2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-14723Before version 4.8.2, WordPress mishandled % characters and additional placeholder values in $wpdb->prepare, and thus di...
CVE-2017-14722Before version 4.8.2, WordPress allowed a Directory Traversal attack in the Customizer component via a crafted theme fil...
CVE-2017-14721Before version 4.8.2, WordPress allowed Cross-Site scripting in the plugin editor via a crafted plugin name.
CVE-2017-14720Before version 4.8.2, WordPress allowed a Cross-Site scripting attack in the template list view via a crafted template n...
CVE-2017-14719Before version 4.8.2, WordPress was vulnerable to a directory traversal attack during unzip operations in the ZipArchive...
CVE-2017-14718Before version 4.8.2, WordPress was susceptible to a Cross-Site Scripting attack in the link modal via a javascript: or ...
CVE-2017-14627Stack-based buffer overflows in CyberLink LabelPrint 2.5 allow remote attackers to execute arbitrary code via the (1) au...
CVE-2017-14717In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Description parameter.
CVE-2017-14716In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Title parameter.
CVE-2017-14715In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Alerts Title parameter.
CVE-2017-14714In EPESI 1.8.2 rev20170830, there is Stored XSS in the Phonecalls Subject parameter.
CVE-2017-14713In EPESI 1.8.2 rev20170830, there is Stored XSS in the Phonecalls Description parameter.
CVE-2017-14712In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Phonecall Notes Title parameter.
CVE-2017-14694Foxit Reader 8.3.2.25013 and earlier and Foxit PhantomPDF 8.3.2.25013 and earlier, when running in single instance mode,...
CVE-2017-14706DenyAll WAF before 6.4.1 allows unauthenticated remote attackers to obtain authentication information by making a typeOf...
CVE-2017-14705DenyAll WAF before 6.4.1 allows unauthenticated remote command execution via TCP port 3001 because shell metacharacters ...
CVE-2017-6277NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEs...
CVE-2017-6272NVIDIA GPU Display Driver contains a vulnerability in the kernel mode layer handler where a value passed from a user to ...
CVE-2017-6271NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer handler for DxgkDdiCreateAllocation ...
CVE-2017-6270NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer handler for DxgkDdiCreateAllocation ...
CVE-2017-6269NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEs...
CVE-2017-6268NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEs...
CVE-2017-6267NVIDIA GPU Display Driver contains a vulnerability in the kernel mode layer handler where an incorrect initialization of...
CVE-2017-6266NVIDIA GPU Display Driver contains a vulnerability in the kernel mode layer handler where improper access controls could...
CVE-2017-14081Proxy command injection vulnerabilities in Trend Micro Mobile Security (Enterprise) versions before 9.7 Patch 3 allow re...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now