2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-6814In WordPress before 4.7.3, there is authenticated Cross-Site Scripting (XSS) via Media File Metadata. This is demonstrat...
CVE-2017-6812paintballrefjosh/MaNGOSWebV4 4.0.8 is vulnerable to a reflected XSS in inc/admin/template_files/admin.vote.php (id param...
CVE-2017-6811paintballrefjosh/MaNGOSWebV4 4.0.8 is vulnerable to a reflected XSS in inc/admin/template_files/admin.shop.php (id param...
CVE-2017-6810paintballrefjosh/MaNGOSWebV4 4.0.8 is vulnerable to a reflected XSS in inc/admin/template_files/admin.fplinks.php (linki...
CVE-2017-6809paintballrefjosh/MaNGOSWebV4 4.0.8 is vulnerable to a reflected XSS in inc/admin/template_files/admin.donate.php (id par...
CVE-2017-6808paintballrefjosh/MaNGOSWebV4 4.0.8 is vulnerable to a reflected XSS in inc/admin/template_files/admin.faq.php (id parame...
CVE-2017-6513The WHMCS Reseller Module V2 2.0.2 in Softaculous Virtualizor before 2.9.1.0 does not verify the user correctly, which a...
CVE-2017-6466F-Secure Software Updater 2.20, as distributed in several F-Secure products, downloads installation packages over plain ...
CVE-2017-5638CRITICAL9.8The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha...
CVE-2017-6804Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ...
CVE-2017-6802An issue was discovered in ytnef before 1.9.2. There is a potential heap-based buffer over-read on incoming Compressed R...
CVE-2017-6801An issue was discovered in ytnef before 1.9.2. There is a potential out-of-bounds access with fields of Size 0 in TNEFPa...
CVE-2017-6800An issue was discovered in ytnef before 1.9.2. An invalid memory access (heap-based buffer over-read) can occur during h...
CVE-2017-6799A cross-site scripting (XSS) vulnerability in view_filters_page.php in MantisBT before 2.2.1 allows remote attackers to ...
CVE-2017-6798HIGH7.8Trend Micro Endpoint Sensor 1.6 before b1290 has a DLL hijacking vulnerability that allows remote attackers to execute a...
CVE-2017-6596partclone.chkimg in partclone 0.2.89 is prone to a heap-based buffer overflow vulnerability due to insufficient validati...
CVE-2017-6506In Azure Data Expert Ultimate 2.2.16, the SMTP verification function suffers from a buffer overflow vulnerability, leadi...
CVE-2017-6427A Buffer Overflow was discovered in EvoStream Media Server 1.7.1. A crafted HTTP request with a malicious header will ca...
CVE-2017-5859CRITICAL9.8On Cambium Networks cnPilot R200/201 devices before 4.3, there is a vulnerability involving the certificate of the devic...
CVE-2017-2788CRITICAL10A buffer overflows exists in the psnotifyd application of the Pharos PopUp printer client version 9.0. A specially craft...
CVE-2017-2787CRITICAL9A buffer overflows exists in the psnotifyd application of the Pharos PopUp printer client version 9.0. A specially craft...
CVE-2017-2786HIGH7.5A denial of service vulnerability exists in the psnotifyd application of the Pharos PopUp printer client version 9.0. A ...
CVE-2017-2785CRITICAL10An exploitable buffer overflow exists in the psnotifyd application of the Pharos PopUp printer client version 9.0. A spe...
CVE-2017-6355Integer overflow in the vrend_create_shader function in vrend_renderer.c in virglrenderer before 0.6.0 allows local gues...
CVE-2017-6314MEDIUM5.5The make_available_at_least function in io-tiff.c in gdk-pixbuf allows context-dependent attackers to cause a denial of ...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now