2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-1000080 | HIGH | 7.5 | 1.0% | Jul 17, 2017 | Linux foundation ONOS 1.9.0 allows unauthenticated use of websockets. |
| CVE-2017-1000079 | HIGH | 7.5 | 1.3% | Jul 17, 2017 | Linux foundation ONOS 1.9.0 is vulnerable to a DoS. |
| CVE-2017-1000078 | MEDIUM | 6.1 | 0.7% | Jul 17, 2017 | Linux foundation ONOS 1.9 is vulnerable to XSS in the device. registration |
| CVE-2017-1000075 | — | — | 2.0% | Jul 17, 2017 | Creolabs Gravity version 1.0 is vulnerable to a stack overflow in the memcmp function |
| CVE-2017-1000074 | — | — | 2.0% | Jul 17, 2017 | Creolabs Gravity version 1.0 is vulnerable to a stack overflow in the string_repeat() function. |
| CVE-2017-1000073 | — | — | 2.9% | Jul 17, 2017 | Creolabs Gravity version 1.0 is vulnerable to a heap overflow in an undisclosed component that can result in arbitrary c... |
| CVE-2017-1000072 | — | — | 2.1% | Jul 17, 2017 | Creolabs Gravity version 1.0 is vulnerable to a Double Free in gravity_value resulting potentially leading to modificati... |
| CVE-2017-1000071 | — | — | 3.5% | Jul 17, 2017 | Jasig phpCAS version 1.3.4 is vulnerable to an authentication bypass in the validateCAS20 function when configured to au... |
| CVE-2017-1000070 | — | — | 1.0% | Jul 17, 2017 | The Bitly oauth2_proxy in version 2.1 and earlier was affected by an open redirect vulnerability during the start and te... |
| CVE-2017-1000069 | — | — | 0.7% | Jul 17, 2017 | CSRF in Bitly oauth2_proxy 2.1 during authentication flow |
| CVE-2017-1000068 | HIGH | 7.5 | 1.8% | Jul 17, 2017 | TestTrack Server versions 1.0 and earlier are vulnerable to an authentication flaw in the split disablement feature resu... |
| CVE-2017-1000067 | — | — | 1.1% | Jul 17, 2017 | MODX Revolution version 2.x - 2.5.6 is vulnerable to blind SQL injection caused by improper sanitization by the escape m... |
| CVE-2017-1000066 | — | — | 1.4% | Jul 17, 2017 | The entry details view function in KeePass version 1.32 inadvertently decrypts certain database entries into memory, whi... |
| CVE-2017-1000065 | — | — | 0.7% | Jul 17, 2017 | Multiple Cross-site scripting (XSS) vulnerabilities in rpc.php in OpenMediaVault release 2.1 in Access Rights Management... |
| CVE-2017-1000064 | — | — | 1.3% | Jul 17, 2017 | kittoframework kitto version 0.5.1 is vulnerable to memory exhaustion in the router resulting in DoS |
| CVE-2017-1000063 | — | — | 0.8% | Jul 17, 2017 | kittoframework kitto version 0.5.1 is vulnerable to an XSS in the 404 page resulting in information disclosure |
| CVE-2017-1000062 | — | — | 3.9% | Jul 17, 2017 | kittoframework kitto 0.5.1 is vulnerable to directory traversal in the router resulting in remote code execution |
| CVE-2017-1000061 | — | — | 1.3% | Jul 17, 2017 | xmlsec 1.2.23 and before is vulnerable to XML External Entity Expansion when parsing crafted input documents, resulting ... |
| CVE-2017-1000060 | CRITICAL | 9.8 | 3.5% | Jul 17, 2017 | EyesOfNetwork (EON) 5.1 Unauthenticated SQL Injection in eonweb leading to remote root |
| CVE-2017-1000059 | — | — | 1.1% | Jul 17, 2017 | Live Helper Chat version 2.06v and older is vulnerable to Cross-Site Scripting in the HTTP Header handling resulting in ... |
| CVE-2017-1000058 | — | — | 0.7% | Jul 17, 2017 | Stored XSS vulnerabilities in chevereto CMS before version 3.8.11, one in the user profile and one in the Exif data pars... |
| CVE-2017-1000057 | — | — | — | Jul 17, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA d... |
| CVE-2017-1000056 | — | — | 2.4% | Jul 17, 2017 | Kubernetes version 1.5.0-1.5.4 is vulnerable to a privilege escalation in the PodSecurityPolicy admission plugin resulti... |
| CVE-2017-1000055 | — | — | — | Jul 17, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2017-1000054 | — | — | 0.7% | Jul 17, 2017 | Rocket.Chat version 0.8.0 and newer is vulnerable to XSS in the markdown link parsing code for messages. |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now