2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-10585 | — | — | 1.8% | Jun 1, 2018 | libxl provides Node bindings for the libxl library for reading and writing excel (XLS and XLSX) spreadsheets. libxl down... |
| CVE-2016-10582 | — | — | 1.7% | Jun 1, 2018 | closurecompiler is a Closure Compiler for node.js. closurecompiler downloads binary resources over HTTP, which leaves it... |
| CVE-2016-10581 | — | — | 1.7% | Jun 1, 2018 | Steroids is PhoneGap on Steroids, providing native UI elements, multiple WebViews and enhancements for better developer ... |
| CVE-2016-10580 | — | — | 1.7% | Jun 1, 2018 | nodewebkit is an installer for node-webkit. nodewebkit downloads zipped resources over HTTP, which leaves it vulnerable ... |
| CVE-2016-10579 | — | — | 1.1% | Jun 1, 2018 | Chromedriver is an NPM wrapper for selenium ChromeDriver. Chromedriver before 2.26.1 downloads binary resources over HTT... |
| CVE-2016-10576 | — | — | 1.7% | Jun 1, 2018 | Fuseki server wrapper and management API in fuseki before 1.0.1 downloads binary resources over HTTP, which leaves it vu... |
| CVE-2016-10575 | — | — | 1.8% | Jun 1, 2018 | Kindlegen is a simple Node.js wrapper of the official kindlegen program. Kindlegen versions before 1.1.0 download binary... |
| CVE-2016-10574 | — | — | 1.8% | Jun 1, 2018 | apk-parser3 is a module to extract Android Manifest info from an APK file. apk-parser3 versions before 0.1.3 download bi... |
| CVE-2016-10572 | — | — | 1.7% | May 31, 2018 | mongodb-instance before 0.0.3 installs mongodb locally. mongodb-instance downloads binary resources over HTTP, which lea... |
| CVE-2016-10571 | — | — | 1.7% | May 31, 2018 | bkjs-wand is imagemagick wand support for node.js and backendjs bkjs-wand versions lower than 0.3.2 download binary reso... |
| CVE-2016-10569 | — | — | 1.8% | May 31, 2018 | embedza is a module to create HTML snippets/embeds from URLs using info from oEmbed, Open Graph, meta tags. embedza vers... |
| CVE-2016-10565 | — | — | 1.1% | May 31, 2018 | operadriver is a Opera Driver for Selenium. operadriver versions below 0.2.3 download binary resources over HTTP, which ... |
| CVE-2016-10564 | — | — | 1.1% | May 31, 2018 | apk-parser is a tool to extract Android Manifest info from an APK file. apk-parser versions below 0.1.6 download binary ... |
| CVE-2016-10563 | — | — | 0.8% | May 31, 2018 | During the installation process, the go-ipfs-deps module before 0.4.4 insecurely downloads resources over HTTP. This all... |
| CVE-2016-10562 | — | — | 1.7% | May 31, 2018 | iedriver is an NPM wrapper for Selenium IEDriver. iedriver versions below 3.0.0 download binary resources over HTTP, whi... |
| CVE-2016-10561 | — | — | 1.5% | May 31, 2018 | Bitty is a development web server tool that functions similar to `python -m SimpleHTTPServer`. Version 0.2.10 has a dire... |
| CVE-2016-10557 | — | — | 1.1% | May 31, 2018 | appium-chromedriver is a Node.js wrapper around Chromedriver. Versions below 2.9.4 download binary resources over HTTP, ... |
| CVE-2016-10555 | — | — | 4.9% | May 31, 2018 | Since "algorithm" isn't enforced in jwt.decode()in jwt-simple 0.3.0 and earlier, a malicious user could choose what algo... |
| CVE-2016-10554 | — | — | 1.9% | May 31, 2018 | sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Mi... |
| CVE-2016-10553 | — | — | 1.3% | May 31, 2018 | sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Mi... |
| CVE-2016-10552 | — | — | 0.5% | May 31, 2018 | igniteui 0.0.5 and earlier downloads JavaScript and CSS resources over insecure protocol. |
| CVE-2016-10550 | — | — | 1.9% | May 31, 2018 | sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Mi... |
| CVE-2016-10549 | — | — | 0.6% | May 31, 2018 | Sails is an MVC style framework for building realtime web applications. Version 0.12.7 and lower have an issue with the ... |
| CVE-2016-10548 | — | — | 1.2% | May 31, 2018 | Arbitrary code execution is possible in reduce-css-calc node module <=1.2.4 through crafted css. This makes cross sites ... |
| CVE-2016-10547 | — | — | 1.4% | May 31, 2018 | Nunjucks is a full featured templating engine for JavaScript. Versions 2.4.2 and lower have a cross site scripting (XSS)... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now