2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-9388 | — | — | 3.6% | Jun 17, 2019 | An issue was discovered on Vera VeraEdge 1.7.19 and Veralite 1.7.481 devices. The device provides a web user interface t... |
| CVE-2017-8252 | — | — | 0.2% | Jun 14, 2019 | Kernel can inject faults in computations during the execution of TrustZone leading to information disclosure in Snapdrag... |
| CVE-2017-15123 | MEDIUM | 5.3 | 1.4% | Jun 12, 2019 | A flaw was found in the CloudForms web interface, versions 5.8 - 5.10, where the RSS feed URLs are not properly restrict... |
| CVE-2017-18378 | HIGH | 8.4 | 8.2% | Jun 11, 2019 | In NETGEAR ReadyNAS Surveillance before 1.4.3-17 x86 and before 1.1.4-7 ARM, $_GET['uploaddir'] is not escaped and is pa... |
| CVE-2017-18377 | CRITICAL | 9.8 | 6.4% | Jun 11, 2019 | An issue was discovered on Wireless IP Camera (P2P) WIFICAM cameras. There is Command Injection in the set_ftp.cgi scrip... |
| CVE-2017-13718 | — | — | 2.1% | Jun 10, 2019 | The HTTP API supported by Starry Station (aka Starry Router) allows brute forcing the PIN setup by the user on the devic... |
| CVE-2017-13717 | — | — | 2.6% | Jun 10, 2019 | Starry Station (aka Starry Router) sets the Access-Control-Allow-Origin header to "*". This allows any hosted file on an... |
| CVE-2017-6261 | HIGH | 8.2 | 0.4% | Jun 5, 2019 | NVIDIA Vibrante Linux version 1.1, 2.0, and 2.2 contains a vulnerability in the user space driver in which protection me... |
| CVE-2017-14854 | CRITICAL | 9.1 | 7.2% | Jun 3, 2019 | A stack buffer overflow exists in one of the Orpak SiteOmat CGI components, allowing for remote code execution. The vuln... |
| CVE-2017-14853 | HIGH | 8.6 | 3.8% | Jun 3, 2019 | The Orpak SiteOmat OrCU component is vulnerable to code injection, for all versions prior to 2017-09-25, due to a search... |
| CVE-2017-14852 | HIGH | 8.6 | 1.0% | Jun 3, 2019 | An insecure communication was found between a user and the Orpak SiteOmat management console for all known versions, due... |
| CVE-2017-14851 | CRITICAL | 9.8 | 4.0% | Jun 3, 2019 | A SQL injection vulnerability exists in all Orpak SiteOmat versions prior to 2017-09-25. The vulnerability is in the log... |
| CVE-2017-14850 | MEDIUM | 6.1 | 1.7% | Jun 3, 2019 | All known versions of the Orpak SiteOmat web management console is vulnerable to multiple instances of Stored Cross-site... |
| CVE-2017-14728 | CRITICAL | 9.8 | 6.2% | Jun 3, 2019 | An authentication bypass was found in an unknown area of the SiteOmat source code. All SiteOmat BOS versions are affecte... |
| CVE-2017-18376 | — | — | 1.9% | Jun 2, 2019 | An improper authorization check in the User API in TheHive before 2.13.4 and 3.x before 3.3.1 allows users with read-onl... |
| CVE-2017-18375 | — | — | 1.6% | May 24, 2019 | Ampache 3.8.3 allows PHP Object Instantiation via democratic.ajax.php and democratic.class.php. |
| CVE-2017-13667 | — | — | 0.9% | May 23, 2019 | OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: SSRF. |
| CVE-2017-11560 | — | — | 1.4% | May 23, 2019 | An issue was discovered in ZOHO ManageEngine OpManager 12.2. By adding a Google Map to the application, an authenticated... |
| CVE-2017-11559 | — | — | 4.5% | May 23, 2019 | An issue was discovered in ZOHO ManageEngine OpManager 12.2. The 'apiKey' parameter of "/api/json/admin/getmailserverset... |
| CVE-2017-11557 | — | — | 3.7% | May 23, 2019 | An issue was discovered in ZOHO ManageEngine Applications Manager 12.3. It is possible for an unauthenticated user to vi... |
| CVE-2017-11365 | — | — | 1.9% | May 23, 2019 | Certain Symfony products are affected by: Incorrect Access Control. This affects Symfony 2.7.30 and Symfony 2.8.23 and S... |
| CVE-2017-13668 | — | — | 0.5% | May 23, 2019 | OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS). |
| CVE-2017-11740 | — | — | 3.1% | May 23, 2019 | In Zoho ManageEngine Application Manager 13.1 Build 13100, the administrative user has the ability to upload files/binar... |
| CVE-2017-11739 | — | — | 2.8% | May 23, 2019 | In Zoho ManageEngine Application Manager 13.1 Build 13100, an authenticated user, with administrative privileges, has th... |
| CVE-2017-11738 | — | — | 4.1% | May 23, 2019 | In Zoho ManageEngine Application Manager prior to 14.6 Build 14660, the 'haid' parameter of the '/auditLogAction.do' mod... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now