2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-1000080HIGH7.5Linux foundation ONOS 1.9.0 allows unauthenticated use of websockets.
CVE-2017-1000079HIGH7.5Linux foundation ONOS 1.9.0 is vulnerable to a DoS.
CVE-2017-1000078MEDIUM6.1Linux foundation ONOS 1.9 is vulnerable to XSS in the device. registration
CVE-2017-1000075Creolabs Gravity version 1.0 is vulnerable to a stack overflow in the memcmp function
CVE-2017-1000074Creolabs Gravity version 1.0 is vulnerable to a stack overflow in the string_repeat() function.
CVE-2017-1000073Creolabs Gravity version 1.0 is vulnerable to a heap overflow in an undisclosed component that can result in arbitrary c...
CVE-2017-1000072Creolabs Gravity version 1.0 is vulnerable to a Double Free in gravity_value resulting potentially leading to modificati...
CVE-2017-1000071Jasig phpCAS version 1.3.4 is vulnerable to an authentication bypass in the validateCAS20 function when configured to au...
CVE-2017-1000070The Bitly oauth2_proxy in version 2.1 and earlier was affected by an open redirect vulnerability during the start and te...
CVE-2017-1000069CSRF in Bitly oauth2_proxy 2.1 during authentication flow
CVE-2017-1000068HIGH7.5TestTrack Server versions 1.0 and earlier are vulnerable to an authentication flaw in the split disablement feature resu...
CVE-2017-1000067MODX Revolution version 2.x - 2.5.6 is vulnerable to blind SQL injection caused by improper sanitization by the escape m...
CVE-2017-1000066The entry details view function in KeePass version 1.32 inadvertently decrypts certain database entries into memory, whi...
CVE-2017-1000065Multiple Cross-site scripting (XSS) vulnerabilities in rpc.php in OpenMediaVault release 2.1 in Access Rights Management...
CVE-2017-1000064kittoframework kitto version 0.5.1 is vulnerable to memory exhaustion in the router resulting in DoS
CVE-2017-1000063kittoframework kitto version 0.5.1 is vulnerable to an XSS in the 404 page resulting in information disclosure
CVE-2017-1000062kittoframework kitto 0.5.1 is vulnerable to directory traversal in the router resulting in remote code execution
CVE-2017-1000061xmlsec 1.2.23 and before is vulnerable to XML External Entity Expansion when parsing crafted input documents, resulting ...
CVE-2017-1000060CRITICAL9.8EyesOfNetwork (EON) 5.1 Unauthenticated SQL Injection in eonweb leading to remote root
CVE-2017-1000059Live Helper Chat version 2.06v and older is vulnerable to Cross-Site Scripting in the HTTP Header handling resulting in ...
CVE-2017-1000058Stored XSS vulnerabilities in chevereto CMS before version 3.8.11, one in the user profile and one in the Exif data pars...
CVE-2017-1000057Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA d...
CVE-2017-1000056Kubernetes version 1.5.0-1.5.4 is vulnerable to a privilege escalation in the PodSecurityPolicy admission plugin resulti...
CVE-2017-1000055Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ...
CVE-2017-1000054Rocket.Chat version 0.8.0 and newer is vulnerable to XSS in the markdown link parsing code for messages.

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now