|
cve-2017-6334
|
NETGEAR DGN2200 Devices OS Command Injection Vulnerability |
HIGH
|
N/A
|
N/A
|
cvelistv5 |
2022-03-25 |
|
cve-2017-6327
|
Symantec Messaging Gateway Remote Code Execution Vulnerability |
HIGH
|
N/A
|
N/A
|
cvelistv5 |
2021-11-03 |
|
cve-2017-6316
|
Citrix Multiple Products Remote Code Execution Vulnerability |
HIGH
|
N/A
|
N/A
|
cvelistv5 |
2022-03-25 |
|
cve-2017-6090
|
Unrestricted file upload vulnerability in clients/editclient.php in PhpCollab 2.5.1 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in logos_clients/. |
HIGH
|
8.8
|
N/A
|
cvelistv5 |
2026-06-17 |
|
cve-2017-6077
|
NETGEAR DGN2200 Remote Code Execution Vulnerability |
HIGH
|
N/A
|
N/A
|
cvelistv5 |
2022-03-07 |
|
cve-2017-5689
|
Intel Active Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability Privilege Escalation Vulnerability |
HIGH
|
N/A
|
N/A
|
cvelistv5 |
2022-01-28 |
|
cve-2017-5638
|
Apache Struts Remote Code Execution Vulnerability |
CRITICAL
|
N/A
|
N/A
|
cvelistv5 |
2021-11-03 |
|
cve-2017-5521
|
NETGEAR Multiple Devices Exposure of Sensitive Information Vulnerability |
HIGH
|
N/A
|
N/A
|
cvelistv5 |
2022-09-08 |
|
cve-2017-5173
|
CVE-2017-5173 |
HIGH
|
N/A
|
N/A
|
cvelistv5 |
|
|
cve-2017-5070
|
Google Chromium V8 Type Confusion Vulnerability |
HIGH
|
N/A
|
N/A
|
cvelistv5 |
2022-06-08 |
|
cve-2017-5030
|
Google Chromium V8 Memory Corruption Vulnerability |
HIGH
|
N/A
|
N/A
|
cvelistv5 |
2022-06-08 |
|
cve-2017-3881
|
Cisco IOS and IOS XE Remote Code Execution Vulnerability |
HIGH
|
N/A
|
N/A
|
cvelistv5 |
2022-03-25 |
|
cve-2017-3506
|
Oracle WebLogic Server OS Command Injection Vulnerability |
HIGH
|
7.4
|
N/A
|
cvelistv5 |
2024-06-03 |
|
cve-2017-3066
|
Adobe ColdFusion Deserialization Vulnerability |
CRITICAL
|
9.8
|
N/A
|
cvelistv5 |
2025-02-24 |
|
cve-2017-20149
|
The Mikrotik RouterOS web server allows memory corruption in releases before Stable 6.38.5 and Long-term 6.37.5, aka Chimay-Red. A remote and unauthenticated user can trigger the vulnerability by sending a crafted HTTP request. An attacker can use this vulnerability to execute arbitrary code on the affected system, as exploited in the wild in mid-2017 and later. |
CRITICAL
|
9.8
|
N/A
|
cvelistv5 |
2026-06-17 |
|
cve-2017-18378
|
CVE-2017-18378 |
HIGH
|
8.4
|
N/A
|
cvelistv5 |
|
|
cve-2017-18368
|
Zyxel P660HN-T1A Routers Command Injection Vulnerability |
CRITICAL
|
9.8
|
N/A
|
cvelistv5 |
2023-08-07 |
|
cve-2017-18362
|
Kaseya VSA SQL Injection Vulnerability |
CRITICAL
|
9.8
|
N/A
|
cvelistv5 |
2022-05-24 |
|
cve-2017-18349
|
parseObject in Fastjson before 1.2.25, as used in FastjsonEngine in Pippo 1.11.0 and other products, allows remote attackers to execute arbitrary code via a crafted JSON request, as demonstrated by a crafted rmi:// URI in the dataSourceName field of HTTP POST data to the Pippo /json URI, which is mishandled in AjaxApplication.java. |
CRITICAL
|
9.8
|
N/A
|
cvelistv5 |
2026-06-17 |
|
cve-2017-18046
|
Buffer overflow on Dasan GPON ONT WiFi Router H640X 12.02-01121 2.77p1-1124 and 3.03p2-1146 devices allows remote attackers to execute arbitrary code via a long POST request to the login_action function in /cgi-bin/login_action.cgi (aka cgipage.cgi). |
CRITICAL
|
9.8
|
N/A
|
cvelistv5 |
2026-06-17 |
|
cve-2017-17562
|
Embedthis GoAhead Remote Code Execution Vulnerability |
HIGH
|
N/A
|
N/A
|
cvelistv5 |
2021-12-10 |
|
cve-2017-17560
|
An issue was discovered on Western Digital MyCloud PR4100 2.30.172 devices. The web administration component, /web/jquery/uploader/multi_uploadify.php, provides multipart upload functionality that is accessible without authentication and can be used to place a file anywhere on the device's file system. This allows an attacker the ability to upload a PHP shell onto the device and obtain arbitrary code execution as root. |
CRITICAL
|
9.8
|
N/A
|
cvelistv5 |
2026-06-17 |
|
cve-2017-17215
|
Huawei HG532 with some customized versions has a remote code execution vulnerability. An authenticated attacker could send malicious packets to port 37215 to launch attacks. Successful exploit could lead to the remote execution of arbitrary code. |
HIGH
|
8.8
|
N/A
|
cvelistv5 |
2026-06-17 |
|
cve-2017-17106
|
Credentials for Zivif PR115-204-P-RS V2.3.4.2103 Webcams can be obtained by an unauthenticated remote attacker using a standard web /cgi-bin/hi3510/param.cgi?cmd=getuser HTTP request. This vulnerability exists because of a lack of authentication checks in requests to CGI pages. |
CRITICAL
|
9.8
|
N/A
|
cvelistv5 |
2026-06-17 |
|
cve-2017-17105
|
Zivif PR115-204-P-RS V2.3.4.2103 and V4.7.4.2121 (and possibly in-between versions) web cameras are vulnerable to unauthenticated, blind remote command injection via CGI scripts used as part of the web interface, as demonstrated by a cgi-bin/iptest.cgi?cmd=iptest.cgi&-time="1504225666237"&-url=$(reboot) request. |
CRITICAL
|
9.8
|
N/A
|
cvelistv5 |
2026-06-17 |
|
cve-2017-16959
|
The locale feature in cgi-bin/luci on TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allows remote authenticated users to test for the existence of arbitrary files by making an operation=write;locale=%0d request, and then making an operation=read request with a crafted Accept-Language HTTP header, related to the set_sysinfo and get_sysinfo functions in /usr/lib/lua/luci/controller/locale.lua in uhttpd. |
MEDIUM
|
6.5
|
N/A
|
cvelistv5 |
2026-06-17 |
|
cve-2017-16651
|
Roundcube Webmail File Disclosure Vulnerability |
HIGH
|
N/A
|
N/A
|
cvelistv5 |
2021-11-03 |
|
cve-2017-15944
|
Palo Alto Networks PAN-OS Remote Code Execution Vulnerability |
CRITICAL
|
9.8
|
N/A
|
cvelistv5 |
2022-08-18 |
|
cve-2017-15363
|
CVE-2017-15363 |
HIGH
|
N/A
|
N/A
|
cvelistv5 |
|
|
cve-2017-14135
|
enigma2-plugins/blob/master/webadmin/src/WebChilds/Script.py in the webadmin plugin for opendreambox 2.0.0 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the command parameter to the /script URI. |
CRITICAL
|
9.8
|
N/A
|
cvelistv5 |
2026-06-17 |