2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-3189 | — | — | 6.5% | Jul 24, 2018 | The dotCMS administration panel, versions 3.7.1 and earlier, "Push Publishing" feature in Enterprise Pro is vulnerable t... |
| CVE-2017-3188 | — | — | 2.8% | Jul 24, 2018 | The dotCMS administration panel, versions 3.7.1 and earlier, "Push Publishing" feature in Enterprise Pro is vulnerable t... |
| CVE-2017-3187 | — | — | 1.1% | Jul 24, 2018 | The dotCMS administration panel, versions 3.7.1 and earlier, are vulnerable to cross-site request forgery. The dotCMS ad... |
| CVE-2017-3183 | — | — | 2.1% | Jul 24, 2018 | Sage XRT Treasury, version 3, fails to properly restrict database access to authorized users, which may enable any authe... |
| CVE-2017-3182 | — | — | 0.3% | Jul 24, 2018 | On the iOS platform, the ThreatMetrix SDK versions prior to 3.2 fail to validate SSL certificates provided by HTTPS conn... |
| CVE-2017-3181 | — | — | 1.7% | Jul 24, 2018 | Multiple TIBCO Products are prone to multiple unspecified SQL-injection vulnerabilities because it fails to properly san... |
| CVE-2017-3180 | — | — | 0.6% | Jul 24, 2018 | Multiple TIBCO Products are prone to multiple unspecified cross-site scripting vulnerabilities because it fails to prope... |
| CVE-2017-18104 | — | — | 1.6% | Jul 24, 2018 | The Webhooks component of Atlassian Jira before version 7.6.7 and from version 7.7.0 before version 7.11.0 allows remote... |
| CVE-2017-1633 | MEDIUM | 4.3 | 1.7% | Jul 20, 2018 | IBM Sterling B2B Integrator 5.2 through 5.2.6 could allow an authenticated attacker to obtain sensitive variable name in... |
| CVE-2017-1575 | MEDIUM | 5.1 | 0.2% | Jul 20, 2018 | IBM Sterling B2B Integrator Standard Edition (IBM Sterling File Gateway 2.2.0 through 2.2.6) uses weaker than expected c... |
| CVE-2017-1544 | LOW | 2.4 | 0.4% | Jul 20, 2018 | IBM Sterling B2B Integrator Standard Edition (IBM Sterling File Gateway 2.2.0 through 2.2.6) caches usernames and passwo... |
| CVE-2017-18343 | — | — | 6.1% | Jul 20, 2018 | The debug handler in Symfony before v2.7.33, 2.8.x before v2.8.26, 3.x before v3.2.13, and 3.3.x before v3.3.6 has XSS v... |
| CVE-2017-7481 | CRITICAL | 9.8 | 4.6% | Jul 19, 2018 | Ansible before versions 2.3.1.0 and 2.4.0.0 fails to properly mark lookup-plugin results as unsafe. If an attacker could... |
| CVE-2017-2673 | MEDIUM | 6.8 | 2.1% | Jul 19, 2018 | An authorization-check flaw was discovered in federation configurations of the OpenStack Identity service (keystone). An... |
| CVE-2017-18103 | — | — | 0.8% | Jul 18, 2018 | The atlassian-http library, as used in various Atlassian products, before version 2.0.2 allows remote attackers to spoof... |
| CVE-2017-17541 | — | — | 0.9% | Jul 16, 2018 | A Cross-site Scripting (XSS) vulnerability in Fortinet FortiManager 6.0.0, 5.6.4 and below versions, FortiAnalyzer 6.0.0... |
| CVE-2017-15137 | MEDIUM | 4.3 | 1.0% | Jul 16, 2018 | The OpenShift image import whitelist failed to enforce restrictions correctly when running commands such as "oc tag", fo... |
| CVE-2017-7468 | MEDIUM | 4.8 | 1.9% | Jul 16, 2018 | In curl and libcurl 7.52.0 to and including 7.53.1, libcurl would attempt to resume a TLS session even if the client cer... |
| CVE-2017-2638 | MEDIUM | 6.5 | 1.6% | Jul 16, 2018 | It was found that the REST API in Infinispan before version 9.0.0 did not properly enforce auth constraints. An attacker... |
| CVE-2017-13097 | — | — | 0.5% | Jul 13, 2018 | The P1735 IEEE standard describes flawed methods for encrypting electronic-design intellectual property (IP), as well as... |
| CVE-2017-13096 | — | — | 0.5% | Jul 13, 2018 | The P1735 IEEE standard describes flawed methods for encrypting electronic-design intellectual property (IP), as well as... |
| CVE-2017-13095 | — | — | 0.5% | Jul 13, 2018 | The P1735 IEEE standard describes flawed methods for encrypting electronic-design intellectual property (IP), as well as... |
| CVE-2017-13094 | — | — | 0.3% | Jul 13, 2018 | The P1735 IEEE standard describes flawed methods for encrypting electronic-design intellectual property (IP), as well as... |
| CVE-2017-13093 | — | — | 0.5% | Jul 13, 2018 | The P1735 IEEE standard describes flawed methods for encrypting electronic-design intellectual property (IP), as well as... |
| CVE-2017-13092 | — | — | 0.5% | Jul 13, 2018 | The P1735 IEEE standard describes flawed methods for encrypting electronic-design intellectual property (IP), as well as... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now