2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2017-16025Nes is a websocket extension library for hapi. Hapi is a webserver framework. Versions below and including 6.4.0 have a ...
CVE-2017-16024The sync-exec module is used to simulate child_process.execSync in node versions <0.11.9. Sync-exec uses tmp directories...
CVE-2017-16023Decamelize is used to convert a dash/dot/underscore/space separated string to camelCase. Decamelize 1.1.0 through 1.1.1 ...
CVE-2017-16022Morris.js creates an svg graph, with labels that appear when hovering over a point. The hovering label names are not esc...
CVE-2017-16019GitBook is a command line tool (and Node.js library) for building beautiful books using GitHub/Git and Markdown (or Asci...
CVE-2017-16018Restify is a framework for building REST APIs. Restify >=2.0.0 <=4.0.4 using URL encoded script tags in a non-existent U...
CVE-2017-16017sanitize-html is a library for scrubbing html input for malicious values Versions 1.2.2 and below have a cross site scri...
CVE-2017-16016Sanitize-html is a library for scrubbing html input of malicious values. Versions 1.11.1 and below are vulnerable to cro...
CVE-2017-16015Forms is a library for easily creating HTML forms. Versions before 1.3.0 did not have proper html escaping. This means t...
CVE-2017-16013hapi is a web and services application framework. When hapi >= 15.0.0 <= 16.1.0 encounters a malformed `accept-encoding`...
CVE-2017-16012Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-9251. Reason: This candidate is a duplicate of...
CVE-2017-16011Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-6708. Reason: This candidate is a duplicate of...
CVE-2017-16008i18next is a language translation framework. Because of how the interpolation is implemented, making replacements from t...
CVE-2017-16007node-jose is a JavaScript implementation of the JSON Object Signing and Encryption (JOSE) for current web browsers and n...
CVE-2017-16006Remarkable is a markdown parser. In versions 1.6.2 and lower, remarkable allows the use of `data:` URIs in links and can...
CVE-2017-16005Http-signature is a "Reference implementation of Joyent's HTTP Signature Scheme". In versions <=0.9.11, http-signature s...
CVE-2017-0930augustine node module suffers from a Path Traversal vulnerability due to lack of validation of url, which allows a malic...
CVE-2017-0928html-janitor node module suffers from an External Control of Critical State Data vulnerability via user-control of the '...
CVE-2017-18285The Gentoo app-backup/burp package before 2.1.32 has incorrect group ownership of the /etc/burp directory, which might a...
CVE-2017-18284The Gentoo app-backup/burp package before 2.1.32 sets the ownership of the PID file directory to the burp account, which...
CVE-2017-6153Features in F5 BIG-IP 13.0.0-13.1.0.3, 12.1.0-12.1.3.1, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1 system that utilizes i...
CVE-2017-17171Some Huawei smart phones have the denial of service (DoS) vulnerability due to the improper processing of malicious para...
CVE-2017-16153gaoxuyan is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in t...
CVE-2017-16061tkinter was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm...
CVE-2017-16047mysqljs was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now