Known Exploited Vulnerabilities (KEV)

ID Title Severity CVSS EPSS Source Updated
cve-2017-9805 Apache Struts Deserialization of Untrusted Data Vulnerability HIGH N/A N/A cvelistv5 2021-11-03
cve-2017-9791 Apache Struts 1 Improper Input Validation Vulnerability HIGH N/A N/A cvelistv5 2022-02-10
cve-2017-9506 The IconUriServlet of the Atlassian OAuth Plugin from version 1.3.0 before version 1.9.12 and from version 2.0.0 before version 2.0.4 allows remote attackers to access the content of internal network resources and/or perform an XSS attack via Server Side Request Forgery (SSRF). MEDIUM 6.1 N/A cvelistv5 2026-06-17
cve-2017-9248 Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability CRITICAL 9.8 N/A cvelistv5 2021-11-03
cve-2017-8961 A directory traversal vulnerability in HPE Intelligent Management Center (IMC) PLAT 7.3 E0504P02 could allow remote code execution. HIGH 8.8 N/A cvelistv5 2026-06-17
cve-2017-8759 Microsoft .NET Framework Remote Code Execution Vulnerability HIGH 7.8 N/A cvelistv5 2021-11-03
cve-2017-8570 Microsoft Office Remote Code Execution Vulnerability HIGH 7.8 N/A cvelistv5 2022-02-25
cve-2017-8543 Microsoft Windows Search Remote Code Execution Vulnerability HIGH N/A N/A cvelistv5 2022-05-24
cve-2017-8540 Microsoft Malware Protection Engine Improper Restriction of Operations Vulnerability HIGH N/A N/A cvelistv5 2022-03-03
cve-2017-8464 Microsoft Windows Shell (.lnk) Remote Code Execution Vulnerability HIGH N/A N/A cvelistv5 2022-02-10
cve-2017-8291 Artifex Ghostscript Type Confusion Vulnerability HIGH N/A N/A cvelistv5 2022-05-24
cve-2017-8226 Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices have default credentials that are hardcoded in the firmware and can be extracted by anyone who reverses the firmware to identify them. If the firmware version V2.420.AC00.16.R 9/9/2016 is dissected using binwalk tool, one obtains a _user-x.squashfs.img.extracted archive which contains the filesystem set up on the device that many of the binaries in the /usr folder. The binary "sonia" is the one that has the vulnerable function that sets up the default credentials on the device. If one opens this binary in IDA-pro, one will notice that this follows a ARM little endian format. The function sub_3DB2FC in IDA pro is identified to be setting up the values at address 0x003DB5A6. The sub_5C057C then sets this value and adds it to the Configuration files in /mnt/mtd/Config/Account1 file. CRITICAL 9.8 N/A cvelistv5 2026-06-17
cve-2017-8046 spring-boot: Malicious PATCH requests submitted to servers can use specially crafted JSON data to run arbitrary Java code CRITICAL 10.0 N/A cvelistv5 2026-08-04
cve-2017-7927 A Use of Password Hash Instead of Password for Authentication issue was discovered in Dahua DH-IPC-HDBW23A0RN-ZS, DH-IPC-HDBW13A0SN, DH-IPC-HDW1XXX, DH-IPC-HDW2XXX, DH-IPC-HDW4XXX, DH-IPC-HFW1XXX, DH-IPC-HFW2XXX, DH-IPC-HFW4XXX, DH-SD6CXX, DH-NVR1XXX, DH-HCVR4XXX, DH-HCVR5XXX, DHI-HCVR51A04HE-S3, DHI-HCVR51A08HE-S3, and DHI-HCVR58A32S-S2 devices. The use of password hash instead of password for authentication vulnerability was identified, which could allow a malicious user to bypass authentication without obtaining the actual password. HIGH 7.3 N/A cvelistv5 2026-06-17
cve-2017-7921 Hikvision Multiple Products Improper Authentication Vulnerability CRITICAL 9.8 N/A cvelistv5 2026-03-05
cve-2017-7876 CVE-2017-7876 CRITICAL 10.0 N/A cvelistv5
cve-2017-7494 Samba Remote Code Execution Vulnerability CRITICAL N/A N/A cvelistv5 2023-03-30
cve-2017-7269 Microsoft Windows Server Buffer Overflow Vulnerability CRITICAL 9.8 N/A cvelistv5 2021-11-03
cve-2017-6884 Zyxel EMG2926 Routers Command Injection Vulnerability CRITICAL N/A N/A cvelistv5 2023-09-18
cve-2017-6862 NETGEAR Multiple Devices Buffer Overflow Vulnerability HIGH N/A N/A cvelistv5 2022-06-08
cve-2017-6744 Cisco IOS Software SNMP Remote Code Execution Vulnerability HIGH N/A N/A cvelistv5 2022-03-03
cve-2017-6743 Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability HIGH N/A N/A cvelistv5 2022-03-03
cve-2017-6742 Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability HIGH 8.8 N/A cvelistv5 2023-04-19
cve-2017-6740 Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability HIGH N/A N/A cvelistv5 2022-03-03
cve-2017-6739 Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability HIGH N/A N/A cvelistv5 2022-03-03
cve-2017-6738 Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability HIGH N/A N/A cvelistv5 2022-03-03
cve-2017-6737 Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability HIGH N/A N/A cvelistv5 2022-03-03
cve-2017-6736 Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability HIGH N/A N/A cvelistv5 2022-03-03
cve-2017-6663 Cisco IOS Software and Cisco IOS XE Software Denial-of-Service Vulnerability HIGH N/A N/A cvelistv5 2022-03-03
cve-2017-6627 Cisco IOS Software and Cisco IOS XE Software UDP Packet Processing Denial-of-Service Vulnerability HIGH N/A N/A cvelistv5 2022-03-03