2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2016-10546An arbitrary code injection vector was found in PouchDB 6.0.4 and lesser via the map/reduce functions used in PouchDB te...
CVE-2016-10544uws is a WebSocket server library. By sending a 256mb websocket message to a uws server instance with permessage-deflate...
CVE-2016-10543call is an HTTP router that is primarily used by the hapi framework. There exists a bug in call versions 2.0.1-3.0.1 tha...
CVE-2016-10542ws is a "simple to use, blazing fast and thoroughly tested websocket client, server and console for node.js, up-to-date ...
CVE-2016-10540Minimatch is a minimal matching utility that works by converting glob expressions into JavaScript `RegExp` objects. The ...
CVE-2016-10539negotiator is an HTTP content negotiator for Node.js and is used by many modules and frameworks including Express and Ko...
CVE-2016-10538The package `node-cli` before 1.0.0 insecurely uses the lock_file and log_file. Both of these are temporary, but it allo...
CVE-2016-10537backbone is a module that adds in structure to a JavaScript heavy application through key-value pairs and custom events ...
CVE-2016-10536engine.io-client is the client for engine.io, the implementation of a transport-based cross-browser/cross-device bi-dire...
CVE-2016-10535csrf-lite is a cross-site request forgery protection library for framework-less node sites. csrf-lite uses `===`, a fail...
CVE-2016-10534electron-packager is a command line tool that packages Electron source code into `.app` and `.exe` packages. along with ...
CVE-2016-10533express-restify-mongoose is a module to easily create a flexible REST interface for mongoose models. express-restify-mon...
CVE-2016-10532console-io is a module that allows users to implement a web console in their application. A malicious user could bypass ...
CVE-2016-10531marked is an application that is meant to parse and compile markdown. Due to the way that marked 0.3.5 and earlier parse...
CVE-2016-10530The airbrake module 0.3.8 and earlier defaults to sending environment variables over HTTP. Environment variables can oft...
CVE-2016-10529Droppy versions <3.5.0 does not perform any verification for cross-domain websocket requests. An attacker is able to mak...
CVE-2016-10528restafary is a REpresentful State Transfer API for Creating, Reading, Using, Deleting files on a server from the web. Re...
CVE-2016-10527The riot-compiler version version 2.3.21 has an issue in a regex (Catastrophic Backtracking) thats make it unusable unde...
CVE-2016-10526A common setup to deploy to gh-pages on every commit via a CI system is to expose a github token to ENV and to use it di...
CVE-2016-10523MQTT before 3.4.6 and 4.0.x before 4.0.5 allows specifically crafted MQTT packets to crash the application, making a DoS...
CVE-2016-10519A security issue was found in bittorrent-dht before 5.1.3 that allows someone to send a specific series of messages to a...
CVE-2016-10518A vulnerability was found in the ping functionality of the ws module before 1.0.0 which allowed clients to allocate memo...
CVE-2016-10698mystem-fix is a node.js wrapper for MyStem morphology text analyzer by Yandex.ru mystem-fix downloads binary resources o...
CVE-2016-10682massif is a Phantomjs fork massif downloads resources over HTTP, which leaves it vulnerable to MITM attacks. It may be p...
CVE-2016-10681roslib-socketio - The standard ROS Javascript Library fork for add support to socket.io roslib-socketio downloads binary...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now