2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-1000053HIGH8.1Elixir Plug before v1.0.4, v1.1.7, v1.2.3 and v1.3.2 is vulnerable to arbitrary code execution in the deserialization fu...
CVE-2017-1000052HIGH7.8Elixir Plug before v1.0.4, v1.1.7, v1.2.3 and v1.3.2 is vulnerable to null byte injection in the Plug.Static component, ...
CVE-2017-1000051Cross-site scripting (XSS) vulnerability in pad export in XWiki labs CryptPad before 1.1.1 allows remote attackers to in...
CVE-2017-1000050HIGH7.5JasPer 2.0.12 is vulnerable to a NULL pointer exception in the function jp2_encode which failed to check to see if the i...
CVE-2017-1000049Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-8864. Reason: This candidate is a reservation ...
CVE-2017-1000048the web framework using ljharb's qs module older than v6.3.2, v6.2.3, v6.1.2, and v6.0.4 is vulnerable to a DoS. A malic...
CVE-2017-1000047CRITICAL9.8rbenv (all current versions) is vulnerable to Directory Traversal in the specification of Ruby version resulting in arbi...
CVE-2017-1000046Mautic 2.6.1 and earlier fails to set flags on session cookies
CVE-2017-1000045Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA d...
CVE-2017-1000044gtk-vnc 0.4.2 and older doesn't check framebuffer boundaries correctly when updating framebuffer which may lead to memor...
CVE-2017-1000043MEDIUM6.1Mapbox.js versions 1.x prior to 1.6.6 and 2.x prior to 2.2.4 are vulnerable to a cross-site-scripting attack in certain ...
CVE-2017-1000042Mapbox.js versions 1.x prior to 1.6.5 and 2.x prior to 2.1.7 are vulnerable to a cross-site-scripting attack in certain ...
CVE-2017-1000039Framadate version 1.0 is vulnerable to Formula Injection in the CSV Export resulting possible Information Disclosure and...
CVE-2017-1000038WordPress plugin Relevanssi version 3.5.7.1 is vulnerable to stored XSS resulting in attacker being able to execute Java...
CVE-2017-1000037RVM automatically loads environment variables from files in $PWD resulting in command execution RVM vulnerable to comman...
CVE-2017-1000036Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA d...
CVE-2017-1000035Tiny Tiny RSS before 829d478f is vulnerable to XSS window.opener attack
CVE-2017-1000034Akka versions <=2.4.16 and 2.5-M1 are vulnerable to a java deserialization attack in its Remoting component resulting in...
CVE-2017-1000033Wordpress Plugin Vospari Forms version < 1.4 is vulnerable to a reflected cross site scripting in the form submission re...
CVE-2017-1000032Cross-Site scripting (XSS) vulnerabilities in Cacti 0.8.8b allow remote attackers to inject arbitrary web script or HTML...
CVE-2017-1000031SQL injection vulnerability in graph_templates_inputs.php in Cacti 0.8.8b allows remote attackers to execute arbitrary S...
CVE-2017-1000030Oracle, GlassFish Server Open Source Edition 3.0.1 (build 22) is vulnerable to Java Key Store Password Disclosure vulner...
CVE-2017-1000029Oracle, GlassFish Server Open Source Edition 3.0.1 (build 22) is vulnerable to Local File Inclusion vulnerability, that ...
CVE-2017-1000028Oracle, GlassFish Server Open Source Edition 4.1 is vulnerable to both authenticated and unauthenticated Directory Trave...
CVE-2017-1000027Koozali Foundation SME Server versions 8.x, 9.x, 10.x are vulnerable to an open URL redirect vulnerability in the user w...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now