Known Exploited Vulnerabilities (KEV)

ID Title Severity CVSS EPSS Source Updated
cve-2017-18046 Buffer overflow on Dasan GPON ONT WiFi Router H640X 12.02-01121 2.77p1-1124 and 3.03p2-1146 devices allows remote attackers to execute arbitrary code via a long POST request to the login_action function in /cgi-bin/login_action.cgi (aka cgipage.cgi). CRITICAL 9.8 5.04% cvelistv5 2026-06-17
cve-2017-17562 Embedthis GoAhead Remote Code Execution Vulnerability HIGH N/A 96.26% cvelistv5 2021-12-10
cve-2017-17560 An issue was discovered on Western Digital MyCloud PR4100 2.30.172 devices. The web administration component, /web/jquery/uploader/multi_uploadify.php, provides multipart upload functionality that is accessible without authentication and can be used to place a file anywhere on the device's file system. This allows an attacker the ability to upload a PHP shell onto the device and obtain arbitrary code execution as root. CRITICAL 9.8 73.40% cvelistv5 2026-06-17
cve-2017-17215 Huawei HG532 with some customized versions has a remote code execution vulnerability. An authenticated attacker could send malicious packets to port 37215 to launch attacks. Successful exploit could lead to the remote execution of arbitrary code. HIGH 8.8 78.28% cvelistv5 2026-06-17
cve-2017-17106 Credentials for Zivif PR115-204-P-RS V2.3.4.2103 Webcams can be obtained by an unauthenticated remote attacker using a standard web /cgi-bin/hi3510/param.cgi?cmd=getuser HTTP request. This vulnerability exists because of a lack of authentication checks in requests to CGI pages. CRITICAL 9.8 15.26% cvelistv5 2026-06-17
cve-2017-17105 Zivif PR115-204-P-RS V2.3.4.2103 and V4.7.4.2121 (and possibly in-between versions) web cameras are vulnerable to unauthenticated, blind remote command injection via CGI scripts used as part of the web interface, as demonstrated by a cgi-bin/iptest.cgi?cmd=iptest.cgi&-time="1504225666237"&-url=$(reboot) request. CRITICAL 9.8 84.56% cvelistv5 2026-06-17
cve-2017-16959 The locale feature in cgi-bin/luci on TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allows remote authenticated users to test for the existence of arbitrary files by making an operation=write;locale=%0d request, and then making an operation=read request with a crafted Accept-Language HTTP header, related to the set_sysinfo and get_sysinfo functions in /usr/lib/lua/luci/controller/locale.lua in uhttpd. MEDIUM 6.5 1.91% cvelistv5 2026-06-17
cve-2017-16651 SUSE CVE CVE-2017-16651 HIGH 7.8 45.74% cvelistv5 2025-03-15
cve-2017-15944 Palo Alto Networks PAN-OS Remote Code Execution Vulnerability CRITICAL 9.8 98.30% cvelistv5 2022-08-18
cve-2017-15363 CVE-2017-15363 HIGH N/A 15.33% cvelistv5
cve-2017-14135 enigma2-plugins/blob/master/webadmin/src/WebChilds/Script.py in the webadmin plugin for opendreambox 2.0.0 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the command parameter to the /script URI. CRITICAL 9.8 21.84% cvelistv5 2026-06-17
cve-2017-12637 SAP NetWeaver Directory Traversal Vulnerability HIGH 7.5 95.11% cvelistv5 2025-03-19
cve-2017-12635 SUSE CVE CVE-2017-12635 UNKNOWN N/A 99.84% cvelistv5 2026-05-13
cve-2017-12617 Apache Tomcat Remote Code Execution Vulnerability HIGH N/A 99.97% cvelistv5 2022-03-25
cve-2017-12615 SUSE CVE CVE-2017-12615 HIGH 8.1 99.64% cvelistv5 2026-08-31
cve-2017-12319 Cisco IOS XE Software Ethernet Virtual Private Network Border Gateway Protocol Denial-of-Service Vulnerability HIGH N/A 5.24% cvelistv5 2022-03-03
cve-2017-12240 Cisco IOS and IOS XE Software DHCP Remote Code Execution Vulnerability HIGH N/A 13.77% cvelistv5 2022-03-03
cve-2017-12238 Cisco Catalyst 6800 Series Switches VPLS Denial-of-Service Vulnerability HIGH N/A 2.02% cvelistv5 2022-03-03
cve-2017-12237 Cisco IOS and IOS XE Software Internet Key Exchange Denial-of-Service Vulnerability HIGH N/A 7.07% cvelistv5 2022-03-03
cve-2017-12235 Cisco IOS Software for Cisco Industrial Ethernet Switches PROFINET Denial-of-Service Vulnerability HIGH N/A 7.07% cvelistv5 2022-03-03
cve-2017-12234 Cisco IOS Software Common Industrial Protocol Request Denial-of-Service Vulnerability HIGH N/A 7.07% cvelistv5 2022-03-03
cve-2017-12233 Cisco IOS Software Common Industrial Protocol Request Denial-of-Service Vulnerability HIGH N/A 7.07% cvelistv5 2022-03-03
cve-2017-12232 Cisco IOS Software for Cisco Integrated Services Routers Denial-of-Service Vulnerability HIGH N/A 2.15% cvelistv5 2022-03-03
cve-2017-12231 Cisco IOS Software Network Address Translation Denial-of-Service Vulnerability HIGH N/A 7.07% cvelistv5 2022-03-03
cve-2017-12149 Red Hat JBoss Application Server Remote Code Execution Vulnerability CRITICAL N/A 90.71% cvelistv5 2021-12-10
cve-2017-11882 Microsoft Office Memory Corruption Vulnerability HIGH 7.8 99.94% cvelistv5 2021-11-03
cve-2017-11826 Microsoft Office Remote Code Execution Vulnerability HIGH N/A 81.16% cvelistv5 2022-03-03
cve-2017-11774 Microsoft Office Outlook Security Feature Bypass Vulnerability HIGH N/A 59.63% cvelistv5 2021-11-03
cve-2017-11610 SUSE CVE CVE-2017-11610 UNKNOWN N/A 87.38% cvelistv5 2026-05-13
cve-2017-11357 Telerik UI for ASP.NET AJAX Insecure Direct Object Reference Vulnerability CRITICAL 9.8 77.68% cvelistv5 2023-01-26