Vulnerabilities (CVE)

Total 398740 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-1000065 1 Openmediavault 1 Openmediavault 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Multiple Cross-site scripting (XSS) vulnerabilities in rpc.php in OpenMediaVault release 2.1 in Access Rights Management(Users) functionality allows attackers to inject arbitrary web scripts and execute malicious scripts within an authenticated client's browser.
CVE-2017-1000064 1 Kitto Project 1 Kitto 2026-06-17 5.0 MEDIUM 7.5 HIGH
kittoframework kitto version 0.5.1 is vulnerable to memory exhaustion in the router resulting in DoS
CVE-2017-1000063 1 Kitto Project 1 Kitto 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
kittoframework kitto version 0.5.1 is vulnerable to an XSS in the 404 page resulting in information disclosure
CVE-2017-1000062 1 Kitto Project 1 Kitto 2026-06-17 5.0 MEDIUM 7.5 HIGH
kittoframework kitto 0.5.1 is vulnerable to directory traversal in the router resulting in remote code execution
CVE-2017-1000061 1 Xmlsec Project 1 Xmlsec 2026-06-17 5.8 MEDIUM 7.1 HIGH
xmlsec 1.2.23 and before is vulnerable to XML External Entity Expansion when parsing crafted input documents, resulting in possible information disclosure or denial of service
CVE-2017-1000060 1 Eyesofnetwork 1 Eyesofnetwork 2026-06-17 10.0 HIGH 9.8 CRITICAL
EyesOfNetwork (EON) 5.1 Unauthenticated SQL Injection in eonweb leading to remote root
CVE-2017-1000059 1 Livehelperchat 1 Live Helper Chat 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Live Helper Chat version 2.06v and older is vulnerable to Cross-Site Scripting in the HTTP Header handling resulting in the execution of any user provided Javascript code in the session of other users.
CVE-2017-1000058 1 Chevereto 1 Chevereto 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Stored XSS vulnerabilities in chevereto CMS before version 3.8.11, one in the user profile and one in the Exif data parser.
CVE-2017-1000056 1 Kubernetes 1 Kubernetes 2026-06-17 7.5 HIGH 9.8 CRITICAL
Kubernetes version 1.5.0-1.5.4 is vulnerable to a privilege escalation in the PodSecurityPolicy admission plugin resulting in the ability to make use of any existing PodSecurityPolicy object.
CVE-2017-1000054 1 Rocketchat 1 Rocket.chat 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Rocket.Chat version 0.8.0 and newer is vulnerable to XSS in the markdown link parsing code for messages.
CVE-2017-1000053 1 Plug Project 1 Plug 2026-06-17 6.8 MEDIUM 8.1 HIGH
Elixir Plug before v1.0.4, v1.1.7, v1.2.3 and v1.3.2 is vulnerable to arbitrary code execution in the deserialization functions of Plug.Session.
CVE-2017-1000052 1 Plug Project 1 Plug 2026-06-17 4.6 MEDIUM 7.8 HIGH
Elixir Plug before v1.0.4, v1.1.7, v1.2.3 and v1.3.2 is vulnerable to null byte injection in the Plug.Static component, which may allow users to bypass filetype restrictions.
CVE-2017-1000051 1 Xwiki 1 Cryptpad 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in pad export in XWiki labs CryptPad before 1.1.1 allows remote attackers to inject arbitrary web script or HTML via the pad content
CVE-2017-1000050 4 Canonical, Fedoraproject, Jasper Project and 1 more 6 Ubuntu Linux, Fedora, Jasper and 3 more 2026-06-17 5.0 MEDIUM 7.5 HIGH
JasPer 2.0.12 is vulnerable to a NULL pointer exception in the function jp2_encode which failed to check to see if the image contained at least one component resulting in a denial-of-service.
CVE-2017-1000048 1 Qs Project 1 Qs 2026-06-17 5.0 MEDIUM 7.5 HIGH
the web framework using ljharb's qs module older than v6.3.2, v6.2.3, v6.1.2, and v6.0.4 is vulnerable to a DoS. A malicious user can send a evil request to cause the web framework crash.
CVE-2017-1000047 1 Rbenv Project 1 Rbenv 2026-06-17 7.5 HIGH 9.8 CRITICAL
rbenv (all current versions) is vulnerable to Directory Traversal in the specification of Ruby version resulting in arbitrary code execution
CVE-2017-1000046 1 Mautic 1 Mautic 2026-06-17 5.0 MEDIUM 7.5 HIGH
Mautic 2.6.1 and earlier fails to set flags on session cookies
CVE-2017-1000044 1 Gnome 1 Gtk-vnc 2026-06-17 7.5 HIGH 9.8 CRITICAL
gtk-vnc 0.4.2 and older doesn't check framebuffer boundaries correctly when updating framebuffer which may lead to memory corruption when rendering
CVE-2017-1000043 1 Mapbox 1 Mapbox.js 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Mapbox.js versions 1.x prior to 1.6.6 and 2.x prior to 2.2.4 are vulnerable to a cross-site-scripting attack in certain uncommon usage scenarios via TileJSON name and map share control
CVE-2017-1000042 1 Mapbox Project 1 Mapbox 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Mapbox.js versions 1.x prior to 1.6.5 and 2.x prior to 2.1.7 are vulnerable to a cross-site-scripting attack in certain uncommon usage scenarios via TileJSON Name.