Skip to main content

Year archive

CVEs published in 2017

Archive summary

14,642 CVEs published in 2017 — 2,108 Critical, 6,607 High, 5,693 Medium, 234 Low, 0 Unrated.

CVE-2017-17721

Published Dec 18, 2017

CWEBNET/WOSummary/List in ZUUSE BEIMS ContractorWeb .NET 5.18.0.0 allows SQL injection via the tradestatus, assetno, assignto, building, domain, jobtype, site, trade, woType, work…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-14583

Published Dec 18, 2017

NetApp Clustered Data ONTAP versions 9.x prior to 9.1P10 and 9.2P2 are susceptible to a vulnerability which allows an attacker to cause a Denial of Service (DoS) in SMB environmen…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-12630

Published Dec 18, 2017

In Apache Drill 1.11.0 and earlier when submitting form from Query page users are able to pass arbitrary script or HTML which will take effect on Profile page afterwards. Example:…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-17741

Published Dec 18, 2017

The KVM implementation in the Linux kernel through 4.14.7 allows attackers to obtain potentially sensitive information from kernel memory, aka a write_mmio stack-based out-of-boun…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-17739

Published Dec 18, 2017

The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) has directory traversal via the /storage.html rp parameter, allowing an attacker to read or write to file…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-17733

Published Dec 18, 2017

Maccms 8.x allows remote command execution via the wd parameter in an index.php?m=vod-search request.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-17731

Published Dec 18, 2017

DedeCMS through 5.7 has SQL Injection via the $_FILES superglobal to plus/recommend.php.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-17730

Published Dec 18, 2017

DedeCMS through 5.7 has SQL Injection via the logo parameter to plus/flink_add.php.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-17727

Published Dec 18, 2017

DedeCMS through 5.6 allows arbitrary file upload and PHP code execution by embedding the PHP code in a .jpg file, which is used in the templet parameter to member/article_edit.php.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-17716

Published Dec 17, 2017

GitLab 9.4.x before 9.4.2 does not support LDAP SSL certificate verification, but a verify_certificates LDAP option was mentioned in the 9.4 release announcement. This issue occur…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-16950

Published Dec 17, 2017

Cross - site scripting (XSS) vulnerability in UrBackup Server before 2.1.20 allows remote attackers to inject arbitrary web script or HTML via the action parameter.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-17714

Published Dec 16, 2017

Trape before 2017-11-05 has XSS via the /nr red parameter, the /nr vId parameter, the /register User-Agent HTTP header, the /register country parameter, the /register countryCode…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-17713

Published Dec 16, 2017

Trape before 2017-11-05 has SQL injection via the /nr red parameter, the /nr vId parameter, the /register User-Agent HTTP header, the /register country parameter, the /register co…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 451-475 of 14,642 CVEsPage 19 of 586