2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-16127 | — | — | 1.5% | Jun 7, 2018 | The module pandora-doomsday infects other modules. It's since been unpublished from the registry. |
| CVE-2017-16126 | — | — | 0.9% | Jun 7, 2018 | The module botbait is a tool to be used to track bot and automated tools usage with-in the npm ecosystem. botbait is kno... |
| CVE-2017-16125 | — | — | 2.0% | Jun 7, 2018 | rtcmulticonnection-client is a signaling implementation for RTCMultiConnection.js, a multi-session manager. rtcmulticonn... |
| CVE-2017-16124 | — | — | 2.0% | Jun 7, 2018 | node-server-forfront is a simple static file server. node-server-forfront is vulnerable to a directory traversal issue, ... |
| CVE-2017-16123 | — | — | 2.0% | Jun 7, 2018 | welcomyzt is a simple file server. welcomyzt is vulnerable to a directory traversal issue, giving an attacker access to ... |
| CVE-2017-16122 | — | — | 2.0% | Jun 7, 2018 | cuciuci is a simple fileserver. cuciuci is vulnerable to a directory traversal issue, giving an attacker access to the f... |
| CVE-2017-16121 | — | — | 2.0% | Jun 7, 2018 | datachannel-client is a signaling implementation for DataChannel.js. datachannel-client is vulnerable to a directory tra... |
| CVE-2017-16120 | — | — | 2.0% | Jun 7, 2018 | liyujing is a static file server. liyujing is vulnerable to a directory traversal issue, giving an attacker access to th... |
| CVE-2017-16119 | — | — | 1.6% | Jun 7, 2018 | Fresh is a module used by the Express.js framework for HTTP response freshness testing. It is vulnerable to a regular ex... |
| CVE-2017-16118 | — | — | 1.9% | Jun 7, 2018 | The forwarded module is used by the Express.js framework to handle the X-Forwarded-For header. It is vulnerable to a reg... |
| CVE-2017-16117 | — | — | 1.6% | Jun 7, 2018 | slug is a module to slugify strings, even if they contain unicode. slug is vulnerable to regular expression denial of se... |
| CVE-2017-16114 | — | — | 1.8% | Jun 7, 2018 | The marked module is vulnerable to a regular expression denial of service. Based on the information published in the pub... |
| CVE-2017-16113 | — | — | 1.5% | Jun 7, 2018 | The parsejson module is vulnerable to regular expression denial of service when untrusted user input is passed into it t... |
| CVE-2017-16111 | — | — | 1.1% | Jun 7, 2018 | The content module is a module to parse HTTP Content-* headers. It is used by the hapijs framework to provide this funct... |
| CVE-2017-16110 | — | — | 2.0% | Jun 7, 2018 | weather.swlyons is a simple web server for weather updates. weather.swlyons is vulnerable to a directory traversal issue... |
| CVE-2017-16109 | — | — | 1.7% | Jun 7, 2018 | easyquick is a simple web server. easyquick is vulnerable to a directory traversal issue, giving an attacker access to t... |
| CVE-2017-16108 | — | — | 2.0% | Jun 7, 2018 | gaoxiaotingtingting is an HTTP server. gaoxiaotingtingting is vulnerable to a directory traversal issue, giving an attac... |
| CVE-2017-16107 | — | — | 2.0% | Jun 7, 2018 | pooledwebsocket is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "..... |
| CVE-2017-16106 | — | — | 2.0% | Jun 7, 2018 | tmock is a static file server. tmock is vulnerable to a directory traversal issue, giving an attacker access to the file... |
| CVE-2017-16105 | — | — | 2.0% | Jun 7, 2018 | serverwzl is a simple http server. serverwzl is vulnerable to a directory traversal issue, giving an attacker access to ... |
| CVE-2017-16104 | — | — | 2.0% | Jun 7, 2018 | citypredict.whauwiller is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by plac... |
| CVE-2017-16103 | — | — | 2.0% | Jun 7, 2018 | serveryztyzt is a simple http server. serveryztyzt is vulnerable to a directory traversal issue, giving an attacker acce... |
| CVE-2017-16102 | — | — | 2.0% | Jun 7, 2018 | serverhuwenhui is a simple http server. serverhuwenhui is vulnerable to a directory traversal issue, giving an attacker ... |
| CVE-2017-16101 | — | — | 2.0% | Jun 7, 2018 | serverwg is a simple http server. serverwg is vulnerable to a directory traversal issue, giving an attacker access to th... |
| CVE-2017-16100 | — | — | 5.1% | Jun 7, 2018 | dns-sync is a sync/blocking dns resolver. If untrusted user input is allowed into the resolve() method then command inje... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now