CVEs from 2017

11,796 normalized CVEs published or assigned in this year.

Total
11,796
critical
critical 1,647
high
high 5,043
medium
medium 4,165
low
low 159
% Critical
14.0%
% with KEV
0.7%
% with exploit
0.8%

Top vendors

Top products

  • imagemagick 1,426
  • joomla\! 932
  • kanboard 848
  • ntp 762
  • tomcat 676
  • mahara 572
  • postgresql 492
  • asterisk 435
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Published Description Impact
CVE-2017-7494 high 9.5 3y ago Samba contains a remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share and then cause the server to load and execute it. archsusedebian
CVE-2017-8291 high 9.5 4y ago Artifex Ghostscript allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a "/OutputFile. archsusedebian
CVE-2017-16651 high 9.5 5y ago Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, including configuration files, as exploited in the … archdebian
CVE-2017-1000253 unknown 1.5 2y ago Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (committed on April 14, 2015). This kernel vulnerability w… susedebian
CVE-2017-12617 unknown 1.5 4y ago Unrestricted Upload of File with Dangerous Type Apache Tomcat susejava
CVE-2017-9791 unknown 1.5 4y ago Code execution in Apache Struts 1 plugin java
CVE-2017-1000353 unknown 1.5 4y ago Deserialization of Untrusted Data in Jenkins java
CVE-2017-1000486 unknown 1.5 5y ago Inadequate Encryption Strength java
CVE-2017-5638 unknown 1.5 8y ago Apache Struts vulnerable to remote arbitrary command execution due to improper input validation java
CVE-2017-12615 unknown 1.5 8y ago When running Apache Tomcat on Windows with HTTP PUTs enabled it was possible to upload a JSP file to the server susejava
CVE-2017-9805 unknown 1.5 8y ago REST Plugin in Apache Struts uses an XStreamHandler with an instance of XStream for deserialization without any type filtering java