14,642 vulnerabilities published in 2017
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to obtain
IBM API Connect 5.0.0.0 could allow a remote attacker to obtain sensitive information, caused by improper handling of re
The Avira Mobile Security app before 1.5.11 for iOS sends sensitive login information in cleartext.
On D-Link DIR-605L devices, firmware before 2.08UIBetaB01.bin allows an unauthenticated GET request to trigger a reboot.
QNAP QTS before 4.2.6 build 20170517 has a flaw in the change password function.
In uClibc 0.9.33.2, there is stack exhaustion (uncontrolled recursion) in the check_dst_limits_calc_pos_1 function in mi
In meta/classes/package_ipk.bbclass in Poky in poky-pyro 17.0.0 for Yocto Project through YP Core - Pyro 2.3, attackers
GnuTLS version 3.5.12 and earlier is vulnerable to a NULL pointer dereference while decoding a status response TLS exten
Kibana before 4.5.4 and 4.1.11 when a custom output is configured for logging in, cookies and authorization headers coul
Logstash prior to version 2.3.4, Elasticsearch Output plugin would log to file HTTP authorization headers which could co
Logstash prior to version 2.1.2, the CSV output can be attacked via engineered input that will create malicious formulas
Logstash versions prior to 2.3.3, when using the Netflow Codec plugin, a remote attacker crafting malicious Netflow v5,
X-Pack 5.1.1 did not properly apply document and field level security to multi-search and multi-get requests so users wi
Kibana versions prior to 5.2.1 configured for SSL client access, file descriptors will fail to be cleaned up after certa
Jetty through 9.4.x is prone to a timing channel in util/security/Password.java, which makes it easier for remote attack
XML external entity (XXE) vulnerability in Citrix XenMobile Server 9.x and 10.x before 10.5 RP3 allows attackers to obta
The grub_ext2_read_block function in fs/ext2.c in GNU GRUB before 2013-11-12, as used in shlr/grub/fs/ext2.c in radare2
The Milwaukee ONE-KEY Android mobile application stores the master token in plaintext in the apk binary.
If multiple users are concurrently logged into a single system where one user is sending a command via the Lenovo ToolsC
The HTTP strict parsing changes added in Apache httpd 2.2.32 and 2.4.24 introduced a bug in token list parsing, which al
Adobe Captivate versions 9 and earlier have an information disclosure vulnerability resulting from abuse of the quiz rep
In Wireshark 2.2.7, PROFINET IO data with a high recursion depth allows remote attackers to cause a denial of service (s
An exploitable buffer overflow vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Came
An exploitable buffer overflow vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Came
A Resource Consumption issue was discovered in Trihedral VTScada Versions prior to 11.2.26. The client does not properly
An Information Exposure issue was discovered in Trihedral VTScada Versions prior to 11.2.26. Some files are exposed with
Multiple SQL injection vulnerabilities in GLPI 0.90.4 allow an authenticated remote attacker to execute arbitrary SQL co
ExpressionEngine version 2.x < 2.11.8 and version 3.x < 3.5.5 create an object signing token with weak entropy. Successf
'/cgi-bin/admin/downloadMedias.cgi' of the web service in most of the VIVOTEK Network Cameras is vulnerable, which allow
/cgi-bin/wapopen in Boa 0.94.14rc21 allows the injection of "../.." using the FILECAMERA variable (sent by GET) to read
A vulnerability in the ingress UDP packet processing functionality of Cisco Virtualized Packet Core-Distributed Instance
ntopng before 3.0 allows HTTP Response Splitting.
The NetKVM Windows Virtio driver allows remote attackers to cause a denial of service (guest crash) via a crafted length
The NetworkInterface::getHost function in NetworkInterface.cpp in ntopng before 3.0 allows remote attackers to cause a d
There is an invalid free in Image::printIFDStructure that leads to a Segmentation fault in Exiv2 0.26. A crafted input w
OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to remote denial-of-service when receiving malformed IPv6
tpm2-tools versions before 1.1.1 are vulnerable to a password leak due to transmitting password in plaintext from client
IBM QRadar 7.2 and 7.3 does not require that users should have strong passwords by default, which makes it easier for at
TeamSpeak Client 3.0.19 allows remote attackers to cause a denial of service (application crash) via the ᗪ Unicode
Internet Explorer 6, Internet Explorer 7, Internet Explorer 8, Internet Explorer 9, Internet Explorer 10, and Internet E
Huawei Ascend P7 allows remote attackers to cause a denial of service (phone process crash).
res_query in libresolv in glibc before 2.25 allows remote attackers to cause a denial of service (NULL pointer dereferen
Logstash 1.5.x before 1.5.3 and 1.4.x before 1.4.4 allows remote attackers to read communications between Logstash Forwa
ManageEngine Firewall Analyzer before 8.0 does not restrict access permissions.
FreeIPA 4.4.0 allows remote attackers to request an arbitrary SAN name for services.
elog 3.1.1 allows remote attackers to post data as any username in the logbook.
In systemd through 233, certain sizes passed to dns_packet_new in systemd-resolved can cause it to allocate a buffer tha
There is a heap-based buffer overflow in the function hpel_motion in mpegvideo_motion.c in libav 12.1. A crafted input c
FFmpeg before 2.8.12, 3.0.x and 3.1.x before 3.1.9, 3.2.x before 3.2.6, and 3.3.x before 3.3.2 does not properly restric
Apache Ignite 1.0.0-RC3 to 2.0 uses an update notifier component to update the users about new project releases that inc
Scan for 2017 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started