2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2016-20096CRITICAL9.8Linknat VOS3000 and VOS2009 through version 2.1.2.0 contain an unauthenticated SQL injection vulnerability that allows r...
CVE-2016-20052CRITICAL9.8Snews CMS 1.7 contains an unrestricted file upload vulnerability that allows unauthenticated attackers to upload arbitra...
CVE-2016-20049CRITICAL9.8JAD 1.5.8e-1kali1 and prior contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitr...
CVE-2016-20030CRITICAL9.8ZKTeco ZKBioSecurity 3.0 contains a user enumeration vulnerability that allows unauthenticated attackers to discover val...
CVE-2016-20026CRITICAL9.8ZKTeco ZKBioSecurity 3.0 contains hardcoded credentials in the bundled Apache Tomcat server that allow unauthenticated a...
CVE-2016-20024CRITICAL9.8ZKTeco ZKTime.Net 3.0.1.6 contains an insecure file permissions vulnerability that allows unprivileged users to escalate...
CVE-2016-15057CRITICAL9.9** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in a Command ('Command Injection') vuln...
CVE-2016-15048CRITICAL9.8AMTT Hotel Broadband Operation System (HiBOS) contains an unauthenticated command injection vulnerability in the /manage...
CVE-2016-15044CRITICAL9.3A remote code execution vulnerability exists in Kaltura versions prior to 11.1.0-2 due to unsafe deserialization of user...
CVE-2016-15043CRITICAL9.8The WP Mobile Detector plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation ...
CVE-2016-15042CRITICAL9.8The Frontend File Manager (versions < 4.0), N-Media Post Front-end Form (versions < 1.1) plugins for WordPress are vulne...
CVE-2016-15040CRITICAL9.8The Kento Post View Counter plugin for WordPress is vulnerable to SQL Injection via the 'kento_pvc_geo' parameter in ver...
CVE-2016-20021CRITICAL9.8In Gentoo Portage before 3.0.47, there is missing PGP validation of executed code: the standalone emerge-webrsync downlo...
CVE-2016-15034CRITICAL9.8A vulnerability was found in Dynacase Webdesk and classified as critical. Affected by this issue is the function freedom...
CVE-2016-15033CRITICAL9.8The Delete All Comments plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation...
CVE-2016-15031CRITICAL9.8A vulnerability was found in PHP-Login 1.0. It has been declared as critical. This vulnerability affects the function ch...
CVE-2016-15021CRITICAL9.8A vulnerability was found in nickzren alsdb. It has been rated as critical. This issue affects some unknown processing. ...
CVE-2016-15020CRITICAL9.8A vulnerability was found in liftkit database up to 2.13.1. It has been classified as critical. This affects the functio...
CVE-2016-15018CRITICAL9.8A vulnerability was found in krail-jpa up to 0.9.1. It has been classified as critical. This affects an unknown part. Th...
CVE-2016-15017CRITICAL9.8A vulnerability has been found in fabarea media_upload on TYPO3 and classified as critical. This vulnerability affects t...
CVE-2016-15016CRITICAL9.8A vulnerability was found in mrtnmtth joomla_mod_einsatz_stats up to 0.2. It has been classified as critical. This affec...
CVE-2016-15013CRITICAL9.8A vulnerability was found in ForumHulp searchresults. It has been rated as critical. Affected by this issue is the funct...
CVE-2016-15012CRITICAL9.8** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in forcedotcom SalesforceMobileSDK-Windows up to 4.x. It has b...
CVE-2016-15011CRITICAL9.8A vulnerability classified as problematic was found in e-Contract dssp up to 1.3.1. Affected by this vulnerability is th...
CVE-2016-15007CRITICAL9.8A vulnerability was found in Centralized-Salesforce-Dev-Framework. It has been declared as problematic. Affected by this...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now