Vulnerabilities (CVE)

Filtered by CWE-506
Total 100 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-16202 1 Cofeescript Project 1 Cofeescript 2026-06-17 5.0 MEDIUM 7.5 HIGH
The cofeescript module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.
CVE-2017-16128 1 Npm-script-demo Project 1 Npm-script-demo 2026-06-17 10.0 HIGH 9.8 CRITICAL
The module npm-script-demo opened a connection to a command and control server. It has been removed from the npm registry.
CVE-2017-16081 1 Cross-env.js Project 1 Cross-env.js 2026-06-17 5.0 MEDIUM 7.5 HIGH
cross-env.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16080 1 Nodesass Project 1 Nodesass 2026-06-17 5.0 MEDIUM 7.5 HIGH
nodesass was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16079 1 Smb Project 1 Smb 2026-06-17 5.0 MEDIUM 7.5 HIGH
smb was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16078 1 Shadowsock Project 1 Shadowsock 2026-06-17 5.0 MEDIUM 7.5 HIGH
shadowsock was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16077 1 Mongose Project 1 Mongose 2026-06-17 5.0 MEDIUM 7.5 HIGH
mongose was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16076 1 Proxy.js Project 1 Proxy.js 2026-06-17 5.0 MEDIUM 7.5 HIGH
proxy.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16075 1 Http-proxy.js Project 1 Http-proxy.js 2026-06-17 5.0 MEDIUM 7.5 HIGH
http-proxy.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16074 1 Crossenv Project 1 Crossenv 2026-06-17 5.0 MEDIUM 7.5 HIGH
crossenv was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16073 1 Noderequest Project 1 Noderequest 2026-06-17 5.0 MEDIUM 7.5 HIGH
noderequest was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16072 1 Nodemailer.js Project 1 Nodemailer.js 2026-06-17 5.0 MEDIUM 7.5 HIGH
nodemailer.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16071 1 Nodemailer-js Project 1 Nodemailer-js 2026-06-17 5.0 MEDIUM 7.5 HIGH
nodemailer-js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16070 1 Nodecaffe Project 1 Nodecaffe 2026-06-17 5.0 MEDIUM 7.5 HIGH
nodecaffe was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16069 1 Nodeffmpeg Project 1 Nodeffmpeg 2026-06-17 5.0 MEDIUM 7.5 HIGH
nodeffmpeg was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16068 1 Ffmepg Project 1 Ffmepg 2026-06-17 5.0 MEDIUM 7.5 HIGH
ffmepg was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16067 1 Node-opencv Project 1 Node-opencv 2026-06-17 5.0 MEDIUM 7.5 HIGH
node-opencv was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16066 1 Opencv.js Project 1 Opencv.js 2026-06-17 5.0 MEDIUM 7.5 HIGH
opencv.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16065 1 Openssl.js Project 1 Openssl.js 2026-06-17 5.0 MEDIUM 7.5 HIGH
openssl.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16064 1 Node-openssl Project 1 Node-openssl 2026-06-17 5.0 MEDIUM 7.5 HIGH
node-openssl was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.