2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-7388 | MEDIUM | 6.1 | 0.8% | Apr 1, 2017 | A Cross-Site Scripting (XSS) was discovered in 'wallacepos v1.4.1'. The vulnerability exists due to insufficient filtrat... |
| CVE-2017-7387 | — | — | 0.7% | Apr 1, 2017 | TheFirstQuestion/HelpMeWatchWho before 2017-03-28 is vulnerable to a reflected XSS in HelpMeWatchWho-master/unaired.php ... |
| CVE-2017-7386 | — | — | 0.7% | Apr 1, 2017 | citymont/symetrie v.0.9.6 is vulnerable to a reflected XSS in symetrie-master/app/commands/page.php (model parameter). |
| CVE-2017-7374 | HIGH | 7.8 | 0.8% | Mar 31, 2017 | Use-after-free vulnerability in fs/crypto/ in the Linux kernel before 4.10.7 allows local users to cause a denial of ser... |
| CVE-2017-2775 | HIGH | 7.5 | 2.9% | Mar 31, 2017 | An exploitable memory corruption vulnerability exists in the LvVariantUnflatten functionality in 64-bit versions of LabV... |
| CVE-2017-1171 | — | — | 0.7% | Mar 31, 2017 | The IBM TRIRIGA Application Platform 3.3, 3,4, and 3,5 contain a vulnerability that could allow an authenticated user to... |
| CVE-2017-1154 | — | — | 1.0% | Mar 31, 2017 | IBM Algorithmics One-Algo Risk Application 4.9.1, 5.0, and 5.1.0 could allow a user to gain access to files in the local... |
| CVE-2017-3010 | — | — | 4.6% | Mar 31, 2017 | Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitabl... |
| CVE-2017-3009 | — | — | 4.4% | Mar 31, 2017 | Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitabl... |
| CVE-2017-7363 | — | — | 0.8% | Mar 31, 2017 | Pixie 1.0.4 allows an admin/index.php s=publish&m=module&x= XSS attack. |
| CVE-2017-7362 | — | — | 0.8% | Mar 31, 2017 | Pixie 1.0.4 allows an admin/index.php s=publish&m=dynamic&x= XSS attack. |
| CVE-2017-7361 | — | — | 0.8% | Mar 31, 2017 | Pixie 1.0.4 allows an admin/index.php s=publish&m=static&x= XSS attack. |
| CVE-2017-7360 | — | — | 0.8% | Mar 31, 2017 | Pixie 1.0.4 allows an admin/index.php s=settings&x= XSS attack. |
| CVE-2017-7359 | — | — | 1.2% | Mar 31, 2017 | Pixie 1.0.4 allows an admin/index.php s=login&m= XSS attack. |
| CVE-2017-7309 | — | — | 57.7% | Mar 31, 2017 | A cross-site scripting (XSS) vulnerability in the MantisBT Configuration Report page (adm_config_report.php) allows remo... |
| CVE-2017-7241 | — | — | 0.9% | Mar 31, 2017 | A cross-site scripting (XSS) vulnerability in the MantisBT Move Attachments page (move_attachments_page.php, part of adm... |
| CVE-2017-6973 | — | — | 0.9% | Mar 31, 2017 | A cross-site scripting (XSS) vulnerability in the MantisBT Configuration Report page (adm_config_report.php) allows remo... |
| CVE-2017-2647 | — | — | 0.4% | Mar 31, 2017 | The KEYS subsystem in the Linux kernel before 3.18 allows local users to gain privileges or cause a denial of service (N... |
| CVE-2017-7346 | — | — | 0.4% | Mar 30, 2017 | The vmw_gb_surface_define_ioctl function in drivers/gpu/drm/vmwgfx/vmwgfx_surface.c in the Linux kernel through 4.10.7 d... |
| CVE-2017-7253 | — | — | 2.3% | Mar 30, 2017 | Dahua IP Camera devices 3.200.0001.6 can be exploited via these steps: 1. Use the default low-privilege credentials to l... |
| CVE-2017-6412 | — | — | 7.5% | Mar 30, 2017 | In Sophos Web Appliance (SWA) before 4.3.1.2, Session Fixation could occur, aka NSWA-1310. |
| CVE-2017-6184 | — | — | 2.5% | Mar 30, 2017 | In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's interface responsible for generating reports wa... |
| CVE-2017-6183 | — | — | 3.2% | Mar 30, 2017 | In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's configuration utilities for adding (and detecti... |
| CVE-2017-6182 | — | — | 16.6% | Mar 30, 2017 | In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's interface responsible for generating reports wa... |
| CVE-2017-5185 | — | — | 1.7% | Mar 30, 2017 | A vulnerability was discovered in NetIQ Sentinel Server 8.0 before 8.0.1 that may allow remote denial of service. |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now