2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-1425 | — | — | 0.7% | Sep 26, 2017 | IBM Business Process Manager 8.0.1.1 and 8.5.7 is vulnerable to cross-site scripting. This vulnerability allows users to... |
| CVE-2017-14745 | — | — | 1.2% | Sep 26, 2017 | The *_get_synthetic_symtab functions in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Bin... |
| CVE-2017-5200 | — | — | 3.2% | Sep 26, 2017 | Salt-api in SaltStack Salt before 2015.8.13, 2016.3.x before 2016.3.5, and 2016.11.x before 2016.11.2 allows arbitrary c... |
| CVE-2017-5192 | — | — | 1.7% | Sep 26, 2017 | When using the local_batch client from salt-api in SaltStack Salt before 2015.8.13, 2016.3.x before 2016.3.5, and 2016.1... |
| CVE-2017-14704 | — | — | 8.5% | Sep 26, 2017 | Multiple unrestricted file upload vulnerabilities in the (1) imageSubmit and (2) proof_submit functions in Claydip Larav... |
| CVE-2017-14602 | — | — | 2.4% | Sep 26, 2017 | A vulnerability has been identified in the management interface of Citrix NetScaler Application Delivery Controller (ADC... |
| CVE-2017-13129 | — | — | 1.1% | Sep 26, 2017 | Cross-site request forgery (CSRF) vulnerability in ZKTeco ZKTime Web 2.0.1.12280 allows remote authenticated users to hi... |
| CVE-2017-14703 | — | — | 2.1% | Sep 26, 2017 | SQL injection vulnerability in Cash Back Comparison Script 1.0 allows remote attackers to execute arbitrary SQL commands... |
| CVE-2017-14744 | — | — | 0.6% | Sep 26, 2017 | UEditor 1.4.3.3 has XSS via the SRC attribute of an IFRAME element. |
| CVE-2017-14743 | — | — | 1.2% | Sep 26, 2017 | Faleemi FSC-880 00.01.01.0048P2 devices allow unauthenticated SQL injection via the Username element in an XML document ... |
| CVE-2017-12154 | — | — | 0.5% | Sep 26, 2017 | The prepare_vmcs02 function in arch/x86/kvm/vmx.c in the Linux kernel through 4.13.3 does not ensure that the "CR8-load ... |
| CVE-2017-1000252 | — | — | 0.5% | Sep 26, 2017 | The KVM subsystem in the Linux kernel through 4.13.3 allows guest OS users to cause a denial of service (assertion failu... |
| CVE-2017-14741 | — | — | 1.4% | Sep 26, 2017 | The ReadCAPTIONImage function in coders/caption.c in ImageMagick 7.0.7-3 allows remote attackers to cause a denial of se... |
| CVE-2017-14739 | — | — | 3.0% | Sep 26, 2017 | The AcquireResampleFilterThreadSet function in magick/resample-private.h in ImageMagick 7.0.7-4 mishandles failed memory... |
| CVE-2017-14001 | — | — | 6.4% | Sep 26, 2017 | An Improper Neutralization of Special Elements used in an OS Command issue was discovered in Digium Asterisk GUI 2.1.0 a... |
| CVE-2017-9962 | — | — | 1.0% | Sep 26, 2017 | Schneider Electric's ClearSCADA versions released prior to August 2017 are susceptible to a memory allocation vulnerabil... |
| CVE-2017-9961 | — | — | 0.4% | Sep 26, 2017 | A vulnerability exists in Schneider Electric's Pro-Face GP Pro EX version 4.07.000 that allows an attacker to execute ar... |
| CVE-2017-9960 | — | — | 1.1% | Sep 26, 2017 | An information disclosure vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prio... |
| CVE-2017-9959 | — | — | 0.3% | Sep 26, 2017 | A vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the system ac... |
| CVE-2017-9958 | — | — | 0.3% | Sep 26, 2017 | An improper access control vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and pri... |
| CVE-2017-9957 | — | — | 1.6% | Sep 26, 2017 | A vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the web servi... |
| CVE-2017-9956 | — | — | 1.1% | Sep 26, 2017 | An authentication bypass vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior... |
| CVE-2017-7974 | — | — | 4.6% | Sep 26, 2017 | A path traversal information disclosure vulnerability exists in Schneider Electric's U.motion Builder software versions ... |
| CVE-2017-7973 | — | — | 1.5% | Sep 26, 2017 | A SQL injection vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which... |
| CVE-2017-7972 | — | — | 0.5% | Sep 26, 2017 | A vulnerability exists in Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and Po... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now