2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-18385cPanel before 68.0.15 allows unprivileged users to access restricted directories during account restores (SEC-311).
CVE-2017-18384cPanel before 68.0.15 allows jailed accounts to restore files that are outside of the jail (SEC-310).
CVE-2017-18383cPanel before 68.0.15 writes home-directory backups to an incorrect location (SEC-309).
CVE-2017-18382cPanel before 68.0.15 allows use of an unreserved e-mail address in DNS zone SOA records (SEC-306).
CVE-2017-18381HIGH7.2The installation process in Open edX before 2017-01-10 exposes a MongoDB instance to external connections with default c...
CVE-2017-18380HIGH7.5edx-platform before 2017-08-03 allows attackers to trigger password-reset e-mail messages in which the reset link has an...
CVE-2017-18379CRITICAL9.8In the Linux kernel before 4.14, an out of boundary access happened in drivers/nvme/target/fc.c.
CVE-2017-7189main/streams/xp_socket.c in PHP 7.x before 2017-03-07 misparses fsockopen calls, such as by interpreting fsockopen('127....
CVE-2017-6217paypal/adaptivepayments-sdk-php v3.9.2 is vulnerable to a reflected XSS in the SetPaymentOptions.php resulting code exec...
CVE-2017-12652CRITICAL9.8libpng before 1.6.32 does not properly check the length of chunks against the user limit.
CVE-2017-8230On Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices, the users on the device are divided into 2 groups "admin" and "us...
CVE-2017-8229Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices allow an unauthenticated attacker to download the administrative cred...
CVE-2017-8228Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices mishandle reboots within the past two hours. Amcrest cloud services d...
CVE-2017-8227Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices have a timeout policy to wait for 5 minutes in case 30 incorrect pass...
CVE-2017-8226Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices have default credentials that are hardcoded in the firmware and can b...
CVE-2017-13719The Amcrest IPM-721S Amcrest_IPC-AWXX_Eng_N_V2.420.AC00.17.R.20170322 allows HTTP requests that permit enabling various ...
CVE-2017-9327Secret data of processes managed by CM is not secured by file permissions.
CVE-2017-9326The keystore password for the Spark History Server may be exposed in unsecured files under the /var/run/cloudera-scm-age...
CVE-2017-9325The provided secure solrconfig.xml sample configuration does not enforce Sentry authorization on /update/json/docs.
CVE-2017-6900An issue was discovered in Riello NetMan 204 14-2 and 15-2. The issue is with the login script and wrongpass Python scri...
CVE-2017-6216novaksolutions/infusionsoft-php-sdk v2016-10-31 is vulnerable to a reflected XSS in the leadscoring.php resulting code e...
CVE-2017-18346SQL injection vulnerability in /wbg/core/_includes/authorization.inc.php in CMS Web-Gooroo through 2013-01-19 allows rem...
CVE-2017-17972packages/subjects/pub/subjects.php in Archon 3.21 rev-1 has XSS in the referer parameter in an index.php?subjecttypeid=x...
CVE-2017-8417HIGH8.8An issue was discovered on D-Link DCS-1100 and DCS-1130 devices. The device requires that a user logging into the device...
CVE-2017-8416HIGH8.8An issue was discovered on D-Link DCS-1100 and DCS-1130 devices. The device runs a custom daemon on UDP port 5978 which ...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now