14,642 vulnerabilities published in 2017
I, Librarian version <=4.6 & 4.7 is vulnerable to OS Command Injection in batchimport.php resulting the web server being
I, Librarian version <=4.6 & 4.7 is vulnerable to Server-Side Request Forgery in the ajaxsupplement.php resulting in the
Redis-store <=v1.3.0 allows unsafe objects to be loaded from redis
CPython (aka Python) up to 2.7.13 is vulnerable to an integer overflow in the PyString_DecodeEscape function in stringob
An issue was discovered in Teluu pjproject (pjlib and pjlib-util) in PJSIP before 2.7.1. Parsing the numeric header fiel
samtools htslib library version 1.4.0 and earlier is vulnerable to buffer overflow in the CRAM rANS codec resulting in p
Elixir's vim plugin, alchemist.vim is vulnerable to remote code execution in the bundled alchemist-server. A malicious w
Cygnux sysPass version 2.1.7 and older is vulnerable to a Local File Inclusion in the functionality of javascript files
QuickerBB version <= 0.7.2 is vulnerable to arbitrary file writes which can lead to remote code execution. This can lead
ROOT xrootd version 4.6.0 and below is vulnerable to an unauthenticated shell command injection resulting in remote code
On Jooan IP Camera A5 2.3.36 devices, an insecure FTP server does not require authentication, which allows remote attack
An issue has been discovered on the Belden Hirschmann Tofino Xenon Security Appliance before 03.2.00. Improper handling
An issue has been discovered on the Belden Hirschmann Tofino Xenon Security Appliance before 03.2.00. Design flaws in OP
A SQL injection in classes/handler/public.php in the forgotpass component of Tiny Tiny RSS 17.4 exists via the login par
LvyeCMS through 3.1 allows remote attackers to upload and execute arbitrary PHP code via directory traversal sequences i
The VC-2 Video Compression encoder in FFmpeg 3.0 and 3.4 allows remote attackers to cause a denial of service (out-of-bo
An issue was discovered in middleware.py in OpenStack Swauth through 1.2.0 when used with OpenStack Swift through 2.15.1
v5/config/system.php in dayrui FineCms 5.2.0 has a default SYS_KEY value and does not require key regeneration for each
A vulnerability in the Intel Deep Learning Training Tool Beta 1 allows a network attacker to remotely execute code as a
Multiple SQL injection vulnerabilities in Fiyo CMS 2.0_1.9.1 allow remote attackers to execute arbitrary SQL commands vi
A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1) passed certain parameters to the jenkin
Ohcount 3.0.0 is prone to a command injection via specially crafted filenames containing shell metacharacters, which can
Missing authentication for the remote configuration port 1236/tcp on the Cohu 3960HD allows an attacker to change config
The webupgrade function on the Cohu 3960HD does not verify the firmware upgrade files or process, allowing an attacker t
Client-side enforcement using JavaScript of server-side security options on the Cohu 3960HD allows an attacker to manipu
QNAP has already patched this vulnerability. This security concern allows a remote attacker to run arbitrary commands on
VCM5010 with software versions earlier before V100R002C50SPC100 has an authentication bypass vulnerability. This is due
The UMA product with software V200R001 and V300R001 has a privilege elevation vulnerability due to insufficient validati
The UMA product with software V200R001 and V300R001 has a privilege elevation vulnerability due to insufficient validati
The UMA product with software V200R001 and V300R001 has a privilege elevation vulnerability due to insufficient validati
The UMA product with software V200R001 has a privilege elevation vulnerability due to insufficient validation or imprope
The UMA product with software V200R001 has a privilege elevation vulnerability due to insufficient validation or imprope
The UMA product with software V200R001 has a privilege elevation vulnerability due to insufficient validation or imprope
The UMA product with software V200R001 has a privilege elevation vulnerability due to insufficient validation or imprope
The UMA product with software V200R001 and V300R001 has a privilege elevation vulnerability due to insufficient validati
The UMA product with software V200R001 and V300R001 has a privilege elevation vulnerability due to insufficient validati
plugins/preauth/pkinit/pkinit_crypto_openssl.c in MIT Kerberos 5 (aka krb5) through 1.15.2 mishandles Distinguished Name
An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. The backup file contains sensitive information in
parser.c in libxml2 before 2.9.5 mishandles parameter-entity references because the NEXTL macro calls the xmlParserHandl
The web server on DBL DBLTek devices allows remote attackers to execute arbitrary OS commands by obtaining the admin pas
Ametys before 4.0.3 requires authentication only for URIs containing a /cms/ substring, which allows remote attackers to
The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to execute arbitr
In Pivotal Spring AMQP versions prior to 1.7.4, 1.6.11, and 1.5.7, an org.springframework.amqp.core.Message may be unsaf
GitPHP by xiphux is vulnerable to OS Command Injections
math.js before 3.17.0 had an arbitrary code execution in the JavaScript engine. Creating a typed function with JavaScrip
math.js before 3.17.0 had an issue where private properties such as a constructor could be replaced by using unicode cha
The Hipchat for Mac desktop client is vulnerable to client-side remote code execution via video call link parsing. Hipch
Use-after-free vulnerability in Samba 4.x before 4.7.3 allows remote attackers to execute arbitrary code via a crafted S
An issue was discovered in EMC ScaleIO 2.0.1.x. A buffer overflow vulnerability in the SDBG service may potentially allo
Customer of Dahua IP camera or IP PTZ could submit relevant device information to receive a time limited temporary passw
Scan for 2017 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started