14,642 vulnerabilities published in 2017
IBM Sametime Meeting Server 8.5.2 and 9.0 could allow a malicious user to lower other users hands in the meeting. IBM X-
IBM Sametime 8.5.2 and 9.0 could allow an unauthorized authenticated user to enumerate group chat ID numbers and join me
IBM Sametime 8.5.1 and 9.0 could allow an authenticated user to enumerate meeting rooms by guessing the meeting room id.
IBM Sametime Meeting Server 8.5.2 and 9.0 could allow a meeting invitee to obtain previously cleared sensitive informati
XML external entity (XXE) vulnerability in bkr/server/jobs.py in Beaker before 20.1 allows remote authenticated users to
The admin pages for power types and key types in Beaker before 20.1 do not have any access controls, which allows remote
A vulnerability in the dynamic access control list (ACL) feature of Cisco IOS XE Software running on Cisco Catalyst 4000
Microsoft Edge in Microsoft Windows 10 Version 1703 allows an attacker to obtain information to further compromise the u
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to leave a mal
Microsoft Edge in Microsoft Windows Version 1703 allows an attacker to obtain information to further compromise the user
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to trick a use
Microsoft Edge in Microsoft Windows 10 Version 1703 allows an attacker to trick a user by redirecting the user to a spec
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Window
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to trick a use
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server
Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to obtain information to further compromise the user's sy
The Entity Registration module 7.x-1.x before 7.x-1.5 for Drupal allows remote attackers to obtain sensitive event regis
Vulnerability in web application Kind Editor v4.1.12, kindeditor/php/upload_json.php does not check authentication befor
In Moodle 3.x, various course reports allow teachers to view details about users in the groups they can't access.
IBM API Connect 5.0.0.0 through 5.0.7.2 could allow an authenticated user to generate an API token when not subscribed t
The (1) filesystem::get_wml_location function in filesystem.cpp and (2) is_legal_file function in filesystem_boost.cpp i
When a cluster is operating in secure mode, a user with read privileges for specific data regions can use the gfsh comma
GitHub Branch Source provides a list of applicable credential IDs to allow users configuring a job to select the one the
Blue Ocean allows the creation of GitHub organization folders that are set up to scan a GitHub organization for reposito
In Kanboard before 1.0.47, by altering form data, an authenticated user can edit swimlanes of a private project of anoth
In Kanboard before 1.0.47, by altering form data, an authenticated user can remove columns from a private project of ano
In Kanboard before 1.0.47, by altering form data, an authenticated user can add a new category to a private project of a
In Kanboard before 1.0.47, by altering form data, an authenticated user can edit a category of a private project of anot
In Kanboard before 1.0.47, by altering form data, an authenticated user can edit metadata of a private project of anothe
In Kanboard before 1.0.47, by altering form data, an authenticated user can add a new task to a private project of anoth
In Kanboard before 1.0.47, by altering form data, an authenticated user can edit tags of a private project of another us
In Kanboard before 1.0.47, by altering form data, an authenticated user can edit columns of a private project of another
In Kanboard before 1.0.47, by altering form data, an authenticated user can remove categories from a private project of
In Kanboard before 1.0.47, by altering form data, an authenticated user can add automatic actions to a private project o
In Kanboard before 1.0.47, by altering form data, an authenticated user can download attachments from a private project
In Kanboard before 1.0.47, by altering form data, an authenticated user can add an internal link to a private project of
In Kanboard before 1.0.47, by altering form data, an authenticated user can edit tasks of a private project of another u
In Kanboard before 1.0.47, by altering form data, an authenticated user can remove automatic actions from a private proj
In Kanboard before 1.0.47, by altering form data, an authenticated user can remove attachments from a private project of
In Kanboard before 1.0.47, by altering form data, an authenticated user can see thumbnails of pictures from a private pr
In Kanboard before 1.0.47, by altering form data, an authenticated user can add an external link to a private project of
In Kanboard before 1.0.47, by altering form data, an authenticated user can at least see the names of tags of a private
RSA Archer GRC Platform prior to 6.2.0.5 is affected by a privilege escalation vulnerability. A low privileged RSA Arche
Cybozu Office 10.0.0 to 10.6.1 allows authenticated attackers to bypass access restriction to perform arbitrary actions
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Window
Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to obtain information to further compromise the user's sy
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arb
OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 contains the following design ga
sharenfs 0.6.4, when built with commits bcdd594 and 7d08880 from the zfs repository, provides world readable access to t
A vulnerability in the cluster database (CDB) management component of Cisco Expressway Series Software and Cisco TelePre
Scan for 2017 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started