2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-7653 | — | — | 1.5% | Jun 5, 2018 | The Eclipse Mosquitto broker up to version 1.4.15 does not reject strings that are not valid UTF-8. A malicious client c... |
| CVE-2017-18286 | — | — | 0.7% | Jun 5, 2018 | nZEDb v0.7.3.3 has XSS in the 404 error page. |
| CVE-2017-16055 | — | — | 1.1% | Jun 4, 2018 | `sqlserver` was a malicious module published with the intent to hijack environment variables. It has been unpublished by... |
| CVE-2017-16054 | — | — | 1.2% | Jun 4, 2018 | `nodefabric` was a malicious module published with the intent to hijack environment variables. It has been unpublished b... |
| CVE-2017-16053 | — | — | 1.1% | Jun 4, 2018 | `fabric-js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by... |
| CVE-2017-16052 | — | — | 1.2% | Jun 4, 2018 | `node-fabric` was a malicious module published with the intent to hijack environment variables. It has been unpublished ... |
| CVE-2017-16051 | — | — | 1.3% | Jun 4, 2018 | `sqliter` was a malicious module published with the intent to hijack environment variables. It has been unpublished by n... |
| CVE-2017-16050 | — | — | 1.1% | Jun 4, 2018 | `sqlite.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by... |
| CVE-2017-16049 | — | — | 1.2% | Jun 4, 2018 | `nodesqlite` was a malicious module published with the intent to hijack environment variables. It has been unpublished b... |
| CVE-2017-16048 | — | — | 1.2% | Jun 4, 2018 | `node-sqlite` was a malicious module published with the intent to hijack environment variables. It has been unpublished ... |
| CVE-2017-16045 | — | — | 1.1% | Jun 4, 2018 | `jquery.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by... |
| CVE-2017-16044 | — | — | 1.5% | Jun 4, 2018 | `d3.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm... |
| CVE-2017-16042 | — | — | 4.4% | Jun 4, 2018 | Growl adds growl notification support to nodejs. Growl before 1.10.2 does not properly sanitize input before passing it ... |
| CVE-2017-16041 | — | — | 0.7% | Jun 4, 2018 | ikst versions before 1.1.2 download resources over HTTP, which leaves it vulnerable to MITM attacks. |
| CVE-2017-16040 | — | — | 1.7% | Jun 4, 2018 | gfe-sass is a library for promises (CommonJS/Promises/A,B,D) gfe-sass downloads resources over HTTP, which leaves it vul... |
| CVE-2017-16039 | — | — | 2.0% | Jun 4, 2018 | `hftp` is a static http or ftp server `hftp` is vulnerable to a directory traversal issue, giving an attacker access to ... |
| CVE-2017-16038 | — | — | 2.5% | Jun 4, 2018 | `f2e-server` 1.12.11 and earlier is vulnerable to a directory traversal issue, giving an attacker access to the filesyst... |
| CVE-2017-16037 | — | — | 2.0% | Jun 4, 2018 | `gomeplus-h5-proxy` is vulnerable to a directory traversal issue, allowing attackers to access any file in the system by... |
| CVE-2017-16036 | — | — | 2.0% | Jun 4, 2018 | `badjs-sourcemap-server` receives files sent by `badjs-sourcemap`. `badjs-sourcemap-server` is vulnerable to a directory... |
| CVE-2017-16035 | — | — | 0.7% | Jun 4, 2018 | The hubl-server module is a wrapper for the HubL Development Server. During installation hubl-server downloads a set of ... |
| CVE-2017-16031 | — | — | 2.0% | Jun 4, 2018 | Socket.io is a realtime application framework that provides communication via websockets. Because socket.io 0.9.6 and ea... |
| CVE-2017-16030 | — | — | 1.2% | Jun 4, 2018 | Useragent is used to parse useragent headers. It uses several regular expressions to accomplish this. An attacker could ... |
| CVE-2017-16029 | — | — | 1.8% | Jun 4, 2018 | hostr is a simple web server that serves up the contents of the current directory. There is a directory traversal vulner... |
| CVE-2017-16028 | — | — | 1.4% | Jun 4, 2018 | react-native-meteor-oauth is a library for Oauth2 login to a Meteor server in React Native. The oauth Random Token is ge... |
| CVE-2017-16026 | — | — | 2.6% | Jun 4, 2018 | Request is an http client. If a request is made using ```multipart```, and the body type is a ```number```, then the spe... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now