CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2017-16177

    Last Modified: 21 Nov 2024

    chatbyvista is a file server. chatbyvista is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

    Published: 7 Jun 2018
    7.5
    High

    CVE-2017-16185

    Last Modified: 21 Nov 2024

    uekw1511server is a static file server. uekw1511server is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

    Published: 7 Jun 2018
    7.5
    High

    CVE-2017-16193

    Last Modified: 21 Nov 2024

    mfrs is a static file server. mfrs is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

    Published: 7 Jun 2018
    7.5
    High

    CVE-2017-16201

    Last Modified: 21 Nov 2024

    zjjserver is a static file server. zjjserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

    Published: 7 Jun 2018
    7.5
    High

    CVE-2017-16204

    Last Modified: 21 Nov 2024

    The jquey module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.

    Published: 7 Jun 2018
    7.3
    High

    CVE-2017-16207

    Last Modified: 21 Nov 2024

    discordi.js is a malicious module based on the discord.js library that exfiltrates login tokens to pastebin.

    Published: 7 Jun 2018
    7.5
    High

    CVE-2017-16212

    Last Modified: 21 Nov 2024

    ltt is a static file server. ltt is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

    Published: 7 Jun 2018
    5.3
    Medium

    CVE-2017-16222

    Last Modified: 21 Nov 2024

    elding is a simple web server. elding is vulnerable to a directory traversal issue, allowing an attacker to access the filesystem by placing "../" in the url. The files accessible, however, are limited to files with a file extension. Sending a GET request to /../../../etc/passwd, for example, will return a 404 on etc/passwd/index.js.

    Published: 7 Jun 2018
    9.8
    Critical

    CVE-2017-16226

    Last Modified: 21 Nov 2024

    The static-eval module is intended to evaluate statically-analyzable expressions. In affected versions, untrusted user input is able to access the global function constructor, effectively allowing arbitrary code execution.

    Published: 7 Jun 2018
    7.5
    High

    CVE-2017-16056

    Last Modified: 21 Nov 2024

    mssql.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

    Published: 7 Jun 2018
    7.5
    High

    CVE-2017-16063

    Last Modified: 21 Nov 2024

    node-opensl was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

    Published: 7 Jun 2018
    7.5
    High

    CVE-2017-16070

    Last Modified: 21 Nov 2024

    nodecaffe was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

    Published: 7 Jun 2018
    7.5
    High

    CVE-2017-16078

    Last Modified: 21 Nov 2024

    shadowsock was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

    Published: 7 Jun 2018
    9.8
    Critical

    CVE-2017-16082

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability was found within the pg module when the remote database or query specifies a specially crafted column name. There are 2 likely scenarios in which one would likely be vulnerable. 1) Executing unsafe, user-supplied sql which contains a malicious column name. 2) Connecting to an untrusted database and executing a query which returns results where any of the column names are malicious.

    Published: 7 Jun 2018
    7.5
    High

    CVE-2017-16085

    Last Modified: 21 Nov 2024

    tinyserver2 is a webserver for static files. tinyserver2 is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.

    Published: 7 Jun 2018
    7.5
    High

    CVE-2017-16093

    Last Modified: 21 Nov 2024

    cyber-js is a simple http server. A cyberjs server is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

    Published: 7 Jun 2018
    7.5
    High

    CVE-2017-16095

    Last Modified: 21 Nov 2024

    serverliujiayi1 is a simple http server. serverliujiayi1 is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.

    Published: 7 Jun 2018
    7.5
    High

    CVE-2017-16098

    Last Modified: 21 Nov 2024

    charset 1.0.0 and below are vulnerable to regular expression denial of service. Input of around 50k characters is required for a slow down of around 2 seconds. Unless node was compiled using the -DHTTP_MAX_HEADER_SIZE= option the default header max length is 80kb, so the impact of the ReDoS is relatively low.

    Published: 7 Jun 2018
    7.5
    High

    CVE-2017-16101

    Last Modified: 21 Nov 2024

    serverwg is a simple http server. serverwg is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.

    Published: 7 Jun 2018
    7.5
    High

    CVE-2017-16108

    Last Modified: 21 Nov 2024

    gaoxiaotingtingting is an HTTP server. gaoxiaotingtingting is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

    Published: 7 Jun 2018
    7.5
    High

    CVE-2017-16206

    Last Modified: 21 Nov 2024

    The cofee-script module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.

    Published: 7 Jun 2018
    5.3
    Medium

    CVE-2017-16109

    Last Modified: 21 Nov 2024

    easyquick is a simple web server. easyquick is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. Access is constrained, however, to supported file types. Requesting a file such as /etc/passwd returns a "not supported" error.

    Published: 7 Jun 2018
    7.5
    High

    CVE-2017-16117

    Last Modified: 21 Nov 2024

    slug is a module to slugify strings, even if they contain unicode. slug is vulnerable to regular expression denial of service is specially crafted untrusted input is passed as input. About 50k characters can block the event loop for 2 seconds.

    Published: 7 Jun 2018
    7.5
    High

    CVE-2017-16125

    Last Modified: 21 Nov 2024

    rtcmulticonnection-client is a signaling implementation for RTCMultiConnection.js, a multi-session manager. rtcmulticonnection-client is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

    Published: 7 Jun 2018
    7.5
    High

    CVE-2017-16170

    Last Modified: 21 Nov 2024

    liuyaserver is a static file server. liuyaserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

    Published: 7 Jun 2018
    7.5
    High

    CVE-2017-16178

    Last Modified: 21 Nov 2024

    intsol-package is a file server. intsol-package is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

    Published: 7 Jun 2018
    7.5
    High

    CVE-2017-16186

    Last Modified: 21 Nov 2024

    360class.jansenhm is a static file server. 360class.jansenhm is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

    Published: 7 Jun 2018
    7.5
    High

    CVE-2017-16194

    Last Modified: 21 Nov 2024

    picard is a micro framework. picard is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

    Published: 7 Jun 2018
    7.5
    High

    CVE-2017-16202

    Last Modified: 21 Nov 2024

    The cofeescript module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.

    Published: 7 Jun 2018
    7.5
    High

    CVE-2017-16205

    Last Modified: 21 Nov 2024

    The coffescript module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.

    Published: 7 Jun 2018
    7.5
    High

    CVE-2018-3711

    Last Modified: 21 Nov 2024

    Fastify node module before 0.38.0 is vulnerable to a denial-of-service attack by sending a request with "Content-Type: application/json" and a very large payload.

    Published: 7 Jun 2018
    7.5
    High

    CVE-2018-3725

    Last Modified: 21 Nov 2024

    hekto node module suffers from a Path Traversal vulnerability due to lack of validation of file, which allows a malicious user to read content of any file with known path.

    Published: 7 Jun 2018
    7.5
    High

    CVE-2017-16057

    Last Modified: 21 Nov 2024

    nodemssql was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

    Published: 7 Jun 2018
    7.5
    High

    CVE-2017-16058

    Last Modified: 21 Nov 2024

    gruntcli was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

    Published: 7 Jun 2018
    7.5
    High

    CVE-2017-16059

    Last Modified: 21 Nov 2024

    mssql-node was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

    Published: 7 Jun 2018
    7.5
    High

    CVE-2017-16060

    Last Modified: 21 Nov 2024

    babelcli was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

    Published: 7 Jun 2018
    7.5
    High

    CVE-2017-16064

    Last Modified: 21 Nov 2024

    node-openssl was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

    Published: 7 Jun 2018
    7.5
    High

    CVE-2017-16065

    Last Modified: 21 Nov 2024

    openssl.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

    Published: 7 Jun 2018
    7.5
    High

    CVE-2017-16066

    Last Modified: 21 Nov 2024

    opencv.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

    Published: 7 Jun 2018
    7.5
    High

    CVE-2017-16067

    Last Modified: 21 Nov 2024

    node-opencv was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

    Published: 7 Jun 2018
    7.5
    High

    CVE-2017-16068

    Last Modified: 21 Nov 2024

    ffmepg was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

    Published: 7 Jun 2018
    7.5
    High

    CVE-2017-16069

    Last Modified: 21 Nov 2024

    nodeffmpeg was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

    Published: 7 Jun 2018
    7.5
    High

    CVE-2017-16071

    Last Modified: 21 Nov 2024

    nodemailer-js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

    Published: 7 Jun 2018
    7.5
    High

    CVE-2017-16072

    Last Modified: 21 Nov 2024

    nodemailer.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

    Published: 7 Jun 2018
    7.5
    High

    CVE-2017-16073

    Last Modified: 21 Nov 2024

    noderequest was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

    Published: 7 Jun 2018
    7.5
    High

    CVE-2017-16074

    Last Modified: 21 Nov 2024

    crossenv was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

    Published: 7 Jun 2018
    7.5
    High

    CVE-2017-16076

    Last Modified: 21 Nov 2024

    proxy.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

    Published: 7 Jun 2018
    7.5
    High

    CVE-2017-16079

    Last Modified: 21 Nov 2024

    smb was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

    Published: 7 Jun 2018
    7.5
    High

    CVE-2017-16080

    Last Modified: 21 Nov 2024

    nodesass was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

    Published: 7 Jun 2018
    7.5
    High

    CVE-2017-16081

    Last Modified: 21 Nov 2024

    cross-env.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

    Published: 7 Jun 2018