2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-14848 | HIGH | 8.8 | 3.0% | Oct 3, 2017 | WPHRM Human Resource Management System for WordPress 1.0 allows SQL Injection via the employee_id parameter. |
| CVE-2017-14773 | — | — | 0.4% | Oct 3, 2017 | Skybox Manager Client Application prior to 8.5.501 is prone to an elevation of privileges vulnerability during authentic... |
| CVE-2017-14772 | — | — | 0.3% | Oct 3, 2017 | Skybox Manager Client Application is prone to information disclosure via a username enumeration attack. A local unauthen... |
| CVE-2017-14771 | — | — | 0.3% | Oct 3, 2017 | Skybox Manager Client Application prior to 8.5.501 is prone to an arbitrary file upload vulnerability due to insufficien... |
| CVE-2017-14770 | — | — | 0.3% | Oct 3, 2017 | Skybox Manager Client Application prior to 8.5.501 is prone to an information disclosure vulnerability of user password ... |
| CVE-2017-14759 | — | — | 1.3% | Oct 3, 2017 | OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might b... |
| CVE-2017-14758 | — | — | 2.7% | Oct 3, 2017 | OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might b... |
| CVE-2017-14757 | — | — | 1.9% | Oct 3, 2017 | OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might b... |
| CVE-2017-14756 | — | — | 0.7% | Oct 3, 2017 | OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might b... |
| CVE-2017-14755 | — | — | 0.7% | Oct 3, 2017 | OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might b... |
| CVE-2017-14754 | — | — | 1.3% | Oct 3, 2017 | OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might b... |
| CVE-2017-14496 | — | — | 66.3% | Oct 3, 2017 | Integer underflow in the add_pseudoheader function in dnsmasq before 2.78 , when the --add-mac, --add-cpe-id or --add-su... |
| CVE-2017-14495 | — | — | 84.3% | Oct 3, 2017 | Memory leak in dnsmasq before 2.78, when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote ... |
| CVE-2017-14494 | — | — | 67.5% | Oct 3, 2017 | dnsmasq before 2.78, when configured as a relay, allows remote attackers to obtain sensitive memory information via vect... |
| CVE-2017-14493 | — | — | 83.6% | Oct 3, 2017 | Stack-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execu... |
| CVE-2017-14492 | — | — | 93.3% | Oct 3, 2017 | Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execut... |
| CVE-2017-1429 | — | — | 0.7% | Oct 3, 2017 | IBM RELM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Jav... |
| CVE-2017-13997 | — | — | 5.1% | Oct 3, 2017 | A Missing Authentication for Critical Function issue was discovered in Schneider Electric InduSoft Web Studio v8.0 SP2 o... |
| CVE-2017-13704 | — | — | 65.4% | Oct 3, 2017 | In dnsmasq before 2.78, if the DNS packet size does not match the expected size, the size parameter in a memset call get... |
| CVE-2017-1369 | — | — | 0.7% | Oct 3, 2017 | IBM RELM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Jav... |
| CVE-2017-1364 | — | — | 0.7% | Oct 3, 2017 | IBM RELM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Jav... |
| CVE-2017-1359 | — | — | 0.7% | Oct 3, 2017 | IBM RELM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Jav... |
| CVE-2017-1345 | — | — | 0.5% | Oct 3, 2017 | IBM Insights Foundation for Energy 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed a... |
| CVE-2017-1335 | — | — | 0.7% | Oct 3, 2017 | IBM RELM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Jav... |
| CVE-2017-1334 | — | — | 0.7% | Oct 3, 2017 | IBM RELM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Jav... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now