2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-2679Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca...
CVE-2017-2678Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca...
CVE-2017-2677Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca...
CVE-2017-2676Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca...
CVE-2017-18636HIGH7.5CDG through 2017-01-01 allows downloadDocument.jsp?command=download&pathAndName= directory traversal.
CVE-2017-18635MEDIUM6.1An XSS vulnerability was discovered in noVNC before 0.6.2 in which the remote VNC server could inject arbitrary HTML int...
CVE-2017-18634CRITICAL9.8The newspaper theme before 6.7.2 for WordPress has script injection via td_ads[header] to admin-ajax.php.
CVE-2017-18615MEDIUM6.1The kama-clic-counter plugin before 3.5.0 for WordPress has XSS.
CVE-2017-18614HIGH8.1The kama-clic-counter plugin 3.4.9 for WordPress has SQL injection via the admin.php order parameter.
CVE-2017-18613MEDIUM6.1The trust-form plugin 2.0 for WordPress has XSS via the wp-admin/admin.php?page=trust-form-edit page parameter.
CVE-2017-18612MEDIUM6.1The wp-whois-domain plugin 1.0.0 for WordPress has XSS via the pages/func-whois.php domain parameter.
CVE-2017-18611MEDIUM6.1The magic-fields plugin before 1.7.2 for WordPress has XSS via the RCCWP_CreateCustomFieldPage.php custom-field-css para...
CVE-2017-18610MEDIUM6.1The magic-fields plugin before 1.7.2 for WordPress has XSS via the RCCWP_CreateCustomFieldPage.php custom-group-id param...
CVE-2017-18609MEDIUM6.1The magic-fields plugin before 1.7.2 for WordPress has XSS via the custom-write-panel-id parameter.
CVE-2017-18608MEDIUM6.1The spotim-comments plugin before 4.0.4 for WordPress has multiple XSS issues.
CVE-2017-18607HIGH8.8The avada theme before 5.1.5 for WordPress has CSRF.
CVE-2017-18606MEDIUM6.1The avada theme before 5.1.5 for WordPress has stored XSS.
CVE-2017-18605CRITICAL9.8The gravitate-qa-tracker plugin through 1.2.1 for WordPress has PHP Object Injection.
CVE-2017-18604HIGH7.5The sitebuilder-dynamic-components plugin through 1.0 for WordPress has PHP object injection via an AJAX request.
CVE-2017-18603MEDIUM6.1The postman-smtp plugin through 2017-10-04 for WordPress has XSS via the wp-admin/tools.php?page=postman_email_log page ...
CVE-2017-18602HIGH8.8The examapp plugin 1.0 for WordPress has SQL injection via the wp-admin/admin.php?page=examapp_UserResult id parameter.
CVE-2017-18601MEDIUM5.4The examapp plugin 1.0 for WordPress has XSS via exam input text fields.
CVE-2017-18600MEDIUM5.4The formcraft3 plugin before 3.4 for WordPress has stored XSS via the "New Form > Heading > Heading Text" field.
CVE-2017-18599MEDIUM6.1The Pinfinity theme before 2.0 for WordPress has XSS via the s parameter.
CVE-2017-18598MEDIUM6.1The Qards plugin through 2017-10-11 for WordPress has XSS via a remote document specified in the url parameter to html2c...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now