14,642 vulnerabilities published in 2017
An improper access control vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch
Jaspersoft JasperReports 4.7 suffers from a saved credential disclosure vulnerability, which allows a remote authenticat
OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might b
A use-after-free in RenderFreetype in MagickCore/annotate.c in ImageMagick 7.0.7-4 Q16 allows attackers to crash the app
WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but stores the analogous wp_users.user_activation_key
When an Apache Geode cluster before v1.2.1 is operating in secure mode, an unauthenticated client can enter multi-user a
ReadDCMImage in coders/dcm.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (NULL pointer
GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (excessive memory allocation) because of an i
In Apache Impala (incubating) before 2.10.0, a malicious user with "ALTER" permissions on an Impala table can access any
Parameterized Trigger Plugin fails to check Item/Build permission: The Parameterized Trigger Plugin did not check the bu
Subversion Plugin connects to a user-specified Subversion repository as part of form validation (e.g. to retrieve a list
Docker Commons Plugin provides a list of applicable credential IDs to allow users configuring a job to select the one th
The default whitelist included the following unsafe entries: DefaultGroovyMethods.putAt(Object, String, Object); Default
When asking to get a file from a file:// URL, libcurl provides a feature that outputs meta-data about the file using HTT
When doing a TFTP transfer and curl/libcurl is given a URL that contains a very long file name (longer than about 515 by
curl supports "globbing" of URLs, in which a user can pass a numerical range to have the tool iterate over those numbers
The Config File Provider Plugin is used to centrally manage configuration files that often include secrets, such as pass
A vulnerability in the Akamai Connect feature of Cisco Wide Area Application Services (WAAS) Appliances could allow an u
A vulnerability in the Network Access Manager (NAM) of Cisco AnyConnect Secure Mobility Client could allow an authentica
The web UI in Rapid7 Metasploit before 4.14.1-20170828 allows logout CSRF, aka R7-2017-22.
Directory traversal vulnerability in the Visor GUI Console in GridGain before 1.7.16, 1.8.x before 1.8.12, 1.9.x before
libjpeg-turbo before 1.3.1 allows remote attackers to cause a denial of service (crash) via a crafted JPEG file, related
An authorized user could upload a template which contained malicious code and accessed sensitive files via an XML Extern
url_check_format in include/functions.inc.php in Piwigo before 2.8.3 allows remote attackers to bypass intended access r
ImageMagick 7.0.7-2 has a memory leak in ReadSGIImage in coders/sgi.c.
ImageMagick 7.0.7-2 has a memory leak in ReadOneJNGImage in coders/png.c.
IBM Financial Transaction Manager for ACH Services for Multi-Platform 3.0.2 could allow an authenticated user to obtain
libjpeg-turbo 1.5.2 has a NULL Pointer Dereference in jdpostct.c and jquant1.c via a crafted JPEG file.
ReadGIFImage in coders/gif.c in ImageMagick 7.0.6-1 and GraphicsMagick 1.3.26 leaves the palette uninitialized when proc
In Apache Ranger before 0.6.2, users with "keyadmin" role should not be allowed to change password for users with "admin
If extended statistics are enabled via 'set chassis extended-statistics', when executing any operation that fetches inte
Apache Subversion's mod_dontdothat module and HTTP clients 1.4.0 through 1.8.16, and 1.9.0 through 1.9.4 are vulnerable
An Information Exposure issue was discovered in ProMinent MultiFLEX M10a Controller web interface. When an authenticated
The embedded web server on ABB Fox515T 1.0 devices is vulnerable to Local File Inclusion. It accepts a parameter that sp
An issue was discovered in Xen through 4.9.x allowing x86 HVM guest OS users to obtain sensitive information from the ho
An issue was discovered in Xen 4.5.x through 4.9.x allowing attackers (who control a stub domain kernel or tool stack) t
An issue was discovered in Xen through 4.9.x allowing x86 PV guest OS users to cause a denial of service (memory leak) b
Red Hat CloudForms 3 Management Engine (CFME) allows remote authenticated users to cause a denial of service (resource c
Double free vulnerability in the j2k_read_ppm_v3 function in OpenJPEG before r2997, as used in PDFium in Google Chrome,
In the 3CX Phone System 15.5.3554.1, the Management Console typically listens to port 5001 and is prone to a directory t
An issue was discovered in Octopus before 3.17.7. When the special Guest user account is granted the CertificateExportPr
In Octopus before 3.17.7, an authenticated user who was explicitly granted the permission to invite new users (aka UserI
Vulnerability in the Oracle Applications DBA component of Oracle E-Business Suite (subcomponent: AD Utilities). Supporte
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Container). Support
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that a
Vulnerability in the XML Database component of Oracle Database Server. Supported versions that are affected are 11.2.0.4
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: FTS). Supported versions that are aff
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Test Frame
Vulnerability in the Oracle Hospitality Suite8 component of Oracle Hospitality Applications (subcomponent: WebConnect).
Vulnerability in the Oracle Hospitality Simphony component of Oracle Hospitality Applications (subcomponent: Import/Expo
Scan for 2017 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started