Skip to main content

Year archive

CVEs published in 2017

Archive summary

14,642 CVEs published in 2017 — 2,108 Critical, 6,607 High, 5,693 Medium, 234 Low, 0 Unrated.

CVE-2017-17763

Published Dec 19, 2017

SuperBeam through 4.1.3, when using the LAN or WiFi Direct Share feature, does not use HTTPS or any integrity-protection mechanism for file transfer, which makes it easier for rem…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-17753

Published Dec 19, 2017

Multiple cross-site scripting (XSS) vulnerabilities in the esb-csv-import-export plugin through 1.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-17744

Published Dec 19, 2017

A cross-site scripting (XSS) vulnerability in the custom-map plugin through 1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the map_id paramet…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-17719

Published Dec 19, 2017

A cross-site scripting (XSS) vulnerability in the wp-concours plugin through 1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the result_messag…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6465

Published Dec 19, 2017

Multiple cross-site scripting (XSS) vulnerabilities in JBPM KIE Workbench 6.0.x allow remote authenticated users to inject arbitrary web script or HTML via vectors related to task…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-17088

Published Dec 19, 2017

The Enterprise version of SyncBreeze 10.2.12 and earlier is affected by a Remote Denial of Service vulnerability. The web server does not check bounds when reading server requests…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-16786

Published Dec 19, 2017

The Web Configuration Utility in Meinberg LANTIME devices with firmware before 6.24.004 allows remote authenticated users with certain privileges to read arbitrary files via (1) t…

CVSS 6.5 · Medium

CVE-2017-15049

Published Dec 19, 2017

The ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 does not properly sanitize user input when constructing a shell command, which allows remote attackers…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-15048

Published Dec 19, 2017

Stack-based buffer overflow in the ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 allows remote attackers to execute arbitrary code by leveraging the zoom…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-17759

Published Dec 19, 2017

Conarc iChannel allows remote attackers to obtain sensitive information, modify the configuration, or cause a denial of service (by deleting the configuration) via a wc.dll?wwMain…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-17105

Published Dec 19, 2017

Zivif PR115-204-P-RS V2.3.4.2103 and V4.7.4.2121 (and possibly in-between versions) web cameras are vulnerable to unauthenticated, blind remote command injection via CGI scripts u…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2017-16949

Published Dec 19, 2017

An issue was discovered in the AccessKeys AccessPress Anonymous Post Pro plugin through 3.1.9 for WordPress. Improper input sanitization allows the attacker to override the settin…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-15877

Published Dec 19, 2017

Insecure Permissions vulnerability in db.php file in GPWeb 8.4.61 allows remote attackers to view the password and user database.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-15876

Published Dec 19, 2017

Unrestricted File Upload vulnerability in GPWeb 8.4.61 allows remote authenticated users to upload any type of file, including a PHP shell.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2017-15875

Published Dec 19, 2017

SQL injection vulnerability in Password Recovery in GPWeb 8.4.61 allows remote attackers to execute arbitrary SQL commands via the "checkemail" parameter.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-15524

Published Dec 19, 2017

The Application Firewall Pack (AFP, aka Web Application Firewall) component on Kemp Load Balancer devices with software before 7.2.40.1 allows a Security Feature Bypass via an HTT…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-11562

Published Dec 19, 2017

A Session Fixation Vulnerability exists in the MT4 Networks SenhaSegura Web Application 2.2.23.8 via login_if.php.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-15700

Published Dec 18, 2017

A flaw in the org.apache.sling.auth.core.AuthUtil#isRedirectValid method in Apache Sling Authentication Service 1.4.0 allows an attacker, through the Sling login form, to trick a…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 426-450 of 14,642 CVEsPage 18 of 586