2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-16119 | — | — | 1.6% | Jun 7, 2018 | Fresh is a module used by the Express.js framework for HTTP response freshness testing. It is vulnerable to a regular ex... |
| CVE-2017-16118 | — | — | 1.9% | Jun 7, 2018 | The forwarded module is used by the Express.js framework to handle the X-Forwarded-For header. It is vulnerable to a reg... |
| CVE-2017-16117 | — | — | 1.6% | Jun 7, 2018 | slug is a module to slugify strings, even if they contain unicode. slug is vulnerable to regular expression denial of se... |
| CVE-2017-16116 | HIGH | 7.5 | 1.7% | Jun 7, 2018 | The string module is a module that provides extra string operations. The string module is vulnerable to regular expressi... |
| CVE-2017-16115 | HIGH | 7.5 | 1.5% | Jun 7, 2018 | The timespan module is vulnerable to regular expression denial of service. Given 50k characters of untrusted user input ... |
| CVE-2017-16114 | — | — | 1.8% | Jun 7, 2018 | The marked module is vulnerable to a regular expression denial of service. Based on the information published in the pub... |
| CVE-2017-16113 | — | — | 1.5% | Jun 7, 2018 | The parsejson module is vulnerable to regular expression denial of service when untrusted user input is passed into it t... |
| CVE-2017-16111 | — | — | 1.1% | Jun 7, 2018 | The content module is a module to parse HTTP Content-* headers. It is used by the hapijs framework to provide this funct... |
| CVE-2017-16110 | — | — | 2.0% | Jun 7, 2018 | weather.swlyons is a simple web server for weather updates. weather.swlyons is vulnerable to a directory traversal issue... |
| CVE-2017-16109 | — | — | 1.7% | Jun 7, 2018 | easyquick is a simple web server. easyquick is vulnerable to a directory traversal issue, giving an attacker access to t... |
| CVE-2017-16108 | — | — | 2.0% | Jun 7, 2018 | gaoxiaotingtingting is an HTTP server. gaoxiaotingtingting is vulnerable to a directory traversal issue, giving an attac... |
| CVE-2017-16107 | — | — | 2.0% | Jun 7, 2018 | pooledwebsocket is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "..... |
| CVE-2017-16106 | — | — | 2.0% | Jun 7, 2018 | tmock is a static file server. tmock is vulnerable to a directory traversal issue, giving an attacker access to the file... |
| CVE-2017-16105 | — | — | 2.0% | Jun 7, 2018 | serverwzl is a simple http server. serverwzl is vulnerable to a directory traversal issue, giving an attacker access to ... |
| CVE-2017-16104 | — | — | 2.0% | Jun 7, 2018 | citypredict.whauwiller is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by plac... |
| CVE-2017-16103 | — | — | 2.0% | Jun 7, 2018 | serveryztyzt is a simple http server. serveryztyzt is vulnerable to a directory traversal issue, giving an attacker acce... |
| CVE-2017-16102 | — | — | 2.0% | Jun 7, 2018 | serverhuwenhui is a simple http server. serverhuwenhui is vulnerable to a directory traversal issue, giving an attacker ... |
| CVE-2017-16101 | — | — | 2.0% | Jun 7, 2018 | serverwg is a simple http server. serverwg is vulnerable to a directory traversal issue, giving an attacker access to th... |
| CVE-2017-16100 | — | — | 5.1% | Jun 7, 2018 | dns-sync is a sync/blocking dns resolver. If untrusted user input is allowed into the resolve() method then command inje... |
| CVE-2017-16099 | — | — | 1.6% | Jun 7, 2018 | The no-case module is vulnerable to regular expression denial of service. When malicious untrusted user input is passed ... |
| CVE-2017-16098 | — | — | 1.7% | Jun 7, 2018 | charset 1.0.0 and below are vulnerable to regular expression denial of service. Input of around 50k characters is requir... |
| CVE-2017-16097 | — | — | 2.0% | Jun 7, 2018 | tiny-http is a simple http server. tiny-http is vulnerable to a directory traversal issue, giving an attacker access to ... |
| CVE-2017-16096 | — | — | 2.0% | Jun 7, 2018 | serveryaozeyan is a simple HTTP server. serveryaozeyan is vulnerable to a directory traversal issue, giving an attacker ... |
| CVE-2017-16095 | — | — | 2.0% | Jun 7, 2018 | serverliujiayi1 is a simple http server. serverliujiayi1 is vulnerable to a directory traversal issue, giving an attacke... |
| CVE-2017-16094 | — | — | 2.0% | Jun 7, 2018 | iter-http is a server for static files. iter-http is vulnerable to a directory traversal issue, giving an attacker acces... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now