2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-12694A Directory Traversal issue was discovered in SpiderControl SCADA Web Server. An attacker may be able to use a simple GE...
CVE-2017-13697controllers/member/api.php in dayrui FineCms 5.0.11 has XSS related to the dirname variable.
CVE-2017-12709A Use of Hard-Coded Credentials issue was discovered in MRD-305-DIN versions older than 1.7.5.0, and MRD-315, MRD-355, M...
CVE-2017-12703A Cross-Site Request Forgery (CSRF) issue was discovered in Westermo MRD-305-DIN versions older than 1.7.5.0, and MRD-31...
CVE-2017-13695The acpi_ns_evaluate() function in drivers/acpi/acpica/nseval.c in the Linux kernel through 4.12.9 does not flush the op...
CVE-2017-13694The acpi_ps_complete_final_op() function in drivers/acpi/acpica/psobject.c in the Linux kernel through 4.12.9 does not f...
CVE-2017-13693The acpi_ds_create_operands() function in drivers/acpi/acpica/dsutils.c in the Linux kernel through 4.12.9 does not flus...
CVE-2017-13692In Tidy 5.5.31, the IsURLCodePoint function in attrs.c allows attackers to cause a denial of service (Segmentation Fault...
CVE-2017-13686net/ipv4/route.c in the Linux kernel 4.13-rc1 through 4.13-rc6 is too late to check for a NULL fi field when RTM_F_FIB_M...
CVE-2017-9555Cross-site scripting (XSS) vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.0-3414 allows re...
CVE-2017-13671app/View/Helper/CommandHelper.php in MISP before 2.4.79 has persistent XSS via comments. It only impacts the users of th...
CVE-2017-12879Cross-site scripting (XSS-STORED) vulnerability in the DEVICES OR SENSORS functionality in Paessler PRTG Network Monitor...
CVE-2017-9511HIGH7.5The MultiPathResource class in Atlassian Fisheye and Crucible, before version 4.4.1 allows anonymous remote attackers to...
CVE-2017-12074Directory traversal vulnerability in the SYNO.DNSServer.Zone.MasterZoneConf in Synology DNS Server before 2.2.1-3042 all...
CVE-2017-9512HIGH7.5The mostActiveCommitters.do resource in Atlassian Fisheye and Crucible, before version 4.4.1 allows anonymous remote att...
CVE-2017-9510The repository changelog resource in Atlassian Fisheye before version 4.4.1 allows remote attackers to inject arbitrary ...
CVE-2017-9509The review file upload resource in Atlassian Crucible before version 4.4.1 allows remote attackers to inject arbitrary H...
CVE-2017-9508Various resources in Atlassian Fisheye and Crucible before version 4.4.1 allow remote attackers to inject arbitrary HTML...
CVE-2017-9507The review dashboard resource in Atlassian Crucible from version 4.1.0 before version 4.4.1 allows remote attackers to i...
CVE-2017-13669SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the setanswered parameter to staffbox.php.
CVE-2017-12679SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the delcheater parameter to cheaterbox.php.
CVE-2017-11424In PyJWT 1.5.0 and below the `invalid_strings` check in `HMACAlgorithm.prepare_key` does not account for all PEM encoded...
CVE-2017-12836CVS 1.12.x, when configured to use SSH for remote repositories, might allow remote attackers to execute arbitrary code v...
CVE-2017-12137arch/x86/mm.c in Xen allows local PV guest OS users to gain host OS privileges via vectors related to map_grant_ref.
CVE-2017-12136Race condition in the grant table code in Xen 4.6.x through 4.9.x allows local guest OS administrators to cause a denial...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now