2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-16026 | — | — | 2.6% | Jun 4, 2018 | Request is an http client. If a request is made using ```multipart```, and the body type is a ```number```, then the spe... |
| CVE-2017-16025 | — | — | 1.9% | Jun 4, 2018 | Nes is a websocket extension library for hapi. Hapi is a webserver framework. Versions below and including 6.4.0 have a ... |
| CVE-2017-16024 | — | — | 2.6% | Jun 4, 2018 | The sync-exec module is used to simulate child_process.execSync in node versions <0.11.9. Sync-exec uses tmp directories... |
| CVE-2017-16023 | — | — | 1.5% | Jun 4, 2018 | Decamelize is used to convert a dash/dot/underscore/space separated string to camelCase. Decamelize 1.1.0 through 1.1.1 ... |
| CVE-2017-16022 | — | — | 0.9% | Jun 4, 2018 | Morris.js creates an svg graph, with labels that appear when hovering over a point. The hovering label names are not esc... |
| CVE-2017-16021 | MEDIUM | 6.5 | 1.3% | Jun 4, 2018 | uri-js is a module that tries to fully implement RFC 3986. One of these features is validating whether or not a supplied... |
| CVE-2017-16020 | CRITICAL | 9.8 | 2.5% | Jun 4, 2018 | Summit is a node web framework. When using the PouchDB driver in the module, Summit 0.1.0 and later allows an attacker t... |
| CVE-2017-16019 | — | — | 0.9% | Jun 4, 2018 | GitBook is a command line tool (and Node.js library) for building beautiful books using GitHub/Git and Markdown (or Asci... |
| CVE-2017-16018 | — | — | 1.0% | Jun 4, 2018 | Restify is a framework for building REST APIs. Restify >=2.0.0 <=4.0.4 using URL encoded script tags in a non-existent U... |
| CVE-2017-16017 | — | — | 1.2% | Jun 4, 2018 | sanitize-html is a library for scrubbing html input for malicious values Versions 1.2.2 and below have a cross site scri... |
| CVE-2017-16016 | — | — | 1.4% | Jun 4, 2018 | Sanitize-html is a library for scrubbing html input of malicious values. Versions 1.11.1 and below are vulnerable to cro... |
| CVE-2017-16015 | — | — | 0.8% | Jun 4, 2018 | Forms is a library for easily creating HTML forms. Versions before 1.3.0 did not have proper html escaping. This means t... |
| CVE-2017-16014 | HIGH | 7.5 | 1.7% | Jun 4, 2018 | Http-proxy is a proxying library. Because of the way errors are handled in versions before 0.7.0, an attacker that force... |
| CVE-2017-16013 | — | — | 1.6% | Jun 4, 2018 | hapi is a web and services application framework. When hapi >= 15.0.0 <= 16.1.0 encounters a malformed `accept-encoding`... |
| CVE-2017-16012 | — | — | — | Jun 4, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-9251. Reason: This candidate is a duplicate of... |
| CVE-2017-16011 | — | — | — | Jun 4, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-6708. Reason: This candidate is a duplicate of... |
| CVE-2017-16009 | MEDIUM | 6.1 | 1.2% | Jun 4, 2018 | ag-grid is an advanced data grid that is library agnostic. ag-grid is vulnerable to Cross-site Scripting (XSS) via Angul... |
| CVE-2017-16008 | — | — | 0.9% | Jun 4, 2018 | i18next is a language translation framework. Because of how the interpolation is implemented, making replacements from t... |
| CVE-2017-16007 | — | — | 0.9% | Jun 4, 2018 | node-jose is a JavaScript implementation of the JSON Object Signing and Encryption (JOSE) for current web browsers and n... |
| CVE-2017-16006 | — | — | 1.0% | Jun 4, 2018 | Remarkable is a markdown parser. In versions 1.6.2 and lower, remarkable allows the use of `data:` URIs in links and can... |
| CVE-2017-16005 | — | — | 0.9% | Jun 4, 2018 | Http-signature is a "Reference implementation of Joyent's HTTP Signature Scheme". In versions <=0.9.11, http-signature s... |
| CVE-2017-0931 | MEDIUM | 6.1 | 1.1% | Jun 4, 2018 | html-janitor node module suffers from a Cross-Site Scripting (XSS) vulnerability via clean() accepting user-controlled v... |
| CVE-2017-0930 | — | — | 1.2% | Jun 4, 2018 | augustine node module suffers from a Path Traversal vulnerability due to lack of validation of url, which allows a malic... |
| CVE-2017-0928 | — | — | 1.0% | Jun 4, 2018 | html-janitor node module suffers from an External Control of Critical State Data vulnerability via user-control of the '... |
| CVE-2017-1748 | MEDIUM | 6.8 | 0.9% | Jun 4, 2018 | IBM Connections 5.0, 5.5, and 6.0 could allow a remote attacker to conduct phishing attacks, using an open redirect atta... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now