2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-6048A Command Injection issue was discovered in Satel Iberia SenNet Data Logger and Electricity Meters: SenNet Optimal DataL...
CVE-2017-6027An Arbitrary File Upload issue was discovered in 3S-Smart Software Solutions GmbH CODESYS Web Server. The following vers...
CVE-2017-6025A Stack Buffer Overflow issue was discovered in 3S-Smart Software Solutions GmbH CODESYS Web Server. The following versi...
CVE-2017-6016An Improper Access Control issue was discovered in LCDS - Leao Consultoria e Desenvolvimento de Sistemas LTDA ME LAquis ...
CVE-2017-5177A Stack Buffer Overflow issue was discovered in VIPA Controls WinPLC7 5.0.45.5921 and prior. A stack-based buffer overfl...
CVE-2017-5176A DLL Hijack issue was discovered in Rockwell Automation Connected Components Workbench (CCW). The following versions ar...
CVE-2017-5174An Authentication Bypass issue was discovered in Geutebruck IP Camera G-Cam/EFD-2250 Version 1.11.0.12. An authenticatio...
CVE-2017-5173CRITICAL9.8An Improper Neutralization of Special Elements (in an OS command) issue was discovered in Geutebruck IP Camera G-Cam/EFD...
CVE-2017-9073Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-0176. Reason: This candidate is a reservation ...
CVE-2017-6652A vulnerability in the web framework of the Cisco TelePresence IX5000 Series could allow an unauthenticated, remote atta...
CVE-2017-6623A vulnerability in a script file that is installed as part of the Cisco Policy Suite (CPS) Software distribution for the...
CVE-2017-6622A vulnerability in the web interface for Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote a...
CVE-2017-6621A vulnerability in the web interface of Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote at...
CVE-2017-3980A directory traversal vulnerability in the ePO Extension in McAfee ePolicy Orchestrator (ePO) 5.9.0, 5.3.2, and 5.1.3 an...
CVE-2017-9072Two CalendarXP products have XSS in common parts of HTML files. CalendarXP FlatCalendarXP through 9.9.290 has XSS in ifl...
CVE-2017-9071In MODX Revolution before 2.5.7, an attacker might be able to trigger XSS by injecting a payload into the HTTP Host head...
CVE-2017-9070In MODX Revolution before 2.5.7, a user with resource edit permissions can inject an XSS payload into the title of any p...
CVE-2017-9069In MODX Revolution before 2.5.7, a user with file upload permissions is able to execute arbitrary code by uploading a fi...
CVE-2017-9068In MODX Revolution before 2.5.7, an attacker is able to trigger Reflected XSS by injecting payloads into several fields ...
CVE-2017-9067In MODX Revolution before 2.5.7, when PHP 5.3.3 is used, an attacker is able to include and execute arbitrary files on t...
CVE-2017-7503It was found that the Red Hat JBoss EAP 7.0.5 implementation of javax.xml.transform.TransformerFactory is vulnerable to ...
CVE-2017-9066In WordPress before 4.7.5, there is insufficient redirect validation in the HTTP class, leading to SSRF.
CVE-2017-9065In WordPress before 4.7.5, there is a lack of capability checks for post meta data in the XML-RPC API.
CVE-2017-9064In WordPress before 4.7.5, a Cross Site Request Forgery (CSRF) vulnerability exists in the filesystem credentials dialog...
CVE-2017-9063In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability related to the Customizer exists, involving an inv...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now