Ipip develops a narrowly scoped product line centered on geolocation and IP intelligence databases, with the durable signal reflecting inadequate protection of sensitive data assets. The recurrent weakness across its offerings centers on missing encryption of sensitive information, a structural concern for products handling geographic and network metadata. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ipip over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-10673HIGH ipip-coffee queries geolocation information from IP ipip-coffee downloads geolocation resources over HTTP, which leaves it vulnerable to MITM attacks. This could impact the integri | Jun 4, 2018 | 8.1 | 22 | NO | NO |
CVE-2016-10594HIGH ipip is a Node.js module to query geolocation information for an IP or domain, based on database by ipip.net. ipip downloads data resources over HTTP, which leaves it vulnerable to | Jun 1, 2018 | 8.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ipip.
Media articles that mention a CVE ID that affects a product developed by Ipip — matched by CVE ID, not by vendor name.