2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-15235 | — | — | 5.5% | Oct 11, 2017 | The File Manager (gollem) module 3.0.11 in Horde Groupware 5.2.21 allows remote attackers to bypass Horde authentication... |
| CVE-2017-15232 | — | — | 2.4% | Oct 11, 2017 | libjpeg-turbo 1.5.2 has a NULL Pointer Dereference in jdpostct.c and jquant1.c via a crafted JPEG file. |
| CVE-2017-15215 | — | — | 1.5% | Oct 11, 2017 | Reflected XSS vulnerability in Shaarli v0.9.1 allows an unauthenticated attacker to inject JavaScript via the searchtags... |
| CVE-2017-15214 | — | — | 0.9% | Oct 11, 2017 | Stored XSS vulnerability in Flyspray 1.0-rc4 before 1.0-rc6 allows an authenticated user to inject JavaScript to gain ad... |
| CVE-2017-15213 | — | — | 0.8% | Oct 11, 2017 | Stored XSS vulnerability in Flyspray before 1.0-rc6 allows an authenticated user to inject JavaScript to gain administra... |
| CVE-2017-15212 | — | — | 1.2% | Oct 11, 2017 | In Kanboard before 1.0.47, by altering form data, an authenticated user can at least see the names of tags of a private ... |
| CVE-2017-15211 | — | — | 1.0% | Oct 11, 2017 | In Kanboard before 1.0.47, by altering form data, an authenticated user can add an external link to a private project of... |
| CVE-2017-15210 | — | — | 1.1% | Oct 11, 2017 | In Kanboard before 1.0.47, by altering form data, an authenticated user can see thumbnails of pictures from a private pr... |
| CVE-2017-15209 | — | — | 0.9% | Oct 11, 2017 | In Kanboard before 1.0.47, by altering form data, an authenticated user can remove attachments from a private project of... |
| CVE-2017-15208 | — | — | 1.0% | Oct 11, 2017 | In Kanboard before 1.0.47, by altering form data, an authenticated user can remove automatic actions from a private proj... |
| CVE-2017-15207 | — | — | 1.0% | Oct 11, 2017 | In Kanboard before 1.0.47, by altering form data, an authenticated user can edit tasks of a private project of another u... |
| CVE-2017-15206 | — | — | 1.0% | Oct 11, 2017 | In Kanboard before 1.0.47, by altering form data, an authenticated user can add an internal link to a private project of... |
| CVE-2017-15205 | — | — | 1.1% | Oct 11, 2017 | In Kanboard before 1.0.47, by altering form data, an authenticated user can download attachments from a private project ... |
| CVE-2017-15204 | — | — | 1.0% | Oct 11, 2017 | In Kanboard before 1.0.47, by altering form data, an authenticated user can add automatic actions to a private project o... |
| CVE-2017-15203 | — | — | 1.0% | Oct 11, 2017 | In Kanboard before 1.0.47, by altering form data, an authenticated user can remove categories from a private project of ... |
| CVE-2017-15202 | — | — | 1.0% | Oct 11, 2017 | In Kanboard before 1.0.47, by altering form data, an authenticated user can edit columns of a private project of another... |
| CVE-2017-15201 | — | — | 1.2% | Oct 11, 2017 | In Kanboard before 1.0.47, by altering form data, an authenticated user can edit tags of a private project of another us... |
| CVE-2017-15200 | — | — | 1.2% | Oct 11, 2017 | In Kanboard before 1.0.47, by altering form data, an authenticated user can add a new task to a private project of anoth... |
| CVE-2017-15199 | — | — | 1.2% | Oct 11, 2017 | In Kanboard before 1.0.47, by altering form data, an authenticated user can edit metadata of a private project of anothe... |
| CVE-2017-15198 | — | — | 1.4% | Oct 11, 2017 | In Kanboard before 1.0.47, by altering form data, an authenticated user can edit a category of a private project of anot... |
| CVE-2017-15197 | — | — | 1.2% | Oct 11, 2017 | In Kanboard before 1.0.47, by altering form data, an authenticated user can add a new category to a private project of a... |
| CVE-2017-15196 | — | — | 1.2% | Oct 11, 2017 | In Kanboard before 1.0.47, by altering form data, an authenticated user can remove columns from a private project of ano... |
| CVE-2017-15195 | — | — | 1.2% | Oct 11, 2017 | In Kanboard before 1.0.47, by altering form data, an authenticated user can edit swimlanes of a private project of anoth... |
| CVE-2017-15194 | — | — | 1.1% | Oct 11, 2017 | include/global_session.php in Cacti 1.1.25 has XSS related to (1) the URI or (2) the refresh page. |
| CVE-2017-15188 | — | — | 0.8% | Oct 11, 2017 | A persistent (stored) XSS vulnerability in the EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote authenticate... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now