CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

node-openssl_project

node-openssl

2 known vulnerabilities · sorted by CVSS score

CVE-2023-49210
CRITICAL9.8

The openssl (aka node-openssl) NPM package through 2.0.0 was characterized as "a nonsense wrapper with no real purpose" by its author, and accepts an opts argument that contains a verb field (used for command execution). NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

node-openssl_project / node-openssl
Network
Published Nov 23, 2023
CVE-2017-16064
HIGH7.5

node-openssl was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

node-openssl_project / node-openssl
Network
Published Jun 7, 2018