2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-10961 | — | — | 0.6% | Jul 18, 2017 | REDCap before 7.5.1 has CSRF in the deletion feature of the File Repository and File Upload components. |
| CVE-2017-1318 | — | — | 3.1% | Jul 18, 2017 | IBM MQ Appliance 8.0 and 9.0 could allow an authenticated messaging administrator to execute arbitrary commands on the s... |
| CVE-2017-11420 | — | — | 5.6% | Jul 18, 2017 | Stack-based buffer overflow in ASUS_Discovery.c in networkmap in Asuswrt-Merlin firmware for ASUS devices and ASUS firmw... |
| CVE-2017-11419 | — | — | 1.0% | Jul 18, 2017 | Fiyo CMS 2.0.7 has SQL injection in /apps/app_article/controller/editor.php via $_POST['id'] and $_POST['art_title']. |
| CVE-2017-11418 | — | — | 1.0% | Jul 18, 2017 | Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_article/controller/article_list.php via $_GET['cat'], $_GET['user'], ... |
| CVE-2017-11417 | — | — | 1.0% | Jul 18, 2017 | Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_article/controller/article_status.php via $_GET['id']. |
| CVE-2017-11416 | — | — | 1.0% | Jul 18, 2017 | Fiyo CMS 2.0.7 has SQL injection in /apps/app_comment/controller/insert.php via the name parameter. |
| CVE-2017-11415 | — | — | 1.0% | Jul 18, 2017 | Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_article/sys_article.php via $_POST['parent_id'], $_POST['desc'], $_PO... |
| CVE-2017-11414 | — | — | 1.0% | Jul 18, 2017 | Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_comment/sys_comment.php via $_POST['comment'], $_POST['name'], $_POST... |
| CVE-2017-11413 | — | — | 1.0% | Jul 18, 2017 | Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_article/controller/comment_status.php via $_GET['id']. |
| CVE-2017-11412 | — | — | 1.0% | Jul 18, 2017 | Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_comment/controller/comment_status.php via $_GET['id']. |
| CVE-2017-11405 | — | — | 0.8% | Jul 18, 2017 | In CMS Made Simple (CMSMS) 2.2.2, remote authenticated administrators can upload a .php file via a CMSContentManager act... |
| CVE-2017-11404 | — | — | 0.8% | Jul 18, 2017 | In CMS Made Simple (CMSMS) 2.2.2, remote authenticated administrators can upload a .php file via a FileManager action to... |
| CVE-2017-11403 | — | — | 28.3% | Jul 18, 2017 | The ReadMNGImage function in coders/png.c in GraphicsMagick 1.3.26 has an out-of-order CloseBlob call, resulting in a us... |
| CVE-2017-9934 | — | — | 2.2% | Jul 17, 2017 | Missing CSRF token checks and improper input validation in Joomla! CMS 1.7.3 through 3.7.2 lead to an XSS vulnerability. |
| CVE-2017-9933 | — | — | 2.3% | Jul 17, 2017 | Improper cache invalidation in Joomla! CMS 1.7.3 through 3.7.2 leads to disclosure of form contents. |
| CVE-2017-9813 | — | — | 2.6% | Jul 17, 2017 | In Kaspersky Anti-Virus for Linux File Server before Maintenance Pack 2 Critical Fix 4 (version 8.0.4.312), the scriptNa... |
| CVE-2017-9812 | — | — | 11.3% | Jul 17, 2017 | The reportId parameter of the getReportStatus action method can be abused in the web interface in Kaspersky Anti-Virus f... |
| CVE-2017-9811 | — | — | 10.5% | Jul 17, 2017 | The kluser is able to interact with the kav4fs-control binary in Kaspersky Anti-Virus for Linux File Server before Maint... |
| CVE-2017-9810 | — | — | 1.9% | Jul 17, 2017 | There are no Anti-CSRF tokens in any forms on the web interface in Kaspersky Anti-Virus for Linux File Server before Mai... |
| CVE-2017-9671 | — | — | 3.2% | Jul 17, 2017 | A heap overflow in apk (Alpine Linux's package manager) allows a remote attacker to cause a denial of service, or achiev... |
| CVE-2017-9669 | — | — | 3.2% | Jul 17, 2017 | A heap overflow in apk (Alpine Linux's package manager) allows a remote attacker to cause a denial of service, or achiev... |
| CVE-2017-9609 | — | — | 1.5% | Jul 17, 2017 | Cross-site scripting (XSS) vulnerability in Blackcat CMS 1.2 allows remote authenticated users to inject arbitrary web s... |
| CVE-2017-9340 | MEDIUM | 6.5 | 1.0% | Jul 17, 2017 | An attacker is logged in as a normal user and can somehow make admin to delete shared folders in ownCloud Server before ... |
| CVE-2017-9339 | MEDIUM | 5.3 | 1.0% | Jul 17, 2017 | A logical error in ownCloud Server before 10.0.2 caused disclosure of valid share tokens for public calendars. Thus gran... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now