2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-1000026HIGH7.5Chef Software's mixlib-archive versions 0.3.0 and older are vulnerable to a directory traversal attack allowing attacker...
CVE-2017-1000025GNOME Web (Epiphany) 3.23 before 3.23.5, 3.22 before 3.22.6, 3.20 before 3.20.7, 3.18 before 3.18.11, and prior versions...
CVE-2017-1000024Shotwell version 0.24.4 or earlier and 0.25.3 or earlier is vulnerable to an information disclosure in the web publishin...
CVE-2017-1000023LogicalDoc Community Edition 7.5.3 and prior is vulnerable to an XSS when using preview on HTML document.
CVE-2017-1000022LogicalDoc Community Edition 7.5.3 and prior contain an Incorrect access control which could leave to privilege escalati...
CVE-2017-1000021LogicalDoc Community Edition 7.5.3 and prior is vulnerable to XXE when indexing XML documents.
CVE-2017-1000020SYN Flood or FIN Flood attack in ECos 1 and other versions embedded devices results in web Authentication Bypass. "eCos ...
CVE-2017-1000018phpMyAdmin 4.0, 4.4., and 4.6 are vulnerable to a DOS attack in the replication status by using a specially crafted tabl...
CVE-2017-1000017phpMyAdmin 4.0, 4.4 and 4.6 are vulnerable to a weakness where a user with appropriate permissions is able to connect to...
CVE-2017-1000016A weakness was discovered where an attacker can inject arbitrary values in to the browser cookies. This is a re-issue of...
CVE-2017-1000015phpMyAdmin 4.0, 4.4, and 4.6 are vulnerable to a CSS injection attack through crafted cookie parameters
CVE-2017-1000014phpMyAdmin 4.0, 4.4, and 4.6 are vulnerable to a DOS weakness in the table editing functionality
CVE-2017-1000013phpMyAdmin 4.0, 4.4, and 4.6 are vulnerable to an open redirect weakness
CVE-2017-1000012MySQL Dumper version 1.24 is vulnerable to stored XSS when displaying the data in the database to the user
CVE-2017-1000011MyWebSQL version 3.6 is vulnerable to stored XSS in the database manager component resulting in account takeover or stea...
CVE-2017-1000010HIGH7.8Audacity 2.1.2 through 2.3.2 is vulnerable to Dll HIjacking in the avformat-55.dll resulting arbitrary code execution.
CVE-2017-1000009CRITICAL9.8Akeneo PIM CE and EE <1.6.6, <1.5.15, <1.4.28 are vulnerable to shell injection in the mass edition, resulting in remote...
CVE-2017-1000008Chyrp Lite version 2016.04 is vulnerable to a CSRF in the user settings function allowing attackers to hijack the authen...
CVE-2017-1000007txAWS (all current versions) fail to perform complete certificate verification resulting in vulnerability to MitM attack...
CVE-2017-1000006Plotly, Inc. plotly.js versions prior to 1.16.0 are vulnerable to an XSS issue.
CVE-2017-1000005PHPMiniAdmin version 1.9.160630 is vulnerable to stored XSS in the name of databases, tables and columns resulting in po...
CVE-2017-1000004ATutor version 2.2.1 and earlier are vulnerable to a SQL injection in the Assignment Dropbox, BasicLTI, Blog Post, Blog,...
CVE-2017-1000003ATutor versions 2.2.1 and earlier are vulnerable to an incorrect access control check vulnerability in the Social Applic...
CVE-2017-1000002ATutor versions 2.2.1 and earlier are vulnerable to a directory traversal and file extension check bypass in the Course ...
CVE-2017-1000001FedMsg 0.18.1 and older is vulnerable to a message validation flaw resulting in message validation not being enabled if ...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now