2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-5594 | HIGH | 7.5 | 7.0% | Jan 25, 2017 | An issue was discovered in Pagekit CMS before 1.0.11. In this vulnerability the remote attacker is able to reset the reg... |
| CVE-2017-5495 | — | — | 18.8% | Jan 24, 2017 | All versions of Quagga, 0.93 through 1.1.0, are vulnerable to an unbounded memory allocation in the telnet 'vty' CLI, le... |
| CVE-2017-2972 | — | — | 2.8% | Jan 24, 2017 | Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitabl... |
| CVE-2017-2971 | — | — | 9.1% | Jan 24, 2017 | Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitabl... |
| CVE-2017-2970 | — | — | 7.4% | Jan 24, 2017 | Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitabl... |
| CVE-2017-2929 | — | — | 4.0% | Jan 24, 2017 | Adobe Acrobat Chrome extension version 15.1.0.3 and earlier have a DOM-based cross-site scripting vulnerability. Success... |
| CVE-2017-5372 | — | — | 3.5% | Jan 23, 2017 | The function msp (aka MSPRuntimeInterface) in the P4 SERVERCORE component in SAP AS JAVA allows remote attackers to obta... |
| CVE-2017-5371 | — | — | 3.7% | Jan 23, 2017 | Odata Server in SAP Adaptive Server Enterprise (ASE) 16 allows remote attackers to cause a denial of service (process cr... |
| CVE-2017-5570 | — | — | 1.2% | Jan 23, 2017 | An issue was discovered in eClinicalWorks Patient Portal 7.0 build 13. This is a blind SQL injection within the messageJ... |
| CVE-2017-5569 | — | — | 2.0% | Jan 23, 2017 | An issue was discovered in eClinicalWorks Patient Portal 7.0 build 13. This is a blind SQL injection within the template... |
| CVE-2017-5182 | — | — | 3.1% | Jan 23, 2017 | Remote Manager in Open Enterprise Server (OES) allows unauthenticated remote attackers to read any arbitrary file, via a... |
| CVE-2017-5575 | — | — | 2.8% | Jan 23, 2017 | SQL injection vulnerability in inc/lib/Options.class.php in GeniXCMS before 1.0.0 allows remote attackers to execute arb... |
| CVE-2017-5574 | — | — | 2.4% | Jan 23, 2017 | SQL injection vulnerability in register.php in GeniXCMS before 1.0.0 allows unauthenticated users to execute arbitrary S... |
| CVE-2017-5563 | — | — | 3.0% | Jan 23, 2017 | LibTIFF version 4.0.7 is vulnerable to a heap-based buffer over-read in tif_lzw.c resulting in DoS or code execution via... |
| CVE-2017-5556 | — | — | 3.7% | Jan 23, 2017 | The ConvertToPDF plugin in Foxit Reader before 8.2 and PhantomPDF before 8.2 on Windows, when the gflags app is enabled,... |
| CVE-2017-5554 | — | — | 3.0% | Jan 23, 2017 | An issue was discovered in ABOOT in OnePlus 3 and 3T OxygenOS before 4.0.2. The attacker can reboot the device into the ... |
| CVE-2017-5553 | — | — | 1.2% | Jan 23, 2017 | Cross-site scripting (XSS) vulnerability in plugins/markdown_plugin/_markdown.plugin.php in b2evolution before 6.8.5 all... |
| CVE-2017-5544 | MEDIUM | 5.9 | 5.2% | Jan 23, 2017 | An issue was discovered on FiberHome Fengine S5800 switches V210R240. An unauthorized attacker can access the device's S... |
| CVE-2017-5539 | — | — | 4.1% | Jan 23, 2017 | The patch for directory traversal (CVE-2017-5480) in b2evolution version 6.8.4-stable has a bypass vulnerability. An att... |
| CVE-2017-5545 | — | — | 3.8% | Jan 21, 2017 | The main function in plistutil.c in libimobiledevice libplist through 1.12 allows attackers to obtain sensitive informat... |
| CVE-2017-5543 | — | — | 2.0% | Jan 20, 2017 | includes/classes/ia.core.users.php in Subrion CMS 4.0.5 allows remote attackers to conduct PHP Object Injection attacks ... |
| CVE-2017-5542 | — | — | 1.2% | Jan 20, 2017 | Cross-site scripting (XSS) vulnerability in template/usererror.missing_extension.php in Symphony CMS before 2.6.10 allow... |
| CVE-2017-5541 | — | — | 2.5% | Jan 20, 2017 | Directory traversal vulnerability in template/usererror.missing_extension.php in Symphony CMS before 2.6.10 allows remot... |
| CVE-2017-2578 | — | — | 0.9% | Jan 20, 2017 | In Moodle 3.x, there is XSS in the assignment submission page. |
| CVE-2017-2576 | — | — | 1.0% | Jan 20, 2017 | In Moodle 2.x and 3.x, there is incorrect sanitization of attributes in forums. |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now