2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-6883 | — | — | 3.4% | Mar 14, 2017 | The ConvertToPDF plugin in Foxit Reader before 8.2.1 and PhantomPDF before 8.2.1 on Windows, when the gflags app is enab... |
| CVE-2017-6877 | — | — | 1.0% | Mar 14, 2017 | Cross-site scripting (XSS) vulnerability in SVG file handling in Lutim 0.7.1 and earlier allows remote attackers to inje... |
| CVE-2017-6874 | HIGH | 7 | 0.3% | Mar 14, 2017 | Race condition in kernel/ucount.c in the Linux kernel through 4.10.2 allows local users to cause a denial of service (us... |
| CVE-2017-6398 | — | — | 55.0% | Mar 14, 2017 | An issue was discovered in Trend Micro InterScan Messaging Security (Virtual Appliance) 9.1-1600. An authenticated user ... |
| CVE-2017-6367 | — | — | 8.6% | Mar 14, 2017 | In Cerberus FTP Server 8.0.10.1, a crafted HTTP request causes the Windows service to crash. The attack methodology invo... |
| CVE-2017-6807 | — | — | 1.1% | Mar 13, 2017 | mod_auth_mellon before 0.13.1 is vulnerable to a Cross-Site Session Transfer attack, where a user with access to one web... |
| CVE-2017-6180 | — | — | 0.5% | Mar 13, 2017 | Keekoon KK002 devices 1.8.12 HD have a Cross Site Request Forgery Vulnerability affecting goform/formChnUserPwd and gofo... |
| CVE-2017-6081 | — | — | 0.6% | Mar 13, 2017 | A CSRF issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. To exploit the vulnerabi... |
| CVE-2017-6080 | — | — | 0.7% | Mar 13, 2017 | An issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1, caused by lack of a protecti... |
| CVE-2017-5929 | CRITICAL | 9.8 | 8.6% | Mar 13, 2017 | QOS.ch Logback before 1.2.0 has a serialization vulnerability affecting the SocketServer and ServerSocketReceiver compon... |
| CVE-2017-5675 | — | — | 1.7% | Mar 13, 2017 | A command-injection vulnerability exists in a web application on a custom-built GoAhead web server used on Foscam, Vstar... |
| CVE-2017-5674 | — | — | 21.6% | Mar 13, 2017 | A vulnerability in a custom-built GoAhead web server used on Foscam, Vstarcam, and multiple white-label IP camera models... |
| CVE-2017-5621 | — | — | 0.7% | Mar 13, 2017 | An issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. XSS can be triggered via mal... |
| CVE-2017-5620 | — | — | 0.7% | Mar 13, 2017 | An XSS issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. Attachments are opened i... |
| CVE-2017-5619 | — | — | 1.5% | Mar 13, 2017 | An issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. Attackers can login with the... |
| CVE-2017-6823 | — | — | 8.0% | Mar 12, 2017 | Fiyo CMS 2.0.6.1 allows remote authenticated users to gain privileges via a modified level parameter to dapur/ in an app... |
| CVE-2017-6820 | — | — | 1.3% | Mar 12, 2017 | rcube_utils.php in Roundcube before 1.1.8 and 1.2.x before 1.2.4 is susceptible to a cross-site scripting vulnerability ... |
| CVE-2017-6444 | HIGH | 7.5 | 13.5% | Mar 12, 2017 | The MikroTik Router hAP Lite 6.25 has no protection mechanism for unsolicited TCP ACK packets in the case of a fast netw... |
| CVE-2017-5626 | — | — | 2.8% | Mar 12, 2017 | OxygenOS before version 4.0.2, on OnePlus 3 and 3T, has two hidden fastboot oem commands (4F500301 and 4F500302) that al... |
| CVE-2017-5624 | — | — | 2.7% | Mar 12, 2017 | An issue was discovered in OxygenOS before 4.0.3 for OnePlus 3 and 3T. The attacker can persistently make the (locked) b... |
| CVE-2017-6819 | — | — | 2.3% | Mar 12, 2017 | In WordPress before 4.7.3, there is cross-site request forgery (CSRF) in Press This (wp-admin/includes/class-wp-press-th... |
| CVE-2017-6818 | — | — | 2.8% | Mar 12, 2017 | In WordPress before 4.7.3 (wp-admin/js/tags-box.js), there is cross-site scripting (XSS) via taxonomy term names. |
| CVE-2017-6817 | — | — | 2.1% | Mar 12, 2017 | In WordPress before 4.7.3 (wp-includes/embed.php), there is authenticated Cross-Site Scripting (XSS) in YouTube URL Embe... |
| CVE-2017-6816 | — | — | 3.1% | Mar 12, 2017 | In WordPress before 4.7.3 (wp-admin/plugins.php), unintended files can be deleted by administrators using the plugin del... |
| CVE-2017-6815 | — | — | 3.0% | Mar 12, 2017 | In WordPress before 4.7.3 (wp-includes/pluggable.php), control characters can trick redirect URL validation. |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now