2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-14048BlackCat CMS 1.2 allows remote authenticated users to inject arbitrary PHP code into info.php via a crafted new_modulena...
CVE-2017-13670In BlackCat CMS 1.2, remote authenticated users can upload any file via the media upload function in backend/media/ajax_...
CVE-2017-14042A memory allocation failure was discovered in the ReadPNMImage function in coders/pnm.c in GraphicsMagick 1.3.26. The vu...
CVE-2017-14041HIGH8.8A stack-based buffer overflow was discovered in the pgxtoimage function in bin/jp2/convert.c in OpenJPEG 2.2.0. The vuln...
CVE-2017-14040HIGH8.8An invalid write access was discovered in bin/jp2/convert.c in OpenJPEG 2.2.0, triggering a crash in the tgatoimage func...
CVE-2017-14039HIGH8.8A heap-based buffer overflow was discovered in the opj_t2_encode_packet function in lib/openjp2/t2.c in OpenJPEG 2.2.0. ...
CVE-2017-1446MEDIUM5.4IBM Emptoris Spend Analysis 9.5.0.0 through 10.1.1 is vulnerable to cross-site scripting. This vulnerability allows user...
CVE-2017-1445IBM Emptoris Spend Analysis 9.5.0.0 through 10.1.1 is vulnerable to cross-site scripting. This vulnerability allows user...
CVE-2017-1443IBM Emptoris Services Procurement 10.0.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to emb...
CVE-2017-1442IBM Emptoris Services Procurement 10.0.0.5 is vulnerable to cross-site request forgery which could allow an attacker to ...
CVE-2017-1441IBM Emptoris Services Procurement 10.0.0.5 could allow a local user to view sensitive information stored locally due to ...
CVE-2017-1440IBM Emptoris Services Procurement 10.0.0.5 could allow a remote attacker to include arbitrary files. A remote attacker c...
CVE-2017-14038CrushFTP before 7.8.0 and 8.x before 8.2.0 has a redirect vulnerability.
CVE-2017-14037CrushFTP before 7.8.0 and 8.x before 8.2.0 has an HTTP header vulnerability.
CVE-2017-14036CrushFTP before 7.8.0 and 8.x before 8.2.0 has XSS.
CVE-2017-14035CrushFTP 8.x before 8.2.0 has a serialization vulnerability.
CVE-2017-14032ARM mbed TLS before 1.3.21 and 2.x before 2.1.9, if optional authentication is configured, allows remote attackers to by...
CVE-2017-11157Multiple untrusted search path vulnerabilities in the installer in Synology Cloud Station Backup before 4.2.5-4396 on Wi...
CVE-2017-9945In the Siemens 7KM PAC Switched Ethernet PROFINET expansion module (All versions < V2.1.3), a Denial-of-Service conditio...
CVE-2017-12735HIGH7.4A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). An attacker who perform...
CVE-2017-12734HIGH7.5A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V1.81.2). An attacker with net...
CVE-2017-12069An XXE vulnerability has been identified in OPC Foundation UA .NET Sample Code before 2017-03-21 and Local Discovery Ser...
CVE-2017-12717An Uncontrolled Search Path Element issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. A malic...
CVE-2017-12713An Incorrect Permission Assignment for Critical Resource issue was discovered in Advantech WebAccess versions prior to V...
CVE-2017-12711An Incorrect Privilege Assignment issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. A built-i...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now