2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-6048 | — | — | 15.5% | May 19, 2017 | A Command Injection issue was discovered in Satel Iberia SenNet Data Logger and Electricity Meters: SenNet Optimal DataL... |
| CVE-2017-6027 | — | — | 2.6% | May 19, 2017 | An Arbitrary File Upload issue was discovered in 3S-Smart Software Solutions GmbH CODESYS Web Server. The following vers... |
| CVE-2017-6025 | — | — | 2.0% | May 19, 2017 | A Stack Buffer Overflow issue was discovered in 3S-Smart Software Solutions GmbH CODESYS Web Server. The following versi... |
| CVE-2017-6016 | — | — | 0.3% | May 19, 2017 | An Improper Access Control issue was discovered in LCDS - Leao Consultoria e Desenvolvimento de Sistemas LTDA ME LAquis ... |
| CVE-2017-5177 | — | — | 17.7% | May 19, 2017 | A Stack Buffer Overflow issue was discovered in VIPA Controls WinPLC7 5.0.45.5921 and prior. A stack-based buffer overfl... |
| CVE-2017-5176 | — | — | 0.5% | May 19, 2017 | A DLL Hijack issue was discovered in Rockwell Automation Connected Components Workbench (CCW). The following versions ar... |
| CVE-2017-5174 | — | — | 52.3% | May 19, 2017 | An Authentication Bypass issue was discovered in Geutebruck IP Camera G-Cam/EFD-2250 Version 1.11.0.12. An authenticatio... |
| CVE-2017-5173 | CRITICAL | 9.8 | 29.6% | May 19, 2017 | An Improper Neutralization of Special Elements (in an OS command) issue was discovered in Geutebruck IP Camera G-Cam/EFD... |
| CVE-2017-9073 | — | — | — | May 18, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-0176. Reason: This candidate is a reservation ... |
| CVE-2017-6652 | — | — | 3.6% | May 18, 2017 | A vulnerability in the web framework of the Cisco TelePresence IX5000 Series could allow an unauthenticated, remote atta... |
| CVE-2017-6623 | — | — | 0.3% | May 18, 2017 | A vulnerability in a script file that is installed as part of the Cisco Policy Suite (CPS) Software distribution for the... |
| CVE-2017-6622 | — | — | 62.2% | May 18, 2017 | A vulnerability in the web interface for Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote a... |
| CVE-2017-6621 | — | — | 6.2% | May 18, 2017 | A vulnerability in the web interface of Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote at... |
| CVE-2017-3980 | — | — | 2.8% | May 18, 2017 | A directory traversal vulnerability in the ePO Extension in McAfee ePolicy Orchestrator (ePO) 5.9.0, 5.3.2, and 5.1.3 an... |
| CVE-2017-9072 | — | — | 0.9% | May 18, 2017 | Two CalendarXP products have XSS in common parts of HTML files. CalendarXP FlatCalendarXP through 9.9.290 has XSS in ifl... |
| CVE-2017-9071 | — | — | 0.6% | May 18, 2017 | In MODX Revolution before 2.5.7, an attacker might be able to trigger XSS by injecting a payload into the HTTP Host head... |
| CVE-2017-9070 | — | — | 0.6% | May 18, 2017 | In MODX Revolution before 2.5.7, a user with resource edit permissions can inject an XSS payload into the title of any p... |
| CVE-2017-9069 | — | — | 1.9% | May 18, 2017 | In MODX Revolution before 2.5.7, a user with file upload permissions is able to execute arbitrary code by uploading a fi... |
| CVE-2017-9068 | — | — | 0.7% | May 18, 2017 | In MODX Revolution before 2.5.7, an attacker is able to trigger Reflected XSS by injecting payloads into several fields ... |
| CVE-2017-9067 | — | — | 0.8% | May 18, 2017 | In MODX Revolution before 2.5.7, when PHP 5.3.3 is used, an attacker is able to include and execute arbitrary files on t... |
| CVE-2017-7503 | — | — | 2.0% | May 18, 2017 | It was found that the Red Hat JBoss EAP 7.0.5 implementation of javax.xml.transform.TransformerFactory is vulnerable to ... |
| CVE-2017-9066 | — | — | 3.7% | May 18, 2017 | In WordPress before 4.7.5, there is insufficient redirect validation in the HTTP class, leading to SSRF. |
| CVE-2017-9065 | — | — | 4.1% | May 18, 2017 | In WordPress before 4.7.5, there is a lack of capability checks for post meta data in the XML-RPC API. |
| CVE-2017-9064 | — | — | 1.7% | May 18, 2017 | In WordPress before 4.7.5, a Cross Site Request Forgery (CSRF) vulnerability exists in the filesystem credentials dialog... |
| CVE-2017-9063 | — | — | 2.0% | May 18, 2017 | In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability related to the Customizer exists, involving an inv... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now