2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-9296 | — | — | 0.9% | May 29, 2017 | Open Redirect vulnerability in Hitachi Device Manager before 8.5.2-01 and Hitachi Tuning Manager before 8.5.2-00 allows ... |
| CVE-2017-9295 | — | — | 1.1% | May 29, 2017 | XXE vulnerability in Hitachi Device Manager before 8.5.2-01 and Hitachi Replication Manager before 8.5.2-00 allows authe... |
| CVE-2017-9294 | — | — | 2.4% | May 29, 2017 | RMI vulnerability in Hitachi Device Manager before 8.5.2-01 allows remote attackers to execute internal commands without... |
| CVE-2017-9292 | — | — | 0.8% | May 29, 2017 | Lansweeper before 6.0.0.65 has XSS in an image retrieval URI, aka Bug 542782. |
| CVE-2017-9289 | — | — | 0.7% | May 29, 2017 | Bram Korsten Note through 1.2.0 is vulnerable to a reflected XSS in note-source\ui\editor.php (edit parameter). |
| CVE-2017-9148 | — | — | 3.9% | May 29, 2017 | The TLS session cache in FreeRADIUS 2.1.1 through 2.1.7, 3.0.x before 3.0.14, 3.1.x before 2017-02-04, and 4.0.x before ... |
| CVE-2017-9288 | — | — | 4.0% | May 29, 2017 | The Raygun4WP plugin 1.8.0 for WordPress is vulnerable to a reflected XSS in sendtesterror.php (backurl parameter). |
| CVE-2017-9287 | MEDIUM | 6.5 | 7.1% | May 29, 2017 | servers/slapd/back-mdb/search.c in OpenLDAP through 2.4.44 is prone to a double free vulnerability. A user with access t... |
| CVE-2017-7917 | — | — | 0.5% | May 29, 2017 | A Cross-Site Request Forgery issue was discovered in Moxa OnCell G3110-HSPA Version 1.3 build 15082117 and previous vers... |
| CVE-2017-7915 | — | — | 1.5% | May 29, 2017 | An Improper Restriction of Excessive Authentication Attempts issue was discovered in Moxa OnCell G3110-HSPA Version 1.3 ... |
| CVE-2017-7913 | — | — | 1.2% | May 29, 2017 | A Plaintext Storage of a Password issue was discovered in Moxa OnCell G3110-HSPA Version 1.3 build 15082117 and previous... |
| CVE-2017-9265 | — | — | 2.8% | May 29, 2017 | In Open vSwitch (OvS) v2.7.0, there is a buffer over-read while parsing the group mod OpenFlow message sent from the con... |
| CVE-2017-9264 | — | — | 2.4% | May 29, 2017 | In lib/conntrack.c in the firewall implementation in Open vSwitch (OvS) 2.6.1, there is a buffer over-read while parsing... |
| CVE-2017-9263 | — | — | 1.0% | May 29, 2017 | In Open vSwitch (OvS) 2.7.0, while parsing an OpenFlow role status message, there is a call to the abort() function for ... |
| CVE-2017-9262 | — | — | 1.8% | May 29, 2017 | In ImageMagick 7.0.5-6 Q16, the ReadJNGImage function in coders/png.c allows attackers to cause a denial of service (mem... |
| CVE-2017-9261 | — | — | 1.5% | May 29, 2017 | In ImageMagick 7.0.5-6 Q16, the ReadMNGImage function in coders/png.c allows attackers to cause a denial of service (mem... |
| CVE-2017-9252 | — | — | 0.6% | May 28, 2017 | andrzuk/FineCMS through 2017-05-28 is vulnerable to a reflected XSS in the search page via the text-search parameter to ... |
| CVE-2017-9251 | — | — | 0.6% | May 28, 2017 | andrzuk/FineCMS through 2017-05-28 is vulnerable to a reflected XSS in the sitename parameter to admin.php. |
| CVE-2017-9250 | HIGH | 7.5 | 2.5% | May 28, 2017 | The lexer_process_char_literal function in jerry-core/parser/js/js-lexer.c in JerryScript 1.0 does not skip memory alloc... |
| CVE-2017-9249 | MEDIUM | 5.4 | 0.7% | May 28, 2017 | Cross-site scripting (XSS) vulnerability in Allen Disk 1.6 allows remote authenticated users to inject arbitrary web scr... |
| CVE-2017-9243 | — | — | 1.0% | May 28, 2017 | Aries QWR-1104 Wireless-N Router with Firmware Version WRC.253.2.0913 has XSS on the Wireless Site Survey page, exploita... |
| CVE-2017-9232 | — | — | 48.5% | May 28, 2017 | Juju before 1.25.12, 2.0.x before 2.0.4, and 2.1.x before 2.1.3 uses a UNIX domain socket without setting appropriate pe... |
| CVE-2017-7296 | — | — | 0.8% | May 28, 2017 | An issue was discovered in Contiki Operating System 3.0. A Persistent XSS vulnerability is present in the MQTT/IBM Cloud... |
| CVE-2017-7295 | — | — | 1.0% | May 28, 2017 | An issue was discovered in Contiki Operating System 3.0. A use-after-free vulnerability exists in httpd-simple.c in cc26... |
| CVE-2017-9242 | — | — | 0.4% | May 27, 2017 | The __ip6_append_data function in net/ipv6/ip6_output.c in the Linux kernel through 4.11.3 is too late in checking wheth... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now