2016 CVE Vulnerabilities

10,648 CVEs published in 2016.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2016-10585——libxl provides Node bindings for the libxl library for reading and writing excel (XLS and XLSX) spreadsheets. libxl down...
CVE-2016-10582——closurecompiler is a Closure Compiler for node.js. closurecompiler downloads binary resources over HTTP, which leaves it...
CVE-2016-10581——Steroids is PhoneGap on Steroids, providing native UI elements, multiple WebViews and enhancements for better developer ...
CVE-2016-10580——nodewebkit is an installer for node-webkit. nodewebkit downloads zipped resources over HTTP, which leaves it vulnerable ...
CVE-2016-10579——Chromedriver is an NPM wrapper for selenium ChromeDriver. Chromedriver before 2.26.1 downloads binary resources over HTT...
CVE-2016-10576——Fuseki server wrapper and management API in fuseki before 1.0.1 downloads binary resources over HTTP, which leaves it vu...
CVE-2016-10575——Kindlegen is a simple Node.js wrapper of the official kindlegen program. Kindlegen versions before 1.1.0 download binary...
CVE-2016-10574——apk-parser3 is a module to extract Android Manifest info from an APK file. apk-parser3 versions before 0.1.3 download bi...
CVE-2016-10572——mongodb-instance before 0.0.3 installs mongodb locally. mongodb-instance downloads binary resources over HTTP, which lea...
CVE-2016-10571——bkjs-wand is imagemagick wand support for node.js and backendjs bkjs-wand versions lower than 0.3.2 download binary reso...
CVE-2016-10569——embedza is a module to create HTML snippets/embeds from URLs using info from oEmbed, Open Graph, meta tags. embedza vers...
CVE-2016-10565——operadriver is a Opera Driver for Selenium. operadriver versions below 0.2.3 download binary resources over HTTP, which ...
CVE-2016-10564——apk-parser is a tool to extract Android Manifest info from an APK file. apk-parser versions below 0.1.6 download binary ...
CVE-2016-10563——During the installation process, the go-ipfs-deps module before 0.4.4 insecurely downloads resources over HTTP. This all...
CVE-2016-10562——iedriver is an NPM wrapper for Selenium IEDriver. iedriver versions below 3.0.0 download binary resources over HTTP, whi...
CVE-2016-10561——Bitty is a development web server tool that functions similar to `python -m SimpleHTTPServer`. Version 0.2.10 has a dire...
CVE-2016-10557——appium-chromedriver is a Node.js wrapper around Chromedriver. Versions below 2.9.4 download binary resources over HTTP, ...
CVE-2016-10555——Since "algorithm" isn't enforced in jwt.decode()in jwt-simple 0.3.0 and earlier, a malicious user could choose what algo...
CVE-2016-10554——sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Mi...
CVE-2016-10553——sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Mi...
CVE-2016-10552——igniteui 0.0.5 and earlier downloads JavaScript and CSS resources over insecure protocol.
CVE-2016-10550——sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Mi...
CVE-2016-10549——Sails is an MVC style framework for building realtime web applications. Version 0.12.7 and lower have an issue with the ...
CVE-2016-10548——Arbitrary code execution is possible in reduce-css-calc node module <=1.2.4 through crafted css. This makes cross sites ...
CVE-2016-10547——Nunjucks is a full featured templating engine for JavaScript. Versions 2.4.2 and lower have a cross site scripting (XSS)...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now