2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2016-10585libxl provides Node bindings for the libxl library for reading and writing excel (XLS and XLSX) spreadsheets. libxl down...
CVE-2016-10582closurecompiler is a Closure Compiler for node.js. closurecompiler downloads binary resources over HTTP, which leaves it...
CVE-2016-10581Steroids is PhoneGap on Steroids, providing native UI elements, multiple WebViews and enhancements for better developer ...
CVE-2016-10580nodewebkit is an installer for node-webkit. nodewebkit downloads zipped resources over HTTP, which leaves it vulnerable ...
CVE-2016-10579Chromedriver is an NPM wrapper for selenium ChromeDriver. Chromedriver before 2.26.1 downloads binary resources over HTT...
CVE-2016-10576Fuseki server wrapper and management API in fuseki before 1.0.1 downloads binary resources over HTTP, which leaves it vu...
CVE-2016-10575Kindlegen is a simple Node.js wrapper of the official kindlegen program. Kindlegen versions before 1.1.0 download binary...
CVE-2016-10574apk-parser3 is a module to extract Android Manifest info from an APK file. apk-parser3 versions before 0.1.3 download bi...
CVE-2016-10572mongodb-instance before 0.0.3 installs mongodb locally. mongodb-instance downloads binary resources over HTTP, which lea...
CVE-2016-10571bkjs-wand is imagemagick wand support for node.js and backendjs bkjs-wand versions lower than 0.3.2 download binary reso...
CVE-2016-10569embedza is a module to create HTML snippets/embeds from URLs using info from oEmbed, Open Graph, meta tags. embedza vers...
CVE-2016-10565operadriver is a Opera Driver for Selenium. operadriver versions below 0.2.3 download binary resources over HTTP, which ...
CVE-2016-10564apk-parser is a tool to extract Android Manifest info from an APK file. apk-parser versions below 0.1.6 download binary ...
CVE-2016-10563During the installation process, the go-ipfs-deps module before 0.4.4 insecurely downloads resources over HTTP. This all...
CVE-2016-10562iedriver is an NPM wrapper for Selenium IEDriver. iedriver versions below 3.0.0 download binary resources over HTTP, whi...
CVE-2016-10561Bitty is a development web server tool that functions similar to `python -m SimpleHTTPServer`. Version 0.2.10 has a dire...
CVE-2016-10557appium-chromedriver is a Node.js wrapper around Chromedriver. Versions below 2.9.4 download binary resources over HTTP, ...
CVE-2016-10555Since "algorithm" isn't enforced in jwt.decode()in jwt-simple 0.3.0 and earlier, a malicious user could choose what algo...
CVE-2016-10554sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Mi...
CVE-2016-10553sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Mi...
CVE-2016-10552igniteui 0.0.5 and earlier downloads JavaScript and CSS resources over insecure protocol.
CVE-2016-10550sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Mi...
CVE-2016-10549Sails is an MVC style framework for building realtime web applications. Version 0.12.7 and lower have an issue with the ...
CVE-2016-10548Arbitrary code execution is possible in reduce-css-calc node module <=1.2.4 through crafted css. This makes cross sites ...
CVE-2016-10547Nunjucks is a full featured templating engine for JavaScript. Versions 2.4.2 and lower have a cross site scripting (XSS)...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now