2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-16026Request is an http client. If a request is made using ```multipart```, and the body type is a ```number```, then the spe...
CVE-2017-16025Nes is a websocket extension library for hapi. Hapi is a webserver framework. Versions below and including 6.4.0 have a ...
CVE-2017-16024The sync-exec module is used to simulate child_process.execSync in node versions <0.11.9. Sync-exec uses tmp directories...
CVE-2017-16023Decamelize is used to convert a dash/dot/underscore/space separated string to camelCase. Decamelize 1.1.0 through 1.1.1 ...
CVE-2017-16022Morris.js creates an svg graph, with labels that appear when hovering over a point. The hovering label names are not esc...
CVE-2017-16021MEDIUM6.5uri-js is a module that tries to fully implement RFC 3986. One of these features is validating whether or not a supplied...
CVE-2017-16020CRITICAL9.8Summit is a node web framework. When using the PouchDB driver in the module, Summit 0.1.0 and later allows an attacker t...
CVE-2017-16019GitBook is a command line tool (and Node.js library) for building beautiful books using GitHub/Git and Markdown (or Asci...
CVE-2017-16018Restify is a framework for building REST APIs. Restify >=2.0.0 <=4.0.4 using URL encoded script tags in a non-existent U...
CVE-2017-16017sanitize-html is a library for scrubbing html input for malicious values Versions 1.2.2 and below have a cross site scri...
CVE-2017-16016Sanitize-html is a library for scrubbing html input of malicious values. Versions 1.11.1 and below are vulnerable to cro...
CVE-2017-16015Forms is a library for easily creating HTML forms. Versions before 1.3.0 did not have proper html escaping. This means t...
CVE-2017-16014HIGH7.5Http-proxy is a proxying library. Because of the way errors are handled in versions before 0.7.0, an attacker that force...
CVE-2017-16013hapi is a web and services application framework. When hapi >= 15.0.0 <= 16.1.0 encounters a malformed `accept-encoding`...
CVE-2017-16012Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-9251. Reason: This candidate is a duplicate of...
CVE-2017-16011Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-6708. Reason: This candidate is a duplicate of...
CVE-2017-16009MEDIUM6.1ag-grid is an advanced data grid that is library agnostic. ag-grid is vulnerable to Cross-site Scripting (XSS) via Angul...
CVE-2017-16008i18next is a language translation framework. Because of how the interpolation is implemented, making replacements from t...
CVE-2017-16007node-jose is a JavaScript implementation of the JSON Object Signing and Encryption (JOSE) for current web browsers and n...
CVE-2017-16006Remarkable is a markdown parser. In versions 1.6.2 and lower, remarkable allows the use of `data:` URIs in links and can...
CVE-2017-16005Http-signature is a "Reference implementation of Joyent's HTTP Signature Scheme". In versions <=0.9.11, http-signature s...
CVE-2017-0931MEDIUM6.1html-janitor node module suffers from a Cross-Site Scripting (XSS) vulnerability via clean() accepting user-controlled v...
CVE-2017-0930augustine node module suffers from a Path Traversal vulnerability due to lack of validation of url, which allows a malic...
CVE-2017-0928html-janitor node module suffers from an External Control of Critical State Data vulnerability via user-control of the '...
CVE-2017-1748MEDIUM6.8IBM Connections 5.0, 5.5, and 6.0 could allow a remote attacker to conduct phishing attacks, using an open redirect atta...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now