2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-12694 | — | — | 3.8% | Aug 25, 2017 | A Directory Traversal issue was discovered in SpiderControl SCADA Web Server. An attacker may be able to use a simple GE... |
| CVE-2017-13697 | — | — | 0.8% | Aug 25, 2017 | controllers/member/api.php in dayrui FineCms 5.0.11 has XSS related to the dirname variable. |
| CVE-2017-12709 | — | — | 0.3% | Aug 25, 2017 | A Use of Hard-Coded Credentials issue was discovered in MRD-305-DIN versions older than 1.7.5.0, and MRD-315, MRD-355, M... |
| CVE-2017-12703 | — | — | 0.6% | Aug 25, 2017 | A Cross-Site Request Forgery (CSRF) issue was discovered in Westermo MRD-305-DIN versions older than 1.7.5.0, and MRD-31... |
| CVE-2017-13695 | — | — | 0.4% | Aug 25, 2017 | The acpi_ns_evaluate() function in drivers/acpi/acpica/nseval.c in the Linux kernel through 4.12.9 does not flush the op... |
| CVE-2017-13694 | — | — | 0.4% | Aug 25, 2017 | The acpi_ps_complete_final_op() function in drivers/acpi/acpica/psobject.c in the Linux kernel through 4.12.9 does not f... |
| CVE-2017-13693 | — | — | 0.4% | Aug 25, 2017 | The acpi_ds_create_operands() function in drivers/acpi/acpica/dsutils.c in the Linux kernel through 4.12.9 does not flus... |
| CVE-2017-13692 | — | — | 1.1% | Aug 25, 2017 | In Tidy 5.5.31, the IsURLCodePoint function in attrs.c allows attackers to cause a denial of service (Segmentation Fault... |
| CVE-2017-13686 | — | — | 0.4% | Aug 24, 2017 | net/ipv4/route.c in the Linux kernel 4.13-rc1 through 4.13-rc6 is too late to check for a NULL fi field when RTM_F_FIB_M... |
| CVE-2017-9555 | — | — | 0.8% | Aug 24, 2017 | Cross-site scripting (XSS) vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.0-3414 allows re... |
| CVE-2017-13671 | — | — | 1.0% | Aug 24, 2017 | app/View/Helper/CommandHelper.php in MISP before 2.4.79 has persistent XSS via comments. It only impacts the users of th... |
| CVE-2017-12879 | — | — | 1.1% | Aug 24, 2017 | Cross-site scripting (XSS-STORED) vulnerability in the DEVICES OR SENSORS functionality in Paessler PRTG Network Monitor... |
| CVE-2017-9511 | HIGH | 7.5 | 3.2% | Aug 24, 2017 | The MultiPathResource class in Atlassian Fisheye and Crucible, before version 4.4.1 allows anonymous remote attackers to... |
| CVE-2017-12074 | — | — | 2.0% | Aug 24, 2017 | Directory traversal vulnerability in the SYNO.DNSServer.Zone.MasterZoneConf in Synology DNS Server before 2.2.1-3042 all... |
| CVE-2017-9512 | HIGH | 7.5 | 2.0% | Aug 24, 2017 | The mostActiveCommitters.do resource in Atlassian Fisheye and Crucible, before version 4.4.1 allows anonymous remote att... |
| CVE-2017-9510 | — | — | 0.8% | Aug 24, 2017 | The repository changelog resource in Atlassian Fisheye before version 4.4.1 allows remote attackers to inject arbitrary ... |
| CVE-2017-9509 | — | — | 0.8% | Aug 24, 2017 | The review file upload resource in Atlassian Crucible before version 4.4.1 allows remote attackers to inject arbitrary H... |
| CVE-2017-9508 | — | — | 0.8% | Aug 24, 2017 | Various resources in Atlassian Fisheye and Crucible before version 4.4.1 allow remote attackers to inject arbitrary HTML... |
| CVE-2017-9507 | — | — | 0.8% | Aug 24, 2017 | The review dashboard resource in Atlassian Crucible from version 4.1.0 before version 4.4.1 allows remote attackers to i... |
| CVE-2017-13669 | — | — | 1.5% | Aug 24, 2017 | SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the setanswered parameter to staffbox.php. |
| CVE-2017-12679 | — | — | 1.5% | Aug 24, 2017 | SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the delcheater parameter to cheaterbox.php. |
| CVE-2017-11424 | — | — | 1.8% | Aug 24, 2017 | In PyJWT 1.5.0 and below the `invalid_strings` check in `HMACAlgorithm.prepare_key` does not account for all PEM encoded... |
| CVE-2017-12836 | — | — | 6.0% | Aug 24, 2017 | CVS 1.12.x, when configured to use SSH for remote repositories, might allow remote attackers to execute arbitrary code v... |
| CVE-2017-12137 | — | — | 0.4% | Aug 24, 2017 | arch/x86/mm.c in Xen allows local PV guest OS users to gain host OS privileges via vectors related to map_grant_ref. |
| CVE-2017-12136 | — | — | 0.3% | Aug 24, 2017 | Race condition in the grant table code in Xen 4.6.x through 4.9.x allows local guest OS administrators to cause a denial... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now