2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-14723 | — | — | 10.4% | Sep 23, 2017 | Before version 4.8.2, WordPress mishandled % characters and additional placeholder values in $wpdb->prepare, and thus di... |
| CVE-2017-14722 | — | — | 7.8% | Sep 23, 2017 | Before version 4.8.2, WordPress allowed a Directory Traversal attack in the Customizer component via a crafted theme fil... |
| CVE-2017-14721 | — | — | 2.1% | Sep 23, 2017 | Before version 4.8.2, WordPress allowed Cross-Site scripting in the plugin editor via a crafted plugin name. |
| CVE-2017-14720 | — | — | 2.1% | Sep 23, 2017 | Before version 4.8.2, WordPress allowed a Cross-Site scripting attack in the template list view via a crafted template n... |
| CVE-2017-14719 | — | — | 13.4% | Sep 23, 2017 | Before version 4.8.2, WordPress was vulnerable to a directory traversal attack during unzip operations in the ZipArchive... |
| CVE-2017-14718 | — | — | 2.1% | Sep 23, 2017 | Before version 4.8.2, WordPress was susceptible to a Cross-Site Scripting attack in the link modal via a javascript: or ... |
| CVE-2017-14627 | — | — | 19.2% | Sep 23, 2017 | Stack-based buffer overflows in CyberLink LabelPrint 2.5 allow remote attackers to execute arbitrary code via the (1) au... |
| CVE-2017-14717 | — | — | 1.4% | Sep 22, 2017 | In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Description parameter. |
| CVE-2017-14716 | — | — | 0.6% | Sep 22, 2017 | In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Title parameter. |
| CVE-2017-14715 | — | — | 0.6% | Sep 22, 2017 | In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Alerts Title parameter. |
| CVE-2017-14714 | — | — | 0.6% | Sep 22, 2017 | In EPESI 1.8.2 rev20170830, there is Stored XSS in the Phonecalls Subject parameter. |
| CVE-2017-14713 | — | — | 0.6% | Sep 22, 2017 | In EPESI 1.8.2 rev20170830, there is Stored XSS in the Phonecalls Description parameter. |
| CVE-2017-14712 | — | — | 1.4% | Sep 22, 2017 | In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Phonecall Notes Title parameter. |
| CVE-2017-14694 | — | — | 7.1% | Sep 22, 2017 | Foxit Reader 8.3.2.25013 and earlier and Foxit PhantomPDF 8.3.2.25013 and earlier, when running in single instance mode,... |
| CVE-2017-14706 | — | — | 28.2% | Sep 22, 2017 | DenyAll WAF before 6.4.1 allows unauthenticated remote attackers to obtain authentication information by making a typeOf... |
| CVE-2017-14705 | — | — | 7.4% | Sep 22, 2017 | DenyAll WAF before 6.4.1 allows unauthenticated remote command execution via TCP port 3001 because shell metacharacters ... |
| CVE-2017-6277 | — | — | 0.4% | Sep 22, 2017 | NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEs... |
| CVE-2017-6272 | — | — | 0.4% | Sep 22, 2017 | NVIDIA GPU Display Driver contains a vulnerability in the kernel mode layer handler where a value passed from a user to ... |
| CVE-2017-6271 | — | — | 0.3% | Sep 22, 2017 | NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer handler for DxgkDdiCreateAllocation ... |
| CVE-2017-6270 | — | — | 0.3% | Sep 22, 2017 | NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer handler for DxgkDdiCreateAllocation ... |
| CVE-2017-6269 | — | — | 0.4% | Sep 22, 2017 | NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEs... |
| CVE-2017-6268 | — | — | 0.4% | Sep 22, 2017 | NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEs... |
| CVE-2017-6267 | — | — | 0.4% | Sep 22, 2017 | NVIDIA GPU Display Driver contains a vulnerability in the kernel mode layer handler where an incorrect initialization of... |
| CVE-2017-6266 | — | — | 0.4% | Sep 22, 2017 | NVIDIA GPU Display Driver contains a vulnerability in the kernel mode layer handler where improper access controls could... |
| CVE-2017-14081 | — | — | 16.6% | Sep 22, 2017 | Proxy command injection vulnerabilities in Trend Micro Mobile Security (Enterprise) versions before 9.7 Patch 3 allow re... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now