2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-8316 | — | — | 2.3% | Aug 3, 2018 | IntelliJ IDEA XML parser was found vulnerable to XML External Entity attack, an attacker can exploit the vulnerability b... |
| CVE-2017-6215 | — | — | 0.8% | Aug 2, 2018 | paypal/permissions-sdk-php is vulnerable to reflected XSS in the samples/GetAccessToken.php verification_code parameter,... |
| CVE-2017-6213 | — | — | 0.8% | Aug 2, 2018 | paypal/invoice-sdk-php is vulnerable to reflected XSS in samples/permissions.php via the permToken parameter, resulting ... |
| CVE-2017-16349 | HIGH | 8.1 | 1.2% | Aug 2, 2018 | An exploitable XML external entity vulnerability exists in the reporting functionality of SAP BPC. A specially crafted X... |
| CVE-2017-16347 | CRITICAL | 9.9 | 1.4% | Aug 2, 2018 | An attacker could send an authenticated HTTP request to trigger this vulnerability in Insteon Hub running firmware versi... |
| CVE-2017-16346 | CRITICAL | 9.9 | 1.4% | Aug 2, 2018 | An attacker could send an authenticated HTTP request to trigger this vulnerability in Insteon Hub running firmware versi... |
| CVE-2017-16345 | CRITICAL | 9.9 | 1.4% | Aug 2, 2018 | An attacker could send an authenticated HTTP request to trigger this vulnerability in Insteon Hub running firmware versi... |
| CVE-2017-16344 | CRITICAL | 9.9 | 1.4% | Aug 2, 2018 | An attacker could send an authenticated HTTP request to trigger this vulnerability in Insteon Hub running firmware versi... |
| CVE-2017-16343 | CRITICAL | 9.9 | 1.4% | Aug 2, 2018 | An attacker could send an authenticated HTTP request to trigger this vulnerability in Insteon Hub running firmware versi... |
| CVE-2017-16342 | CRITICAL | 9.9 | 1.4% | Aug 2, 2018 | An attacker could send an authenticated HTTP request to trigger this vulnerability in Insteon Hub running firmware versi... |
| CVE-2017-16341 | CRITICAL | 9.9 | 1.4% | Aug 2, 2018 | An attacker could send an authenticated HTTP request to trigger this vulnerability in Insteon Hub running firmware versi... |
| CVE-2017-16340 | CRITICAL | 9.9 | 1.4% | Aug 2, 2018 | An attacker could send an authenticated HTTP request to trigger this vulnerability in Insteon Hub running firmware versi... |
| CVE-2017-16339 | CRITICAL | 9.9 | 1.4% | Aug 2, 2018 | An attacker could send an authenticated HTTP request to trigger this vulnerability in Insteon Hub running firmware versi... |
| CVE-2017-16338 | CRITICAL | 9.9 | 1.4% | Aug 2, 2018 | An attacker could send an authenticated HTTP request to trigger this vulnerability in Insteon Hub running firmware versi... |
| CVE-2017-14446 | CRITICAL | 9.9 | 1.3% | Aug 2, 2018 | An exploitable stack-based buffer overflow vulnerability exists in Insteon Hub running firmware version 1012. The HTTP s... |
| CVE-2017-14445 | CRITICAL | 9.9 | 1.1% | Aug 2, 2018 | An exploitable buffer overflow vulnerability exists in Insteon Hub running firmware version 1012. The HTTP server implem... |
| CVE-2017-14444 | CRITICAL | 9.9 | 1.4% | Aug 2, 2018 | An exploitable buffer overflow vulnerability exists in Insteon Hub running firmware version 1012. The HTTP server implem... |
| CVE-2017-9120 | CRITICAL | 9.8 | 7.6% | Aug 2, 2018 | PHP 7.x through 7.1.5 allows remote attackers to cause a denial of service (buffer overflow and application crash) or po... |
| CVE-2017-9118 | HIGH | 7.5 | 3.0% | Aug 2, 2018 | PHP 7.1.5 has an Out of bounds access in php_pcre_replace_impl via a crafted preg_replace call. |
| CVE-2017-5692 | — | — | 0.3% | Aug 1, 2018 | Out-of-bounds read condition in older versions of some Intel Graphics Driver for Windows code branches allows local user... |
| CVE-2017-5693 | — | — | 4.3% | Jul 31, 2018 | Firmware in the Intel Puma 5, 6, and 7 Series might experience resource depletion or timeout, which allows a network att... |
| CVE-2017-13652 | — | — | 1.0% | Jul 31, 2018 | NetApp OnCommand Insight version 7.3.0 and versions prior to 7.2.0 are susceptible to clickjacking attacks which could c... |
| CVE-2017-17708 | — | — | 0.6% | Jul 31, 2018 | Because of insufficient authorization checks it is possible for any authenticated user to change profile data of other u... |
| CVE-2017-17707 | — | — | 0.8% | Jul 31, 2018 | Due to missing authorization checks, any authenticated user is able to list, upload, or delete attachments to password s... |
| CVE-2017-17174 | — | — | 1.1% | Jul 31, 2018 | Some Huawei products RSE6500 V500R002C00; SoftCo V200R003C20SPCb00; VP9660 V600R006C10; eSpace U1981 V100R001C20; V200R0... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now