2016 CVE Vulnerabilities

10,648 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-10615——curses is bindings for the native curses library, a full featured console IO library. curses downloads binary resources ...
CVE-2016-10614——httpsync is a port of libcurl to node.js. httpsync downloads binary resources over HTTP, which leaves it vulnerable to M...
CVE-2016-10613——bionode-sra is a Node.js wrapper for SRA Toolkit. bionode-sra downloads data resources over HTTP, which leaves it vulner...
CVE-2016-10612——dalek-browser-ie-canary is Internet Explorer bindings for DalekJS. dalek-browser-ie-canary downloads binary resources ov...
CVE-2016-10610——unicode-json is a unicode lookup table. unicode-json before 2.0.0 downloads data resources over HTTP, which leaves it vu...
CVE-2016-10609——chromedriver126 is chromedriver version 1.26 for linux OS. chromedriver126 downloads binary resources over HTTP, which l...
CVE-2016-10608——robot-js is a module for native system automation for node.js. robot-js downloads binary resources over HTTP, which leav...
CVE-2016-10607——openframe-glsviewer is a Openframe extension which adds support for shaders via glslViewer. openframe-glsviewer download...
CVE-2016-10606——grunt-webdriver-qunit is a grunt plugin to run qunit with webdriver in grunt grunt-webdriver-qunit downloads binary reso...
CVE-2016-10605——dalek-browser-ie is Internet Explorer bindings for DalekJS. dalek-browser-ie downloads binary resources over HTTP, which...
CVE-2016-10604——dalek-browser-chrome is Google Chrome bindings for DalekJS. dalek-browser-chrome downloads binary resources over HTTP, w...
CVE-2016-10603——air-sdk is a NPM wrapper for the Adobe AIR SDK. air-sdk downloads binary resources over HTTP, which leaves it vulnerable...
CVE-2016-10602——haxe is a cross-platform toolkit haxe downloads zipped resources over HTTP, which leaves it vulnerable to MITM attacks. ...
CVE-2016-10600——webrtc-native uses WebRTC from chromium project. webrtc-native downloads binary resources over HTTP, which leaves it vul...
CVE-2016-10599——sauce-connect is a Node.js wrapper over the SauceLabs SauceConnect.jar program for establishing a secure tunnel for intr...
CVE-2016-10598——arrayfire-js is a module for ArrayFire for the Node.js platform. arrayfire-js downloads binary resources over HTTP, whic...
CVE-2016-10597MEDIUM5.9cobalt-cli downloads resources over HTTP, which leaves it vulnerable to MITM attacks.
CVE-2016-10596——imageoptim is a Node.js wrapper for some images compression algorithms. imageoptim downloads zipped resources over HTTP,...
CVE-2016-10595HIGH8.1jdf-sass is a fork from node-sass, jdf use only. jdf-sass downloads executable resources over HTTP, which leaves it vuln...
CVE-2016-10594——ipip is a Node.js module to query geolocation information for an IP or domain, based on database by ipip.net. ipip downl...
CVE-2016-10592——jser-stat is a JSer.info stat library. jser-stat downloads data resources over HTTP, which leaves it vulnerable to MITM ...
CVE-2016-10588——nw is an installer for nw.js. nw downloads zipped resources over HTTP, It may be possible to cause remote code execution...
CVE-2016-10587——wasdk is a toolkit for creating WebAssembly modules. wasdk downloads binary resources over HTTP, which leaves it vulnera...
CVE-2016-10585——libxl provides Node bindings for the libxl library for reading and writing excel (XLS and XLSX) spreadsheets. libxl down...
CVE-2016-10583HIGH8.1closure-utils is Utilities for Closure Library based projects. closure-utils downloads binary resources over HTTP, which...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now