2017-15378 | — | — | 1.4% | Oct 23, 2017 | SQL Injection exists in the E-Sic 1.0 password reset parameter (aka the cpfcnpj parameter to the /reset URI). |
| CVE-2017-15377 | — | — | 2.0% | Oct 23, 2017 | In Suricata before 4.x, it was possible to trigger lots of redundant checks on the content of crafted network traffic wi... |
| CVE-2017-14332 | — | — | 1.0% | Oct 23, 2017 | Extreme EXOS 15.7, 16.x, 21.x, and 22.x allows remote attackers to hijack sessions by determining SessionID values. |
| CVE-2017-14331 | — | — | 0.4% | Oct 23, 2017 | Extreme EXOS 16.x, 21.x, and 22.x allows administrators to bypass the "exsh restricted shell" protection mechanism and o... |
| CVE-2017-14330 | — | — | 0.3% | Oct 23, 2017 | Extreme EXOS 16.x, 21.x, and 22.x allows administrators to obtain a root shell via vectors involving a privileged proces... |
| CVE-2017-14329 | — | — | 0.3% | Oct 23, 2017 | Extreme EXOS 16.x, 21.x, and 22.x allows administrators to obtain a root shell via vectors involving an exsh debug shell... |
| CVE-2017-14328 | HIGH | 7.5 | 1.3% | Oct 23, 2017 | Extreme EXOS 15.7, 16.x, 21.x, and 22.x allows remote attackers to trigger a buffer overflow leading to a reboot. |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now