14,642 vulnerabilities published in 2017
ofx_proc_file in ofx_preproc.cpp in LibOFX 0.9.12 allows remote attackers to cause a denial of service (heap-based buffe
ReadRLEImage in coders/rle.c in GraphicsMagick 1.3.26 mishandles RLE headers that specify too few colors, which allows r
A vulnerability exists in Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and Po
A vulnerability exists in Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and Po
The ReadCAPTIONImage function in coders/caption.c in ImageMagick 7.0.7-3 allows remote attackers to cause a denial of se
Mojoomla Annual Maintenance Contract (AMC) Management System allows Arbitrary File Upload in profilesetting image handli
A vulnerability in the wireless controller manager of Cisco IOS XE could allow an unauthenticated, adjacent attacker to
A vulnerability in the implementation of a protocol in Cisco Integrated Services Routers Generation 2 (ISR G2) Routers r
A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS 15.0 through 15.4 for Cisco Catalyst 6800 Se
An error was found in the X-Pack Security 5.3.0 to 5.5.2 privilege enforcement. If a user has either 'delete' or 'index'
An authentication vulnerability in HPE BSM Platform Application Performance Management System Health product versions 9.
An authentication vulnerability in HPE BSM Platform Application Performance Management System Health product versions 9.
An insufficient access control vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c P
An improper access control vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch
Jaspersoft JasperReports 4.7 suffers from a saved credential disclosure vulnerability, which allows a remote authenticat
OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might b
A use-after-free in RenderFreetype in MagickCore/annotate.c in ImageMagick 7.0.7-4 Q16 allows attackers to crash the app
WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but stores the analogous wp_users.user_activation_key
When an Apache Geode cluster before v1.2.1 is operating in secure mode, an unauthenticated client can enter multi-user a
ReadDCMImage in coders/dcm.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (NULL pointer
GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (excessive memory allocation) because of an i
In Apache Impala (incubating) before 2.10.0, a malicious user with "ALTER" permissions on an Impala table can access any
Parameterized Trigger Plugin fails to check Item/Build permission: The Parameterized Trigger Plugin did not check the bu
Subversion Plugin connects to a user-specified Subversion repository as part of form validation (e.g. to retrieve a list
Docker Commons Plugin provides a list of applicable credential IDs to allow users configuring a job to select the one th
The default whitelist included the following unsafe entries: DefaultGroovyMethods.putAt(Object, String, Object); Default
When asking to get a file from a file:// URL, libcurl provides a feature that outputs meta-data about the file using HTT
When doing a TFTP transfer and curl/libcurl is given a URL that contains a very long file name (longer than about 515 by
curl supports "globbing" of URLs, in which a user can pass a numerical range to have the tool iterate over those numbers
The Config File Provider Plugin is used to centrally manage configuration files that often include secrets, such as pass
A vulnerability in the Akamai Connect feature of Cisco Wide Area Application Services (WAAS) Appliances could allow an u
A vulnerability in the Network Access Manager (NAM) of Cisco AnyConnect Secure Mobility Client could allow an authentica
The web UI in Rapid7 Metasploit before 4.14.1-20170828 allows logout CSRF, aka R7-2017-22.
Directory traversal vulnerability in the Visor GUI Console in GridGain before 1.7.16, 1.8.x before 1.8.12, 1.9.x before
libjpeg-turbo before 1.3.1 allows remote attackers to cause a denial of service (crash) via a crafted JPEG file, related
An authorized user could upload a template which contained malicious code and accessed sensitive files via an XML Extern
url_check_format in include/functions.inc.php in Piwigo before 2.8.3 allows remote attackers to bypass intended access r
ImageMagick 7.0.7-2 has a memory leak in ReadSGIImage in coders/sgi.c.
ImageMagick 7.0.7-2 has a memory leak in ReadOneJNGImage in coders/png.c.
IBM Financial Transaction Manager for ACH Services for Multi-Platform 3.0.2 could allow an authenticated user to obtain
libjpeg-turbo 1.5.2 has a NULL Pointer Dereference in jdpostct.c and jquant1.c via a crafted JPEG file.
ReadGIFImage in coders/gif.c in ImageMagick 7.0.6-1 and GraphicsMagick 1.3.26 leaves the palette uninitialized when proc
In Apache Ranger before 0.6.2, users with "keyadmin" role should not be allowed to change password for users with "admin
If extended statistics are enabled via 'set chassis extended-statistics', when executing any operation that fetches inte
Apache Subversion's mod_dontdothat module and HTTP clients 1.4.0 through 1.8.16, and 1.9.0 through 1.9.4 are vulnerable
An Information Exposure issue was discovered in ProMinent MultiFLEX M10a Controller web interface. When an authenticated
The embedded web server on ABB Fox515T 1.0 devices is vulnerable to Local File Inclusion. It accepts a parameter that sp
An issue was discovered in Xen through 4.9.x allowing x86 HVM guest OS users to obtain sensitive information from the ho
An issue was discovered in Xen 4.5.x through 4.9.x allowing attackers (who control a stub domain kernel or tool stack) t
An issue was discovered in Xen through 4.9.x allowing x86 PV guest OS users to cause a denial of service (memory leak) b
Scan for 2017 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started