2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-15736 | — | — | 1.0% | Oct 22, 2017 | Cross-site scripting (XSS) vulnerability (stored) in SPIP before 3.1.7 allows remote attackers to inject arbitrary web s... |
| CVE-2017-15735 | — | — | 1.1% | Oct 22, 2017 | In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) for modifying a glossary. |
| CVE-2017-15734 | — | — | 1.1% | Oct 22, 2017 | In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.main.php. |
| CVE-2017-15733 | — | — | 0.6% | Oct 22, 2017 | In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/ajax.attachment.php and admin/att.main.php... |
| CVE-2017-15732 | — | — | 0.6% | Oct 22, 2017 | In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/news.php. |
| CVE-2017-15731 | — | — | 0.6% | Oct 22, 2017 | In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.adminlog.php. |
| CVE-2017-15730 | — | — | 2.5% | Oct 22, 2017 | In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.ratings.php. |
| CVE-2017-15729 | — | — | 0.6% | Oct 22, 2017 | In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) for adding a glossary. |
| CVE-2017-15728 | — | — | 0.6% | Oct 22, 2017 | In phpMyFAQ before 2.9.9, there is Stored Cross-site Scripting (XSS) via metaDescription or metaKeywords. |
| CVE-2017-15727 | — | — | 1.8% | Oct 22, 2017 | In phpMyFAQ before 2.9.9, there is Stored Cross-site Scripting (XSS) via an HTML attachment. |
| CVE-2017-12317 | — | — | 0.3% | Oct 22, 2017 | The Cisco AMP For Endpoints application allows an authenticated, local attacker to access a static key value stored in t... |
| CVE-2017-13127 | — | — | 1.1% | Oct 20, 2017 | The VIP.com application for IOS and Android allows remote attackers to obtain sensitive information and hijack the authe... |
| CVE-2017-15671 | — | — | 1.4% | Oct 20, 2017 | The glob function in glob.c in the GNU C Library (aka glibc or libc6) before 2.27, when invoked with GLOB_TILDE, could s... |
| CVE-2017-15670 | — | — | 3.0% | Oct 20, 2017 | The GNU C Library (aka glibc or libc6) before 2.27 contains an off-by-one error leading to a heap-based buffer overflow ... |
| CVE-2017-15291 | — | — | 1.7% | Oct 20, 2017 | Cross-site scripting (XSS) vulnerability in the Wireless MAC Filtering page in TP-LINK TL-MR3220 wireless routers allows... |
| CVE-2017-6165 | — | — | 1.9% | Oct 20, 2017 | In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM, and WebSafe 11.5.1 HF6 through 11.5.4 H... |
| CVE-2017-6145 | — | — | 1.1% | Oct 20, 2017 | iControl REST in F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM, and WebSafe 12.0.0 through 12.... |
| CVE-2017-6144 | — | — | 0.6% | Oct 20, 2017 | In F5 BIG-IP PEM 12.1.0 through 12.1.2 when downloading the Type Allocation Code (TAC) database file via HTTPS, the serv... |
| CVE-2017-6141 | — | — | 1.1% | Oct 20, 2017 | In F5 BIG-IP LTM, AAM, AFM, APM, ASM, Link Controller, PEM, and WebSafe 12.1.0 through 12.1.2, certain values in a TLS a... |
| CVE-2017-12628 | — | — | 0.8% | Oct 20, 2017 | The JMX server embedded in Apache James, also used by the command line client is exposed to a java de-serialization issu... |
| CVE-2017-14937 | — | — | 1.0% | Oct 20, 2017 | The airbag detonation algorithm allows injury to passenger-car occupants via predictable Security Access (SA) data to th... |
| CVE-2017-2133 | — | — | 1.2% | Oct 20, 2017 | SQL injection vulnerability in Panasonic KX-HJB1000 Home unit devices with firmware GHX1YG 14.50 or HJB1000_4.47 allows ... |
| CVE-2017-2132 | — | — | 1.2% | Oct 20, 2017 | Panasonic KX-HJB1000 Home unit devices with firmware GHX1YG 14.50 or HJB1000_4.47 allow an attacker to delete arbitrary ... |
| CVE-2017-2131 | — | — | 1.2% | Oct 20, 2017 | Panasonic KX-HJB1000 Home unit devices with firmware GHX1YG 14.50 or HJB1000_4.47 allow an attacker to bypass access res... |
| CVE-2017-15651 | — | — | 1.3% | Oct 20, 2017 | PRTG Network Monitor 17.3.33.2830 allows remote authenticated administrators to execute arbitrary code by uploading a .e... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now