2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-16119Fresh is a module used by the Express.js framework for HTTP response freshness testing. It is vulnerable to a regular ex...
CVE-2017-16118The forwarded module is used by the Express.js framework to handle the X-Forwarded-For header. It is vulnerable to a reg...
CVE-2017-16117slug is a module to slugify strings, even if they contain unicode. slug is vulnerable to regular expression denial of se...
CVE-2017-16116HIGH7.5The string module is a module that provides extra string operations. The string module is vulnerable to regular expressi...
CVE-2017-16115HIGH7.5The timespan module is vulnerable to regular expression denial of service. Given 50k characters of untrusted user input ...
CVE-2017-16114The marked module is vulnerable to a regular expression denial of service. Based on the information published in the pub...
CVE-2017-16113The parsejson module is vulnerable to regular expression denial of service when untrusted user input is passed into it t...
CVE-2017-16111The content module is a module to parse HTTP Content-* headers. It is used by the hapijs framework to provide this funct...
CVE-2017-16110weather.swlyons is a simple web server for weather updates. weather.swlyons is vulnerable to a directory traversal issue...
CVE-2017-16109easyquick is a simple web server. easyquick is vulnerable to a directory traversal issue, giving an attacker access to t...
CVE-2017-16108gaoxiaotingtingting is an HTTP server. gaoxiaotingtingting is vulnerable to a directory traversal issue, giving an attac...
CVE-2017-16107pooledwebsocket is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing ".....
CVE-2017-16106tmock is a static file server. tmock is vulnerable to a directory traversal issue, giving an attacker access to the file...
CVE-2017-16105serverwzl is a simple http server. serverwzl is vulnerable to a directory traversal issue, giving an attacker access to ...
CVE-2017-16104citypredict.whauwiller is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by plac...
CVE-2017-16103serveryztyzt is a simple http server. serveryztyzt is vulnerable to a directory traversal issue, giving an attacker acce...
CVE-2017-16102serverhuwenhui is a simple http server. serverhuwenhui is vulnerable to a directory traversal issue, giving an attacker ...
CVE-2017-16101serverwg is a simple http server. serverwg is vulnerable to a directory traversal issue, giving an attacker access to th...
CVE-2017-16100dns-sync is a sync/blocking dns resolver. If untrusted user input is allowed into the resolve() method then command inje...
CVE-2017-16099The no-case module is vulnerable to regular expression denial of service. When malicious untrusted user input is passed ...
CVE-2017-16098charset 1.0.0 and below are vulnerable to regular expression denial of service. Input of around 50k characters is requir...
CVE-2017-16097tiny-http is a simple http server. tiny-http is vulnerable to a directory traversal issue, giving an attacker access to ...
CVE-2017-16096serveryaozeyan is a simple HTTP server. serveryaozeyan is vulnerable to a directory traversal issue, giving an attacker ...
CVE-2017-16095serverliujiayi1 is a simple http server. serverliujiayi1 is vulnerable to a directory traversal issue, giving an attacke...
CVE-2017-16094iter-http is a server for static files. iter-http is vulnerable to a directory traversal issue, giving an attacker acces...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now