Vulnerabilities (CVE)

Total 398770 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-1000193 1 Octobercms 1 October 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
October CMS build 412 is vulnerable to stored WCI (a.k.a XSS) in brand logo image name resulting in JavaScript code execution in the victim's browser.
CVE-2017-1000192 1 Cygnux 1 Syspass 2026-06-17 5.0 MEDIUM 9.8 CRITICAL
Cygnux sysPass version 2.1.7 and older is vulnerable to a Local File Inclusion in the functionality of javascript files inclusion. The attacker can read the configuration files that contain the login and password from the database, private encryption key, as well as other sensitive information.
CVE-2017-1000191 1 Jool 1 Jool 2026-06-17 7.8 HIGH 7.5 HIGH
Jool 3.5.0-3.5.1 is vulnerable to a kernel crashing packet resulting in a DOS.
CVE-2017-1000190 2 Apache, Simplexml Project 2 Solr, Simplexml 2026-06-17 6.4 MEDIUM 9.1 CRITICAL
SimpleXML (latest version 2.7.1) is vulnerable to an XXE vulnerability resulting SSRF, information disclosure, DoS and so on.
CVE-2017-1000189 1 Ejs 1 Ejs 2026-06-17 5.0 MEDIUM 7.5 HIGH
nodejs ejs version older than 2.5.5 is vulnerable to a denial-of-service due to weak input validation in the ejs.renderFile()
CVE-2017-1000188 1 Ejs 1 Ejs 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
nodejs ejs version older than 2.5.5 is vulnerable to a Cross-site-scripting in the ejs.renderFile() resulting in code injection
CVE-2017-1000187 1 Swftools 1 Swftools 2026-06-17 4.3 MEDIUM 7.8 HIGH
In SWFTools, an address access exception was found in pdf2swf. FoFiTrueType::writeTTF()
CVE-2017-1000186 1 Swftools 1 Swftools 2026-06-17 4.3 MEDIUM 5.5 MEDIUM
In SWFTools, a stack overflow was found in pdf2swf.
CVE-2017-1000185 1 Swftools 1 Swftools 2026-06-17 4.3 MEDIUM 5.5 MEDIUM
In SWFTools, a memcpy buffer overflow was found in gif2swf.
CVE-2017-1000182 1 Swftools 1 Swftools 2026-06-17 4.3 MEDIUM 5.5 MEDIUM
In SWFTools, a memory leak was found in wav2swf.
CVE-2017-1000176 1 Swftools 1 Swftools 2026-06-17 4.3 MEDIUM 5.5 MEDIUM
In SWFTools, a memcpy buffer overflow was found in swfc.
CVE-2017-1000174 1 Swftools 1 Swftools 2026-06-17 4.3 MEDIUM 5.5 MEDIUM
In SWFTools, an address access exception was found in swfdump swf_GetBits().
CVE-2017-1000173 1 Creolabs 1 Gravity 2026-06-17 7.5 HIGH 9.8 CRITICAL
Creolabs Gravity Version: 1.0 Heap Overflow Potential Code Execution. By creating a large loop whiling pushing data to a buffer, we can break out of the bounds checking of that buffer. When list.join is called on the data it will read past a buffer resulting in a Heap-Buffer-Overflow.
CVE-2017-1000172 1 Creolabs 1 Gravity 2026-06-17 7.5 HIGH 9.8 CRITICAL
Creolabs Gravity Version: 1.0 Use-After-Free Possible code execution. An example of a Heap-Use-After-Free after the 'sublexer' pointer has been freed. Line 542 of gravity_lexer.c. 'lexer' is being used to access a variable but 'lexer' has already been freed, creating a Heap Use-After-Free condition.
CVE-2017-1000171 1 Mahara 1 Mahara Mobile 2026-06-17 5.0 MEDIUM 9.8 CRITICAL
Mahara Mobile before 1.2.1 is vulnerable to passwords being sent to the Mahara access log in plain text.
CVE-2017-1000170 1 Jqueryfiletree Project 1 Jqueryfiletree 2026-06-17 5.0 MEDIUM 7.5 HIGH
jqueryFileTree 2.1.5 and older Directory Traversal
CVE-2017-1000169 1 Quickerbb Project 1 Quickerbb 2026-06-17 10.0 HIGH 9.8 CRITICAL
QuickerBB version <= 0.7.2 is vulnerable to arbitrary file writes which can lead to remote code execution. This can lead to the complete takeover of the server hosting QuickerBB.
CVE-2017-1000168 1 Sodiumoxide Project 1 Sodiumoxide 2026-06-17 4.3 MEDIUM 6.5 MEDIUM
sodiumoxide 0.0.13 and older scalarmult() vulnerable to degenerate public keys
CVE-2017-1000164 1 Tine20 1 Tine 2.0 2026-06-17 3.5 LOW 5.4 MEDIUM
Tine 2.0 version 2017.02.4 is vulnerable to XSS in the Addressbook resulting code execution and privilege escalation
CVE-2017-1000163 1 Phoenixframework 1 Phoenix 2026-06-17 5.8 MEDIUM 6.1 MEDIUM
The Phoenix Framework versions 1.0.0 through 1.0.4, 1.1.0 through 1.1.6, 1.2.0, 1.2.2 and 1.3.0-rc.0 are vulnerable to unvalidated URL redirection, which may result in phishing or social engineering attacks.