2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-7990 | — | — | 1.1% | Apr 21, 2017 | The Reporting Module 1.12.0 for OpenMRS allows CSRF attacks with resultant XSS, in which administrative authentication i... |
| CVE-2017-6619 | — | — | 2.6% | Apr 20, 2017 | A vulnerability in the web-based GUI of Cisco Integrated Management Controller (IMC) 3.0(1c) could allow an authenticate... |
| CVE-2017-6618 | — | — | 0.9% | Apr 20, 2017 | A vulnerability in the web-based GUI of Cisco Integrated Management Controller (IMC) 3.0(1c) could allow an authenticate... |
| CVE-2017-6617 | — | — | 1.0% | Apr 20, 2017 | A vulnerability in the session identification management functionality of the web-based GUI of Cisco Integrated Manageme... |
| CVE-2017-6616 | — | — | 4.2% | Apr 20, 2017 | A vulnerability in the web-based GUI of Cisco Integrated Management Controller (IMC) 3.0(1c) could allow an authenticate... |
| CVE-2017-6615 | — | — | 1.7% | Apr 20, 2017 | A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE 3.16 could allow an authentic... |
| CVE-2017-6614 | — | — | 1.7% | Apr 20, 2017 | A vulnerability in the file-download feature of the web user interface for Cisco FindIT Network Probe Software 1.0.0 cou... |
| CVE-2017-6613 | — | — | 2.0% | Apr 20, 2017 | A vulnerability in the DNS input packet processor for Cisco Prime Network Registrar could allow an unauthenticated, remo... |
| CVE-2017-6611 | — | — | 1.2% | Apr 20, 2017 | A vulnerability in the web framework code of Cisco Prime Infrastructure 2.2(2) could allow an unauthenticated, remote at... |
| CVE-2017-6610 | — | — | 3.0% | Apr 20, 2017 | A vulnerability in the Internet Key Exchange Version 1 (IKEv1) XAUTH code of Cisco ASA Software could allow an authentic... |
| CVE-2017-6609 | — | — | 2.8% | Apr 20, 2017 | A vulnerability in the IPsec code of Cisco ASA Software could allow an authenticated, remote attacker to cause a reload ... |
| CVE-2017-6608 | — | — | 4.6% | Apr 20, 2017 | A vulnerability in the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) code of Cisco ASA Software could al... |
| CVE-2017-6607 | — | — | 2.4% | Apr 20, 2017 | A vulnerability in the DNS code of Cisco ASA Software could allow an unauthenticated, remote attacker to cause an affect... |
| CVE-2017-4969 | — | — | 0.9% | Apr 20, 2017 | The Cloud Controller in Cloud Foundry cf-release versions prior to v255 allows authenticated developer users to exceed m... |
| CVE-2017-3863 | — | — | 2.8% | Apr 20, 2017 | Multiple vulnerabilities in the EnergyWise module of Cisco IOS (12.2 and 15.0 through 15.6) and Cisco IOS XE (3.2 throug... |
| CVE-2017-3862 | — | — | 2.8% | Apr 20, 2017 | Multiple vulnerabilities in the EnergyWise module of Cisco IOS (12.2 and 15.0 through 15.6) and Cisco IOS XE (3.2 throug... |
| CVE-2017-3861 | — | — | 2.8% | Apr 20, 2017 | Multiple vulnerabilities in the EnergyWise module of Cisco IOS (12.2 and 15.0 through 15.6) and Cisco IOS XE (3.2 throug... |
| CVE-2017-3860 | — | — | 2.8% | Apr 20, 2017 | Multiple vulnerabilities in the EnergyWise module of Cisco IOS (12.2 and 15.0 through 15.6) and Cisco IOS XE (3.2 throug... |
| CVE-2017-3808 | — | — | 2.5% | Apr 20, 2017 | A vulnerability in the Session Initiation Protocol (SIP) UDP throttling process of Cisco Unified Communications Manager ... |
| CVE-2017-3793 | — | — | 1.7% | Apr 20, 2017 | A vulnerability in the TCP normalizer of Cisco Adaptive Security Appliance (ASA) Software (8.0 through 8.7 and 9.0 throu... |
| CVE-2017-1122 | — | — | 0.3% | Apr 20, 2017 | IBM Security Guardium 8.2, 9.0, and 10.0 contains a vulnerability that could allow a local attacker with CLI access to i... |
| CVE-2017-5160 | MEDIUM | 5.3 | 0.5% | Apr 20, 2017 | An Inadequate Encryption Strength issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version... |
| CVE-2017-5158 | CRITICAL | 9.8 | 2.4% | Apr 20, 2017 | An Information Exposure issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 an... |
| CVE-2017-5156 | HIGH | 8.8 | 1.0% | Apr 20, 2017 | A Cross-Site Request Forgery issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5... |
| CVE-2017-5183 | — | — | 0.7% | Apr 20, 2017 | NetIQ Access Manager 4.2.2 and 4.3.x before 4.3.1+, when configured as an Identity Server, has XSS in the AssertionConsu... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now