2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-14524 | — | — | 2.9% | Sep 28, 2017 | Multiple open redirect vulnerabilities in OpenText Documentum Administrator 7.2.0180.0055 allow remote attackers to redi... |
| CVE-2017-1407 | HIGH | 8.8 | 3.4% | Sep 28, 2017 | IBM Security Identity Manager Virtual Appliance 6.0 and 7.0 could allow a remote authenticated attacker to execute arbit... |
| CVE-2017-13676 | — | — | 0.4% | Sep 28, 2017 | Norton Remove & Reinstall can be susceptible to a DLL preloading vulnerability. These types of issues occur when an appl... |
| CVE-2017-12814 | — | — | 7.0% | Sep 28, 2017 | Stack-based buffer overflow in the CPerlHost::Add method in win32/perlhost.h in Perl before 5.24.3-RC1 and 5.26.x before... |
| CVE-2017-12621 | CRITICAL | 9.8 | 8.5% | Sep 28, 2017 | During Jelly (xml) file parsing with Apache Xerces, if a custom doctype entity is declared with a "SYSTEM" entity with a... |
| CVE-2017-11191 | — | — | 1.7% | Sep 28, 2017 | FreeIPA 4.x with API version 2.213 allows a remote authenticated users to bypass intended account-locking restrictions v... |
| CVE-2017-11121 | — | — | 2.8% | Sep 28, 2017 | On Broadcom BCM4355C0 Wi-Fi chips 9.44.78.27.0.1.56 and other chips, properly crafted malicious over-the-air Fast Transi... |
| CVE-2017-11120 | — | — | 9.1% | Sep 28, 2017 | On Broadcom BCM4355C0 Wi-Fi chips 9.44.78.27.0.1.56 and other chips, an attacker can craft a malformed RRM neighbor repo... |
| CVE-2017-10932 | CRITICAL | 9.8 | 4.1% | Sep 28, 2017 | All versions prior to V12.17.20 of the ZTE Microwave NR8000 series products - NR8120, NR8120A, NR8120, NR8150, NR8250, N... |
| CVE-2017-14767 | — | — | 2.7% | Sep 27, 2017 | The sdp_parse_fmtp_config_h264 function in libavformat/rtpdec_h264.c in FFmpeg before 3.3.4 mishandles empty sprop-param... |
| CVE-2017-14766 | — | — | 1.8% | Sep 27, 2017 | The Simple Student Result plugin before 1.6.4 for WordPress has an Authentication Bypass vulnerability because the fn_ss... |
| CVE-2017-14765 | — | — | 0.7% | Sep 27, 2017 | In GeniXCMS 1.1.4, gxadmin/index.php has XSS via the Menu ID field in a page=menus request. |
| CVE-2017-14764 | — | — | 1.5% | Sep 27, 2017 | In the Upload Modules page in GeniXCMS 1.1.4, remote authenticated users can execute arbitrary PHP code via a .php file ... |
| CVE-2017-14763 | — | — | 1.4% | Sep 27, 2017 | In the Install Themes page in GeniXCMS 1.1.4, remote authenticated users can execute arbitrary PHP code via a .php file ... |
| CVE-2017-14762 | — | — | 0.7% | Sep 27, 2017 | In GeniXCMS 1.1.4, /inc/lib/Control/Backend/menus.control.php has XSS via the id parameter. |
| CVE-2017-14761 | — | — | 0.7% | Sep 27, 2017 | In GeniXCMS 1.1.4, /inc/lib/backend/menus.control.php has XSS via the id parameter. |
| CVE-2017-14760 | — | — | 1.5% | Sep 27, 2017 | SQL Injection exists in /includes/event-management/index.php in the event-espresso-free (aka Event Espresso Lite) plugin... |
| CVE-2017-14753 | — | — | 0.9% | Sep 27, 2017 | Cross-site scripting (XSS) vulnerability in the EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote authenticat... |
| CVE-2017-14751 | — | — | 1.3% | Sep 26, 2017 | The Intense WP "WP Jobs" plugin 1.5 for WordPress has XSS, related to the Job Qualification field. |
| CVE-2017-14749 | — | — | 2.0% | Sep 26, 2017 | JerryScript 1.0 allows remote attackers to cause a denial of service (jmem_heap_alloc_block_internal heap memory corrupt... |
| CVE-2017-1539 | — | — | 1.5% | Sep 26, 2017 | IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to privilege escalation by not properly distinguishing inte... |
| CVE-2017-1531 | — | — | 0.7% | Sep 26, 2017 | IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to cross-site scripting. This vulnerability allows users to... |
| CVE-2017-1530 | — | — | 0.7% | Sep 26, 2017 | IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to cross-site scripting. This vulnerability allows users to... |
| CVE-2017-1527 | — | — | 2.0% | Sep 26, 2017 | IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to a XML External Entity Injection (XXE) attack when proces... |
| CVE-2017-14748 | — | — | 1.1% | Sep 26, 2017 | Race condition in Blizzard Overwatch 1.15.0.2 allows remote authenticated users to cause a denial of service (season ban... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now