2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-5521HIGH8.1An issue was discovered on NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R...
CVE-2017-5520The media rename feature in GeniXCMS through 0.0.8 does not consider alternative PHP file extensions when checking uploa...
CVE-2017-5519SQL injection vulnerability in Posts.class.php in GeniXCMS through 0.0.8 allows remote attackers to execute arbitrary SQ...
CVE-2017-5518The media-file upload feature in GeniXCMS through 0.0.8 allows remote attackers to conduct SSRF attacks via a URL, as de...
CVE-2017-5517SQL injection vulnerability in author.control.php in GeniXCMS through 0.0.8 allows remote attackers to execute arbitrary...
CVE-2017-5516Multiple cross-site scripting (XSS) vulnerabilities in the user forms in GeniXCMS through 0.0.8 allow remote attackers t...
CVE-2017-5515Cross-site scripting (XSS) vulnerability in the user prompt function in GeniXCMS through 0.0.8 allows remote authenticat...
CVE-2017-5223An issue was discovered in PHPMailer before 5.2.22. PHPMailer's msgHTML method applies transformations to an HTML docume...
CVE-2017-5494Multiple cross-site scripting (XSS) vulnerabilities in the file types table in b2evolution through 6.8.3 allow remote au...
CVE-2017-5480Directory traversal vulnerability in inc/files/files.ctrl.php in b2evolution through 6.8.3 allows remote authenticated u...
CVE-2017-5493wp-includes/ms-functions.php in the Multisite WordPress API in WordPress before 4.7.1 does not properly choose random nu...
CVE-2017-5492Cross-site request forgery (CSRF) vulnerability in the widget-editing accessibility-mode feature in WordPress before 4.7...
CVE-2017-5491wp-mail.php in WordPress before 4.7.1 might allow remote attackers to bypass intended posting restrictions via a spoofed...
CVE-2017-5490Cross-site scripting (XSS) vulnerability in the theme-name fallback functionality in wp-includes/class-wp-theme.php in W...
CVE-2017-5489Cross-site request forgery (CSRF) vulnerability in WordPress before 4.7.1 allows remote attackers to hijack the authenti...
CVE-2017-5488Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/update-core.php in WordPress before 4.7.1 allow remote a...
CVE-2017-5487wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before...
CVE-2017-2584arch/x86/kvm/emulate.c in the Linux kernel through 4.9.3 allows local users to obtain sensitive information from kernel ...
CVE-2017-5476Serendipity through 2.0.5 allows CSRF for the installation of an event plugin or a sidebar plugin.
CVE-2017-5475comment.php in Serendipity through 2.0.5 allows CSRF in deleting any comments.
CVE-2017-5474Open redirect vulnerability in comment.php in Serendipity through 2.0.5 allows remote attackers to redirect users to arb...
CVE-2017-5473Cross-site request forgery (CSRF) vulnerability in ntopng through 2.4 allows remote attackers to hijack the authenticati...
CVE-2017-0398An information disclosure vulnerability in Audioserver could enable a local malicious application to access data outside...
CVE-2017-5364Memory Corruption Vulnerability in Foxit PDF Toolkit v1.3 allows an attacker to cause Denial of Service and Remote Code ...
CVE-2017-3890MEDIUM6.1A reflected cross-site scripting vulnerability in the BlackBerry WatchDox Server components Appliance-X, version 1.8.1 a...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now