2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-20008HIGH7.5The REST/JSON project 7.x-1.x for Drupal allows session enumeration, aka SA-CONTRIB-2016-033. NOTE: This project is not ...
CVE-2016-20007HIGH7.5The REST/JSON project 7.x-1.x for Drupal allows session name guessing, aka SA-CONTRIB-2016-033. NOTE: This project is no...
CVE-2016-20006HIGH7.5The REST/JSON project 7.x-1.x for Drupal allows blockage of user logins, aka SA-CONTRIB-2016-033. NOTE: This project is ...
CVE-2016-9026CRITICAL9.8Exponent CMS before 2.6.0 has improper input validation in fileController.php.
CVE-2016-9025CRITICAL9.8Exponent CMS before 2.6.0 has improper input validation in purchaseOrderController.php.
CVE-2016-9023CRITICAL9.8Exponent CMS before 2.6.0 has improper input validation in cron/find_help.php.
CVE-2016-9022CRITICAL9.8Exponent CMS before 2.6.0 has improper input validation in usersController.php.
CVE-2016-9021CRITICAL9.8Exponent CMS before 2.6.0 has improper input validation in storeController.php.
CVE-2016-15001Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No...
CVE-2016-0745Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No...
CVE-2016-0744Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No...
CVE-2016-0743Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No...
CVE-2016-11086HIGH7.4lib/oauth/consumer.rb in the oauth-ruby gem through 0.5.4 for Ruby does not verify server X.509 certificates if a certif...
CVE-2016-6502Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2016-6499Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2016-6498Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2016-11085MEDIUM6.5php/qmn_options_questions_tab.php in the quiz-master-next plugin before 4.7.9 for WordPress allows CSRF, with resultant ...
CVE-2016-7064HIGH7.5A flaw was found in pritunl-client before version 1.0.1116.6. A lack of signature verification leads to sensitive inform...
CVE-2016-7063CRITICAL9.8A flaw was found in pritunl-client before version 1.0.1116.6. Arbitrary write to user specified path may lead to privile...
CVE-2016-11084MEDIUM6.1An issue was discovered in Mattermost Server before 2.1.0. It allows XSS via CSRF.
CVE-2016-11083MEDIUM6.1An issue was discovered in Mattermost Server before 2.2.0. It allows XSS because it configures files to be opened in a b...
CVE-2016-11082MEDIUM6.1An issue was discovered in Mattermost Server before 2.2.0. It allows XSS via a crafted link.
CVE-2016-11081MEDIUM4.3An issue was discovered in Mattermost Server before 2.2.0. It allows unintended access to information stored by a web br...
CVE-2016-11080MEDIUM4.3An issue was discovered in Mattermost Server before 3.0.0. It offers superfluous APIs for a Team Administrator to view a...
CVE-2016-11079MEDIUM6.1An issue was discovered in Mattermost Server before 3.0.0. It allows XSS via a redirect URL.

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now