2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-7971 | — | — | 0.8% | Sep 26, 2017 | A vulnerability exists in Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and Po... |
| CVE-2017-7970 | — | — | 0.6% | Sep 26, 2017 | A vulnerability exists in Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and Po... |
| CVE-2017-7969 | — | — | 0.6% | Sep 26, 2017 | A cross-site request forgery vulnerability exists on the Secure Gateway component of Schneider Electric's PowerSCADA Any... |
| CVE-2017-14737 | MEDIUM | 5.5 | 0.3% | Sep 26, 2017 | A cryptographic cache-based side channel in the RSA implementation in Botan before 1.10.17, and 1.11.x and 2.x before 2.... |
| CVE-2017-14735 | — | — | 1.7% | Sep 25, 2017 | OWASP AntiSamy before 1.5.7 allows XSS via HTML5 entities, as demonstrated by use of : to construct a javascript: ... |
| CVE-2017-14734 | — | — | 1.6% | Sep 25, 2017 | The build_msps function in libbpg.c in libbpg 0.9.7 allows remote attackers to cause a denial of service (heap-based buf... |
| CVE-2017-14733 | — | — | 2.1% | Sep 25, 2017 | ReadRLEImage in coders/rle.c in GraphicsMagick 1.3.26 mishandles RLE headers that specify too few colors, which allows r... |
| CVE-2017-14731 | — | — | 1.3% | Sep 25, 2017 | ofx_proc_file in ofx_preproc.cpp in LibOFX 0.9.12 allows remote attackers to cause a denial of service (heap-based buffe... |
| CVE-2017-14730 | — | — | 0.3% | Sep 25, 2017 | The init script in the Gentoo app-admin/logstash-bin package before 5.5.3 and 5.6.x before 5.6.1 has "chown -R" calls fo... |
| CVE-2017-14125 | — | — | 3.2% | Sep 25, 2017 | SQL injection vulnerability in the Responsive Image Gallery plugin before 1.2.1 for WordPress allows remote attackers to... |
| CVE-2017-12905 | CRITICAL | 10 | 2.6% | Sep 25, 2017 | Server Side Request Forgery vulnerability in Vebto Pixie Image Editor 1.4 and 1.7 allows remote attackers to disclose in... |
| CVE-2017-9551 | — | — | 0.6% | Sep 25, 2017 | Mahara 15.04 before 15.04.14 and 16.04 before 16.04.8 and 16.10 before 16.10.5 and 17.04 before 17.04.3 are vulnerable t... |
| CVE-2017-1555 | — | — | 0.9% | Sep 25, 2017 | IBM API Connect 5.0.0.0 through 5.0.7.2 could allow an authenticated user to generate an API token when not subscribed t... |
| CVE-2017-1551 | — | — | 0.9% | Sep 25, 2017 | IBM API Connect 5.0.0.0 through 5.0.7.2 could allow a remote attacker to hijack the clicking action of the victim. By pe... |
| CVE-2017-14729 | — | — | 2.3% | Sep 25, 2017 | The *_get_synthetic_symtab functions in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Bin... |
| CVE-2017-1424 | — | — | 0.7% | Sep 25, 2017 | IBM Business Process Manager 8.5.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbit... |
| CVE-2017-1362 | — | — | 0.3% | Sep 25, 2017 | IBM Security Identity Manager Adapters 6.0 and 7.0 stores user credentials in plain in clear text which can be read by a... |
| CVE-2017-1346 | — | — | 0.2% | Sep 25, 2017 | IBM Business Process Manager 7.5, 8.0, and 8.5 temporarily stores files in a temporary folder during offline installs wh... |
| CVE-2017-1235 | — | — | 2.3% | Sep 25, 2017 | IBM WebSphere MQ 8.0 could allow an authenticated user to cause a premature termination of a client application thread w... |
| CVE-2017-14683 | HIGH | 8.8 | 0.5% | Sep 25, 2017 | geminabox (aka Gem in a Box) before 0.13.7 has CSRF, as demonstrated by an unintended gem upload. |
| CVE-2017-14506 | MEDIUM | 5.4 | 0.7% | Sep 25, 2017 | geminabox (aka Gem in a Box) before 0.13.6 has XSS, as demonstrated by uploading a gem file that has a crafted gem.homep... |
| CVE-2017-14727 | — | — | 2.8% | Sep 23, 2017 | logger.c in the logger plugin in WeeChat before 1.9.1 allows a crash via strftime date/time specifiers, because a buffer... |
| CVE-2017-14726 | — | — | 2.7% | Sep 23, 2017 | Before version 4.8.2, WordPress was vulnerable to a cross-site scripting attack via shortcodes in the TinyMCE visual edi... |
| CVE-2017-14725 | — | — | 2.1% | Sep 23, 2017 | Before version 4.8.2, WordPress was susceptible to an open redirect attack in wp-admin/edit-tag-form.php and wp-admin/us... |
| CVE-2017-14724 | — | — | 2.9% | Sep 23, 2017 | Before version 4.8.2, WordPress was vulnerable to cross-site scripting in oEmbed discovery. |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now