2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-9388An issue was discovered on Vera VeraEdge 1.7.19 and Veralite 1.7.481 devices. The device provides a web user interface t...
CVE-2017-8252Kernel can inject faults in computations during the execution of TrustZone leading to information disclosure in Snapdrag...
CVE-2017-15123MEDIUM5.3A flaw was found in the CloudForms web interface, versions 5.8 - 5.10, where the RSS feed URLs are not properly restrict...
CVE-2017-18378HIGH8.4In NETGEAR ReadyNAS Surveillance before 1.4.3-17 x86 and before 1.1.4-7 ARM, $_GET['uploaddir'] is not escaped and is pa...
CVE-2017-18377CRITICAL9.8An issue was discovered on Wireless IP Camera (P2P) WIFICAM cameras. There is Command Injection in the set_ftp.cgi scrip...
CVE-2017-13718The HTTP API supported by Starry Station (aka Starry Router) allows brute forcing the PIN setup by the user on the devic...
CVE-2017-13717Starry Station (aka Starry Router) sets the Access-Control-Allow-Origin header to "*". This allows any hosted file on an...
CVE-2017-6261HIGH8.2NVIDIA Vibrante Linux version 1.1, 2.0, and 2.2 contains a vulnerability in the user space driver in which protection me...
CVE-2017-14854CRITICAL9.1A stack buffer overflow exists in one of the Orpak SiteOmat CGI components, allowing for remote code execution. The vuln...
CVE-2017-14853HIGH8.6The Orpak SiteOmat OrCU component is vulnerable to code injection, for all versions prior to 2017-09-25, due to a search...
CVE-2017-14852HIGH8.6An insecure communication was found between a user and the Orpak SiteOmat management console for all known versions, due...
CVE-2017-14851CRITICAL9.8A SQL injection vulnerability exists in all Orpak SiteOmat versions prior to 2017-09-25. The vulnerability is in the log...
CVE-2017-14850MEDIUM6.1All known versions of the Orpak SiteOmat web management console is vulnerable to multiple instances of Stored Cross-site...
CVE-2017-14728CRITICAL9.8An authentication bypass was found in an unknown area of the SiteOmat source code. All SiteOmat BOS versions are affecte...
CVE-2017-18376An improper authorization check in the User API in TheHive before 2.13.4 and 3.x before 3.3.1 allows users with read-onl...
CVE-2017-18375Ampache 3.8.3 allows PHP Object Instantiation via democratic.ajax.php and democratic.class.php.
CVE-2017-13667OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: SSRF.
CVE-2017-11560An issue was discovered in ZOHO ManageEngine OpManager 12.2. By adding a Google Map to the application, an authenticated...
CVE-2017-11559An issue was discovered in ZOHO ManageEngine OpManager 12.2. The 'apiKey' parameter of "/api/json/admin/getmailserverset...
CVE-2017-11557An issue was discovered in ZOHO ManageEngine Applications Manager 12.3. It is possible for an unauthenticated user to vi...
CVE-2017-11365Certain Symfony products are affected by: Incorrect Access Control. This affects Symfony 2.7.30 and Symfony 2.8.23 and S...
CVE-2017-13668OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS).
CVE-2017-11740In Zoho ManageEngine Application Manager 13.1 Build 13100, the administrative user has the ability to upload files/binar...
CVE-2017-11739In Zoho ManageEngine Application Manager 13.1 Build 13100, an authenticated user, with administrative privileges, has th...
CVE-2017-11738In Zoho ManageEngine Application Manager prior to 14.6 Build 14660, the 'haid' parameter of the '/auditLogAction.do' mod...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now