2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-1425IBM Business Process Manager 8.0.1.1 and 8.5.7 is vulnerable to cross-site scripting. This vulnerability allows users to...
CVE-2017-14745The *_get_synthetic_symtab functions in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Bin...
CVE-2017-5200Salt-api in SaltStack Salt before 2015.8.13, 2016.3.x before 2016.3.5, and 2016.11.x before 2016.11.2 allows arbitrary c...
CVE-2017-5192When using the local_batch client from salt-api in SaltStack Salt before 2015.8.13, 2016.3.x before 2016.3.5, and 2016.1...
CVE-2017-14704Multiple unrestricted file upload vulnerabilities in the (1) imageSubmit and (2) proof_submit functions in Claydip Larav...
CVE-2017-14602A vulnerability has been identified in the management interface of Citrix NetScaler Application Delivery Controller (ADC...
CVE-2017-13129Cross-site request forgery (CSRF) vulnerability in ZKTeco ZKTime Web 2.0.1.12280 allows remote authenticated users to hi...
CVE-2017-14703SQL injection vulnerability in Cash Back Comparison Script 1.0 allows remote attackers to execute arbitrary SQL commands...
CVE-2017-14744UEditor 1.4.3.3 has XSS via the SRC attribute of an IFRAME element.
CVE-2017-14743Faleemi FSC-880 00.01.01.0048P2 devices allow unauthenticated SQL injection via the Username element in an XML document ...
CVE-2017-12154The prepare_vmcs02 function in arch/x86/kvm/vmx.c in the Linux kernel through 4.13.3 does not ensure that the "CR8-load ...
CVE-2017-1000252The KVM subsystem in the Linux kernel through 4.13.3 allows guest OS users to cause a denial of service (assertion failu...
CVE-2017-14741The ReadCAPTIONImage function in coders/caption.c in ImageMagick 7.0.7-3 allows remote attackers to cause a denial of se...
CVE-2017-14739The AcquireResampleFilterThreadSet function in magick/resample-private.h in ImageMagick 7.0.7-4 mishandles failed memory...
CVE-2017-14001An Improper Neutralization of Special Elements used in an OS Command issue was discovered in Digium Asterisk GUI 2.1.0 a...
CVE-2017-9962Schneider Electric's ClearSCADA versions released prior to August 2017 are susceptible to a memory allocation vulnerabil...
CVE-2017-9961A vulnerability exists in Schneider Electric's Pro-Face GP Pro EX version 4.07.000 that allows an attacker to execute ar...
CVE-2017-9960An information disclosure vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prio...
CVE-2017-9959A vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the system ac...
CVE-2017-9958An improper access control vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and pri...
CVE-2017-9957A vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the web servi...
CVE-2017-9956An authentication bypass vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior...
CVE-2017-7974A path traversal information disclosure vulnerability exists in Schneider Electric's U.motion Builder software versions ...
CVE-2017-7973A SQL injection vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which...
CVE-2017-7972A vulnerability exists in Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and Po...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now