Vulnerabilities (CVE)

Total 398770 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-1000239 1 Invoiceplane 1 Invoiceplane 2026-06-17 3.5 LOW 5.4 MEDIUM
InvoicePlane version 1.4.10 is vulnerable to a Stored Cross Site Scripting resulting in allowing an authenticated user to inject malicious client side script which will be executed in the browser of users if they visit the manipulated site.
CVE-2017-1000238 1 Invoiceplane 1 Invoiceplane 2026-06-17 6.5 MEDIUM 8.8 HIGH
InvoicePlane version 1.4.10 is vulnerable to a Arbitrary File Upload resulting in an authenticated user can upload a malicious file to the webserver. It is possible for an attacker to upload a script which is able to compromise the webserver.
CVE-2017-1000237 1 Scilico 1 I\, Librarian 2026-06-17 7.5 HIGH 9.8 CRITICAL
I, Librarian version <=4.6 & 4.7 is vulnerable to Server-Side Request Forgery in the ajaxsupplement.php resulting in the attacker being able to reset any user's password.
CVE-2017-1000236 1 Scilico 1 I\, Librarian 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
I, Librarian version <=4.6 & 4.7 is vulnerable to Reflected Cross-Site Scripting in the temp.php resulting in an attacker being able to inject malicious client side scripting which will be executed in the browser of users if they visit the manipulated site.
CVE-2017-1000235 1 Scilico 1 I\, Librarian 2026-06-17 10.0 HIGH 9.8 CRITICAL
I, Librarian version <=4.6 & 4.7 is vulnerable to OS Command Injection in batchimport.php resulting the web server being fully compromised.
CVE-2017-1000234 1 Scilico 1 I\, Librarian 2026-06-17 5.0 MEDIUM 5.3 MEDIUM
I, Librarian version <=4.6 & 4.7 is vulnerable to Directory Enumeration in the jqueryFileTree.php resulting in attacker enumerating directories simply by navigating through the "dir" parameter
CVE-2017-1000232 1 Nlnetlabs 1 Ldns 2026-06-17 7.5 HIGH 9.8 CRITICAL
A double-free vulnerability in str2host.c in ldns 1.7.0 have unspecified impact and attack vectors.
CVE-2017-1000231 1 Nlnetlabs 1 Ldns 2026-06-17 7.5 HIGH 9.8 CRITICAL
A double-free vulnerability in parse.c in ldns 1.7.0 have unspecified impact and attack vectors.
CVE-2017-1000230 1 Snap7 Project 1 Snap7 Server 2026-06-17 5.0 MEDIUM 7.5 HIGH
The Snap7 Server version 1.4.1 can be crashed when the ItemCount field of the ReadVar or WriteVar functions of the S7 protocol implementation in Snap7 are provided with unexpected input, thus resulting in denial of service attack.
CVE-2017-1000229 2 Debian, Optipng Project 2 Debian Linux, Optipng 2026-06-17 6.8 MEDIUM 7.8 HIGH
Integer overflow bug in function minitiff_read_info() of optipng 0.7.6 allows an attacker to remotely execute code or cause denial of service.
CVE-2017-1000228 1 Ejs 1 Ejs 2026-06-17 10.0 HIGH 9.8 CRITICAL
nodejs ejs versions older than 2.5.3 is vulnerable to remote code execution due to weak input validation in ejs.renderFile() function
CVE-2017-1000227 1 Parallelus 1 Salutation 2026-06-17 3.5 LOW 5.4 MEDIUM
Stored XSS in Salutation Responsive WordPress + BuddyPress Theme version 3.0.15 could allow logged-in users to do almost anything an admin can
CVE-2017-1000226 1 Fullworksplugins 1 Stop User Enumeration 2026-06-17 5.0 MEDIUM 5.3 MEDIUM
Stop User Enumeration 1.3.8 allows user enumeration via the REST API
CVE-2017-1000225 1 Relevanssi 1 Relevanssi 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Reflected XSS in Relevanssi Premium version 1.14.8 when using relevanssi_didyoumean() could allow unauthenticated attacker to do almost anything an admin can
CVE-2017-1000224 1 Embedplus 1 Youtube 2026-06-17 4.3 MEDIUM 6.5 MEDIUM
CSRF in YouTube (WordPress plugin) could allow unauthenticated attacker to change any setting within the plugin
CVE-2017-1000223 1 Modx 1 Modx Revolution 2026-06-17 3.5 LOW 5.4 MEDIUM
A stored web content injection vulnerability (WCI, a.k.a XSS) is present in MODX Revolution CMS version 2.5.6 and earlier. An authenticated user with permissions to edit users can save malicious JavaScript as a User Group name and potentially take control over victims' accounts. This can lead to an escalation of privileges providing complete administrative control over the CMS.
CVE-2017-1000221 1 Apereo 1 Opencast 2026-06-17 4.0 MEDIUM 6.5 MEDIUM
In Opencast 2.2.3 and older if user names overlap, the Opencast search service used for publication to the media modules and players will handle the access control incorrectly so that users only need to match part of the user name used for the access restriction. For example, a user with the role ROLE_USER will have access to recordings published only for ROLE_USER_X.
CVE-2017-1000220 1 Pidusage Project 1 Pidusage 2026-06-17 7.5 HIGH 9.8 CRITICAL
soyuka/pidusage <=1.1.4 is vulnerable to command injection in the module resulting in arbitrary command execution
CVE-2017-1000219 1 Windows-cpu Project 1 Windows-cpu 2026-06-17 7.5 HIGH 9.8 CRITICAL
npm/KyleRoss windows-cpu all versions vulnerable to command injection resulting in code execution as Node.js user
CVE-2017-1000218 1 Hfiref0x 1 Lightftp 2026-06-17 7.5 HIGH 9.8 CRITICAL
LightFTP version 1.1 is vulnerable to a buffer overflow in the "writelogentry" function resulting a denial of services or a remote code execution.