2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-16093cyber-js is a simple http server. A cyberjs server is vulnerable to a directory traversal issue, giving an attacker acce...
CVE-2017-16092Sencisho is a simple http server for local development. Sencisho is vulnerable to a directory traversal issue, giving an...
CVE-2017-16091xtalk helps your browser talk to nodex, a simple web framework. xtalk is vulnerable to a directory traversal issue, givi...
CVE-2017-16090fsk-server is a simple http server. fsk-server is vulnerable to a directory traversal issue, giving an attacker access t...
CVE-2017-16089serverlyr is a simple http server. serverlyr is vulnerable to a directory traversal issue, giving an attacker access to ...
CVE-2017-16088The safe-eval module describes itself as a safer version of eval. By accessing the object constructors, un-sanitized use...
CVE-2017-16086ua-parser is a port of Browserscope's user agent parser. ua-parser is vulnerable to a ReDoS (Regular Expression Denial o...
CVE-2017-16085tinyserver2 is a webserver for static files. tinyserver2 is vulnerable to a directory traversal issue, giving an attacke...
CVE-2017-16084list-n-stream is a server for static files to list and stream local videos. list-n-stream v0.0.10 or lower is vulnerable...
CVE-2017-16083node-simple-router is a minimalistic router for Node. node-simple-router is vulnerable to a directory traversal issue, g...
CVE-2017-16082A remote code execution vulnerability was found within the pg module when the remote database or query specifies a speci...
CVE-2017-16081cross-env.js was a malicious module published with the intent to hijack environment variables. It has been unpublished b...
CVE-2017-16080nodesass was a malicious module published with the intent to hijack environment variables. It has been unpublished by np...
CVE-2017-16079smb was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16078shadowsock was a malicious module published with the intent to hijack environment variables. It has been unpublished by ...
CVE-2017-16077mongose was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm...
CVE-2017-16076proxy.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by np...
CVE-2017-16075http-proxy.js was a malicious module published with the intent to hijack environment variables. It has been unpublished ...
CVE-2017-16074crossenv was a malicious module published with the intent to hijack environment variables. It has been unpublished by np...
CVE-2017-16073noderequest was a malicious module published with the intent to hijack environment variables. It has been unpublished by...
CVE-2017-16072nodemailer.js was a malicious module published with the intent to hijack environment variables. It has been unpublished ...
CVE-2017-16071nodemailer-js was a malicious module published with the intent to hijack environment variables. It has been unpublished ...
CVE-2017-16070nodecaffe was a malicious module published with the intent to hijack environment variables. It has been unpublished by n...
CVE-2017-16069nodeffmpeg was a malicious module published with the intent to hijack environment variables. It has been unpublished by ...
CVE-2017-16068ffmepg was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now