2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-15235The File Manager (gollem) module 3.0.11 in Horde Groupware 5.2.21 allows remote attackers to bypass Horde authentication...
CVE-2017-15232libjpeg-turbo 1.5.2 has a NULL Pointer Dereference in jdpostct.c and jquant1.c via a crafted JPEG file.
CVE-2017-15215Reflected XSS vulnerability in Shaarli v0.9.1 allows an unauthenticated attacker to inject JavaScript via the searchtags...
CVE-2017-15214Stored XSS vulnerability in Flyspray 1.0-rc4 before 1.0-rc6 allows an authenticated user to inject JavaScript to gain ad...
CVE-2017-15213Stored XSS vulnerability in Flyspray before 1.0-rc6 allows an authenticated user to inject JavaScript to gain administra...
CVE-2017-15212In Kanboard before 1.0.47, by altering form data, an authenticated user can at least see the names of tags of a private ...
CVE-2017-15211In Kanboard before 1.0.47, by altering form data, an authenticated user can add an external link to a private project of...
CVE-2017-15210In Kanboard before 1.0.47, by altering form data, an authenticated user can see thumbnails of pictures from a private pr...
CVE-2017-15209In Kanboard before 1.0.47, by altering form data, an authenticated user can remove attachments from a private project of...
CVE-2017-15208In Kanboard before 1.0.47, by altering form data, an authenticated user can remove automatic actions from a private proj...
CVE-2017-15207In Kanboard before 1.0.47, by altering form data, an authenticated user can edit tasks of a private project of another u...
CVE-2017-15206In Kanboard before 1.0.47, by altering form data, an authenticated user can add an internal link to a private project of...
CVE-2017-15205In Kanboard before 1.0.47, by altering form data, an authenticated user can download attachments from a private project ...
CVE-2017-15204In Kanboard before 1.0.47, by altering form data, an authenticated user can add automatic actions to a private project o...
CVE-2017-15203In Kanboard before 1.0.47, by altering form data, an authenticated user can remove categories from a private project of ...
CVE-2017-15202In Kanboard before 1.0.47, by altering form data, an authenticated user can edit columns of a private project of another...
CVE-2017-15201In Kanboard before 1.0.47, by altering form data, an authenticated user can edit tags of a private project of another us...
CVE-2017-15200In Kanboard before 1.0.47, by altering form data, an authenticated user can add a new task to a private project of anoth...
CVE-2017-15199In Kanboard before 1.0.47, by altering form data, an authenticated user can edit metadata of a private project of anothe...
CVE-2017-15198In Kanboard before 1.0.47, by altering form data, an authenticated user can edit a category of a private project of anot...
CVE-2017-15197In Kanboard before 1.0.47, by altering form data, an authenticated user can add a new category to a private project of a...
CVE-2017-15196In Kanboard before 1.0.47, by altering form data, an authenticated user can remove columns from a private project of ano...
CVE-2017-15195In Kanboard before 1.0.47, by altering form data, an authenticated user can edit swimlanes of a private project of anoth...
CVE-2017-15194include/global_session.php in Cacti 1.1.25 has XSS related to (1) the URI or (2) the refresh page.
CVE-2017-15188A persistent (stored) XSS vulnerability in the EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote authenticate...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now