2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-12092LOW3.7An exploitable file write vulnerability exists in the memory module functionality of Allen Bradley Micrologix 1400 Serie...
CVE-2017-16055`sqlserver` was a malicious module published with the intent to hijack environment variables. It has been unpublished by...
CVE-2017-16054`nodefabric` was a malicious module published with the intent to hijack environment variables. It has been unpublished b...
CVE-2017-16053`fabric-js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by...
CVE-2017-16052`node-fabric` was a malicious module published with the intent to hijack environment variables. It has been unpublished ...
CVE-2017-16051`sqliter` was a malicious module published with the intent to hijack environment variables. It has been unpublished by n...
CVE-2017-16050`sqlite.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by...
CVE-2017-16049`nodesqlite` was a malicious module published with the intent to hijack environment variables. It has been unpublished b...
CVE-2017-16048`node-sqlite` was a malicious module published with the intent to hijack environment variables. It has been unpublished ...
CVE-2017-16046HIGH7.5`mariadb` was a malicious module published with the intent to hijack environment variables. It has been unpublished by n...
CVE-2017-16045`jquery.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by...
CVE-2017-16044`d3.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm...
CVE-2017-16043MEDIUM6.1Shout is an IRC client. Because the `/topic` command in messages is unescaped, attackers have the ability to inject HTML...
CVE-2017-16042Growl adds growl notification support to nodejs. Growl before 1.10.2 does not properly sanitize input before passing it ...
CVE-2017-16041ikst versions before 1.1.2 download resources over HTTP, which leaves it vulnerable to MITM attacks.
CVE-2017-16040gfe-sass is a library for promises (CommonJS/Promises/A,B,D) gfe-sass downloads resources over HTTP, which leaves it vul...
CVE-2017-16039`hftp` is a static http or ftp server `hftp` is vulnerable to a directory traversal issue, giving an attacker access to ...
CVE-2017-16038`f2e-server` 1.12.11 and earlier is vulnerable to a directory traversal issue, giving an attacker access to the filesyst...
CVE-2017-16037`gomeplus-h5-proxy` is vulnerable to a directory traversal issue, allowing attackers to access any file in the system by...
CVE-2017-16036`badjs-sourcemap-server` receives files sent by `badjs-sourcemap`. `badjs-sourcemap-server` is vulnerable to a directory...
CVE-2017-16035The hubl-server module is a wrapper for the HubL Development Server. During installation hubl-server downloads a set of ...
CVE-2017-16031Socket.io is a realtime application framework that provides communication via websockets. Because socket.io 0.9.6 and ea...
CVE-2017-16030Useragent is used to parse useragent headers. It uses several regular expressions to accomplish this. An attacker could ...
CVE-2017-16029hostr is a simple web server that serves up the contents of the current directory. There is a directory traversal vulner...
CVE-2017-16028react-native-meteor-oauth is a library for Oauth2 login to a Meteor server in React Native. The oauth Random Token is ge...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now