2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-18519The customer-area plugin before 7.4.3 for WordPress has XSS via admin pages.
CVE-2017-18518The bws-smtp plugin before 1.1.0 for WordPress has multiple XSS issues.
CVE-2017-18569The my-wp-translate plugin before 1.0.4 for WordPress has CSRF.
CVE-2017-18568The my-wp-translate plugin before 1.0.4 for WordPress has XSS.
CVE-2017-18567The wp-all-import plugin before 3.4.6 for WordPress has XSS.
CVE-2017-18520The democracy-poll plugin before 5.4 for WordPress has XSS via update_l10n in admin/class.DemAdminInit.php.
CVE-2017-18517The bws-pinterest plugin before 1.0.5 for WordPress has multiple XSS issues.
CVE-2017-18552An issue was discovered in net/rds/af_rds.c in the Linux kernel before 4.11. There is an out of bounds write and read in...
CVE-2017-18551MEDIUM6.7An issue was discovered in drivers/i2c/i2c-core-smbus.c in the Linux kernel before 4.14.15. There is an out of bounds wr...
CVE-2017-18550An issue was discovered in drivers/scsi/aacraid/commctrl.c in the Linux kernel before 4.13. There is potential exposure ...
CVE-2017-18549An issue was discovered in drivers/scsi/aacraid/commctrl.c in the Linux kernel before 4.13. There is potential exposure ...
CVE-2017-18547The nelio-ab-testing plugin before 4.6.4 for WordPress has CSRF in experiment forms.
CVE-2017-18546The jayj-quicktag plugin before 1.3.2 for WordPress has CSRF.
CVE-2017-18545The invite-anyone plugin before 1.3.16 for WordPress has incorrect escaping of untrusted Dashboard and front-end input.
CVE-2017-18544The invite-anyone plugin before 1.3.16 for WordPress has admin-panel CSRF.
CVE-2017-18543The invite-anyone plugin before 1.3.16 for WordPress has incorrect access control for email-based invitations.
CVE-2017-18542The zendesk-help-center plugin before 1.0.5 for WordPress has multiple XSS issues.
CVE-2017-18541The xo-security plugin before 1.5.3 for WordPress has XSS.
CVE-2017-18548The note-press plugin before 0.1.2 for WordPress has SQL injection.
CVE-2017-14232The read_chunk function in flif-dec.cpp in Free Lossless Image Format (FLIF) 0.3 allows remote attackers to cause a deni...
CVE-2017-18513The responsive-menu plugin before 3.1.4 for WordPress has no CSRF protection mechanism for the admin interface.
CVE-2017-18512The newsletter-by-supsystic plugin before 1.1.8 for WordPress has CSRF.
CVE-2017-18511The custom-sidebars plugin before 3.0.8.1 for WordPress has CSRF.
CVE-2017-18510The custom-sidebars plugin before 3.1.0 for WordPress has CSRF related to set location, import actions, and export actio...
CVE-2017-18514CRITICAL9.8The simple-login-log plugin before 1.1.2 for WordPress has SQL injection.

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now