14,642 vulnerabilities published in 2017
In the cron package through 3.0pl1-128 on Debian, and through 3.0pl1-128ubuntu2 on Ubuntu, the postinst maintainer scrip
A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to elevate privileges t
A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to execute arbitrary co
A vulnerability in the installation procedure for Cisco Prime Network Software could allow an authenticated, local attac
A vulnerability in the backup and restore functionality of Cisco FireSIGHT System Software could allow an authenticated,
Some Lenovo brand notebook systems do not have write protections properly configured in the system BIOS. This could enab
Intense PC Phoenix SecureCore UEFI firmware does not perform capsule signature validation before upgrading the system fi
A vulnerability in the CLI parser of the Cisco Web Security Appliance (WSA) could allow an authenticated, local attacker
VMware Tools prior to 10.0.9 contains multiple file system races in libDeployPkg, related to the use of hard-coded paths
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Supported versions t
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version
A vulnerability in the CLI of Cisco ASR 5000 Series Aggregated Services Routers running the Cisco StarOS operating syste
A vulnerability in the CLI command-parsing code of Cisco Meeting Server could allow an authenticated, local attacker to
A vulnerability in the USB-modem code of Cisco IOS XE Software running on Cisco ASR 920 Series Aggregation Services Rout
IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) could allow a local user wit
IBM DB2 for Linux, UNIX and Windows 9.7, 10,1, 10.5, and 11.1 (includes DB2 Connect Server) could allow a local user wit
IBM Informix Dynamic Server 12.1 could allow a local user logged in with database administrator user to gain root privil
A vulnerability in the CLI of Cisco UCS Central Software could allow an authenticated, local attacker to gain shell acce
An attacker who obtains access to the location where the LXCA file system is stored may be able to access credentials of
Services and files in Lenovo Fingerprint Manager before 8.01.42 have incorrect ACLs, which allows local users to invalid
The Microsoft Device Guard on Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a security
A vulnerability in the Python scripting subsystem of Cisco NX-OS Software could allow an authenticated, local attacker t
An Unquoted Search Path or Element issue was discovered in Progea Movicon Version 11.5.1181 and prior. An unquoted searc
PRTG Network Monitor 17.3.33.2830 allows remote authenticated administrators to execute arbitrary code by uploading a .e
The Cisco AMP For Endpoints application allows an authenticated, local attacker to access a static key value stored in t
Extreme EXOS 16.x, 21.x, and 22.x allows administrators to obtain a root shell via vectors involving an exsh debug shell
Extreme EXOS 16.x, 21.x, and 22.x allows administrators to obtain a root shell via vectors involving a privileged proces
Extreme EXOS 16.x, 21.x, and 22.x allows administrators to bypass the "exsh restricted shell" protection mechanism and o
A vulnerability in the debug interface of Cisco IP Phone 8800 series could allow an authenticated, local attacker to exe
An untrusted search path (aka DLL Preloading) vulnerability in the Cisco Immunet antimalware installer could allow an au
An untrusted search path (aka DLL Preload) vulnerability in the Cisco Network Academy Packet Tracer software could allow
PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, 9.5.x before 9.5.10, 9.4.x before 9.4.15, 9.3.x before 9.3.20, and 9.2.
The Files APP 7.1.1.308 and earlier versions in some Huawei mobile phones has a vulnerability of plaintext storage of us
FusionSphere OpenStack V100R006C00SPC102(NFV)has an improper verification of cryptographic signature vulnerability. The
A vulnerability in Cisco NX-OS System Software could allow an authenticated, local attacker to bypass signature verifica
A vulnerability in Cisco NX-OS System Software could allow an authenticated, local attacker to bypass signature verifica
A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to perform a comm
A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to perform a comm
A vulnerability in certain system script files that are installed at boot time on Cisco Application Policy Infrastructur
Palo Alto Networks GlobalProtect Agent before 4.0.3 allows attackers with administration rights on the local station to
In EMC Isilon OneFS 8.1.0.0, 8.0.1.0 - 8.0.1.1, 8.0.0.0 - 8.0.0.4, 7.2.1.0 - 7.2.1.5, 7.2.0.x, and 7.1.1.x, a malicious
The mcollective-puppet-agent plugin before 1.11.1 for Puppet allows remote attackers to execute arbitrary code via vecto
The Norwegian Air Shuttle (aka norwegian.com) airline kiosk allows physically proximate attackers to bypass the intended
An issue was discovered in OxygenOS before 4.1.0 on OnePlus 3 and 3T devices. The attacker can change the bootmode of th
USB Pratirodh is prone to sensitive information disclosure. It stores sensitive information such as username and passwor
The cp_report_fixup function in drivers/hid/hid-cypress.c in the Linux kernel 3.2 and 4.x before 4.9.4 allows physically
Stack-based buffer overflow in DMitry (Deepmagic Information Gathering Tool) version 1.3a (Unix) allows attackers to cau
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Smartcard Libraries). The sup
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client mysqldump). Supported versions that ar
An Improper XML Parser Configuration issue was discovered in Schneider Electric Wonderware Historian Client 2014 R2 SP1
Scan for 2017 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started