2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2017-16127The module pandora-doomsday infects other modules. It's since been unpublished from the registry.
CVE-2017-16126The module botbait is a tool to be used to track bot and automated tools usage with-in the npm ecosystem. botbait is kno...
CVE-2017-16125rtcmulticonnection-client is a signaling implementation for RTCMultiConnection.js, a multi-session manager. rtcmulticonn...
CVE-2017-16124node-server-forfront is a simple static file server. node-server-forfront is vulnerable to a directory traversal issue, ...
CVE-2017-16123welcomyzt is a simple file server. welcomyzt is vulnerable to a directory traversal issue, giving an attacker access to ...
CVE-2017-16122cuciuci is a simple fileserver. cuciuci is vulnerable to a directory traversal issue, giving an attacker access to the f...
CVE-2017-16121datachannel-client is a signaling implementation for DataChannel.js. datachannel-client is vulnerable to a directory tra...
CVE-2017-16120liyujing is a static file server. liyujing is vulnerable to a directory traversal issue, giving an attacker access to th...
CVE-2017-16119Fresh is a module used by the Express.js framework for HTTP response freshness testing. It is vulnerable to a regular ex...
CVE-2017-16118The forwarded module is used by the Express.js framework to handle the X-Forwarded-For header. It is vulnerable to a reg...
CVE-2017-16117slug is a module to slugify strings, even if they contain unicode. slug is vulnerable to regular expression denial of se...
CVE-2017-16114The marked module is vulnerable to a regular expression denial of service. Based on the information published in the pub...
CVE-2017-16113The parsejson module is vulnerable to regular expression denial of service when untrusted user input is passed into it t...
CVE-2017-16111The content module is a module to parse HTTP Content-* headers. It is used by the hapijs framework to provide this funct...
CVE-2017-16110weather.swlyons is a simple web server for weather updates. weather.swlyons is vulnerable to a directory traversal issue...
CVE-2017-16109easyquick is a simple web server. easyquick is vulnerable to a directory traversal issue, giving an attacker access to t...
CVE-2017-16108gaoxiaotingtingting is an HTTP server. gaoxiaotingtingting is vulnerable to a directory traversal issue, giving an attac...
CVE-2017-16107pooledwebsocket is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing ".....
CVE-2017-16106tmock is a static file server. tmock is vulnerable to a directory traversal issue, giving an attacker access to the file...
CVE-2017-16105serverwzl is a simple http server. serverwzl is vulnerable to a directory traversal issue, giving an attacker access to ...
CVE-2017-16104citypredict.whauwiller is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by plac...
CVE-2017-16103serveryztyzt is a simple http server. serveryztyzt is vulnerable to a directory traversal issue, giving an attacker acce...
CVE-2017-16102serverhuwenhui is a simple http server. serverhuwenhui is vulnerable to a directory traversal issue, giving an attacker ...
CVE-2017-16101serverwg is a simple http server. serverwg is vulnerable to a directory traversal issue, giving an attacker access to th...
CVE-2017-16100dns-sync is a sync/blocking dns resolver. If untrusted user input is allowed into the resolve() method then command inje...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now