2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-16025 | — | — | 1.9% | Jun 4, 2018 | Nes is a websocket extension library for hapi. Hapi is a webserver framework. Versions below and including 6.4.0 have a ... |
| CVE-2017-16024 | — | — | 2.6% | Jun 4, 2018 | The sync-exec module is used to simulate child_process.execSync in node versions <0.11.9. Sync-exec uses tmp directories... |
| CVE-2017-16023 | — | — | 1.5% | Jun 4, 2018 | Decamelize is used to convert a dash/dot/underscore/space separated string to camelCase. Decamelize 1.1.0 through 1.1.1 ... |
| CVE-2017-16022 | — | — | 0.9% | Jun 4, 2018 | Morris.js creates an svg graph, with labels that appear when hovering over a point. The hovering label names are not esc... |
| CVE-2017-16019 | — | — | 0.9% | Jun 4, 2018 | GitBook is a command line tool (and Node.js library) for building beautiful books using GitHub/Git and Markdown (or Asci... |
| CVE-2017-16018 | — | — | 1.0% | Jun 4, 2018 | Restify is a framework for building REST APIs. Restify >=2.0.0 <=4.0.4 using URL encoded script tags in a non-existent U... |
| CVE-2017-16017 | — | — | 1.2% | Jun 4, 2018 | sanitize-html is a library for scrubbing html input for malicious values Versions 1.2.2 and below have a cross site scri... |
| CVE-2017-16016 | — | — | 1.4% | Jun 4, 2018 | Sanitize-html is a library for scrubbing html input of malicious values. Versions 1.11.1 and below are vulnerable to cro... |
| CVE-2017-16015 | — | — | 0.8% | Jun 4, 2018 | Forms is a library for easily creating HTML forms. Versions before 1.3.0 did not have proper html escaping. This means t... |
| CVE-2017-16013 | — | — | 1.6% | Jun 4, 2018 | hapi is a web and services application framework. When hapi >= 15.0.0 <= 16.1.0 encounters a malformed `accept-encoding`... |
| CVE-2017-16012 | — | — | — | Jun 4, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-9251. Reason: This candidate is a duplicate of... |
| CVE-2017-16011 | — | — | — | Jun 4, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-6708. Reason: This candidate is a duplicate of... |
| CVE-2017-16008 | — | — | 0.9% | Jun 4, 2018 | i18next is a language translation framework. Because of how the interpolation is implemented, making replacements from t... |
| CVE-2017-16007 | — | — | 0.9% | Jun 4, 2018 | node-jose is a JavaScript implementation of the JSON Object Signing and Encryption (JOSE) for current web browsers and n... |
| CVE-2017-16006 | — | — | 1.0% | Jun 4, 2018 | Remarkable is a markdown parser. In versions 1.6.2 and lower, remarkable allows the use of `data:` URIs in links and can... |
| CVE-2017-16005 | — | — | 0.9% | Jun 4, 2018 | Http-signature is a "Reference implementation of Joyent's HTTP Signature Scheme". In versions <=0.9.11, http-signature s... |
| CVE-2017-0930 | — | — | 1.2% | Jun 4, 2018 | augustine node module suffers from a Path Traversal vulnerability due to lack of validation of url, which allows a malic... |
| CVE-2017-0928 | — | — | 1.0% | Jun 4, 2018 | html-janitor node module suffers from an External Control of Critical State Data vulnerability via user-control of the '... |
| CVE-2017-18285 | — | — | 0.3% | Jun 4, 2018 | The Gentoo app-backup/burp package before 2.1.32 has incorrect group ownership of the /etc/burp directory, which might a... |
| CVE-2017-18284 | — | — | 0.3% | Jun 4, 2018 | The Gentoo app-backup/burp package before 2.1.32 sets the ownership of the PID file directory to the burp account, which... |
| CVE-2017-6153 | — | — | 1.7% | Jun 1, 2018 | Features in F5 BIG-IP 13.0.0-13.1.0.3, 12.1.0-12.1.3.1, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1 system that utilizes i... |
| CVE-2017-17171 | — | — | 0.5% | Jun 1, 2018 | Some Huawei smart phones have the denial of service (DoS) vulnerability due to the improper processing of malicious para... |
| CVE-2017-16153 | — | — | 1.8% | May 29, 2018 | gaoxuyan is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in t... |
| CVE-2017-16061 | — | — | 1.1% | May 29, 2018 | tkinter was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm... |
| CVE-2017-16047 | — | — | 1.3% | May 29, 2018 | mysqljs was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now