2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-11132 | HIGH | 7.5 | 0.5% | Aug 1, 2017 | An issue was discovered in heinekingmedia StashCat before 1.5.18 for Android. No certificate pinning is implemented; the... |
| CVE-2017-11131 | — | — | 0.5% | Aug 1, 2017 | An issue was discovered in heinekingmedia StashCat through 1.7.5 for Android, through 0.0.80w for Web, and through 0.0.8... |
| CVE-2017-11130 | — | — | 0.4% | Aug 1, 2017 | An issue was discovered in heinekingmedia StashCat through 1.7.5 for Android, through 0.0.80w for Web, and through 0.0.8... |
| CVE-2017-11129 | — | — | 1.1% | Aug 1, 2017 | An issue was discovered in heinekingmedia StashCat through 1.7.5 for Android. The keystore is locked with a hard-coded p... |
| CVE-2017-11552 | — | — | 6.6% | Aug 1, 2017 | mpg321.c in mpg321 0.3.2-1 does not properly manage memory for use with libmad 0.15.1b, which allows remote attackers to... |
| CVE-2017-12131 | — | — | 0.8% | Aug 1, 2017 | The Easy Testimonials plugin 3.0.4 for WordPress has XSS in include/settings/display.options.php, as demonstrated by the... |
| CVE-2017-12068 | — | — | 0.8% | Aug 1, 2017 | The Event List plugin 0.7.9 for WordPress has XSS in the slug array parameter to wp-admin/admin.php in an el_admin_categ... |
| CVE-2017-12067 | — | — | 1.1% | Aug 1, 2017 | Potrace 1.14 has a heap-based buffer over-read in the interpolate_cubic function in mkbitmap.c. |
| CVE-2017-12066 | — | — | 1.4% | Aug 1, 2017 | Cross-site scripting (XSS) vulnerability in aggregate_graphs.php in Cacti before 1.1.16 allows remote authenticated user... |
| CVE-2017-12065 | — | — | 2.9% | Aug 1, 2017 | spikekill.php in Cacti before 1.1.16 might allow remote attackers to execute arbitrary code via the avgnan, outlier-star... |
| CVE-2017-12064 | — | — | 1.2% | Aug 1, 2017 | The csv_log_html function in library/edihistory/edih_csv_inc.php in OpenEMR 5.0.0 and prior allows attackers to bypass i... |
| CVE-2017-11727 | — | — | 1.1% | Jul 31, 2017 | services/system_io/actionprocessor/Contact.rails in ConnectWise Manage 2017.5 allows arbitrary client-side JavaScript co... |
| CVE-2017-11726 | — | — | 0.5% | Jul 31, 2017 | services/system_io/actionprocessor/System.rails in ConnectWise Manage 2017.5 is vulnerable to Cross-Site Request Forgery... |
| CVE-2017-11648 | — | — | 0.4% | Jul 31, 2017 | Techroutes TR 1803-3G Wireless Cellular Router/Modem 2.4.25 devices do not possess any protection against a CSRF vulnera... |
| CVE-2017-1496 | — | — | 0.5% | Jul 31, 2017 | IBM Sterling B2B Integrator Standard Edition 5.2.x is vulnerable to cross-site scripting. This vulnerability allows user... |
| CVE-2017-1460 | — | — | 1.4% | Jul 31, 2017 | IBM i OSPF 6.1, 7.1, 7.2, and 7.3 is vulnerable when a rogue router spoofs its origin. Routing tables are affected by a ... |
| CVE-2017-1386 | — | — | 1.2% | Jul 31, 2017 | IBM API Connect 5.0.0.0 could allow a user to bypass policy restrictions and create non-compliant passwords which could ... |
| CVE-2017-1370 | — | — | 1.2% | Jul 31, 2017 | IBM Jazz Reporting Service (JRS) 5.0 and 6.0 could disclose sensitive information, including user credentials, through a... |
| CVE-2017-1332 | — | — | 1.0% | Jul 31, 2017 | IBM iNotes 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScr... |
| CVE-2017-1303 | MEDIUM | 6.1 | 1.3% | Jul 31, 2017 | IBM WebSphere Portal and Web Content Manager 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerab... |
| CVE-2017-1227 | — | — | 1.4% | Jul 31, 2017 | IBM Tivoli Endpoint Manager could allow a unauthorized user to consume all resources and crash the system. IBM X-Force I... |
| CVE-2017-11760 | — | — | 1.3% | Jul 31, 2017 | uploadImage.php in ProjeQtOr before 6.3.2 allows remote authenticated users to execute arbitrary PHP code by uploading a... |
| CVE-2017-11670 | — | — | 1.3% | Jul 31, 2017 | A length validation (leading to out-of-bounds read and write) flaw was found in the way eapmd5pass 1.4 handled network t... |
| CVE-2017-11669 | — | — | 1.3% | Jul 31, 2017 | An out-of-bounds read flaw related to the assess_packet function in eapmd5pass.c:211 was found in the way eapmd5pass 1.4... |
| CVE-2017-11668 | — | — | 1.3% | Jul 31, 2017 | An out-of-bounds read flaw related to the assess_packet function in eapmd5pass.c:134 was found in the way eapmd5pass 1.4... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now