2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-20008 | HIGH | 7.5 | 1.0% | Jan 1, 2021 | The REST/JSON project 7.x-1.x for Drupal allows session enumeration, aka SA-CONTRIB-2016-033. NOTE: This project is not ... |
| CVE-2016-20007 | HIGH | 7.5 | 1.0% | Jan 1, 2021 | The REST/JSON project 7.x-1.x for Drupal allows session name guessing, aka SA-CONTRIB-2016-033. NOTE: This project is no... |
| CVE-2016-20006 | HIGH | 7.5 | 1.0% | Jan 1, 2021 | The REST/JSON project 7.x-1.x for Drupal allows blockage of user logins, aka SA-CONTRIB-2016-033. NOTE: This project is ... |
| CVE-2016-9026 | CRITICAL | 9.8 | 1.3% | Dec 31, 2020 | Exponent CMS before 2.6.0 has improper input validation in fileController.php. |
| CVE-2016-9025 | CRITICAL | 9.8 | 1.2% | Dec 31, 2020 | Exponent CMS before 2.6.0 has improper input validation in purchaseOrderController.php. |
| CVE-2016-9023 | CRITICAL | 9.8 | 1.2% | Dec 31, 2020 | Exponent CMS before 2.6.0 has improper input validation in cron/find_help.php. |
| CVE-2016-9022 | CRITICAL | 9.8 | 1.3% | Dec 31, 2020 | Exponent CMS before 2.6.0 has improper input validation in usersController.php. |
| CVE-2016-9021 | CRITICAL | 9.8 | 1.3% | Dec 31, 2020 | Exponent CMS before 2.6.0 has improper input validation in storeController.php. |
| CVE-2016-15001 | — | — | — | Dec 10, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No... |
| CVE-2016-0745 | — | — | — | Nov 5, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No... |
| CVE-2016-0744 | — | — | — | Nov 5, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No... |
| CVE-2016-0743 | — | — | — | Nov 5, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No... |
| CVE-2016-11086 | HIGH | 7.4 | 0.7% | Sep 24, 2020 | lib/oauth/consumer.rb in the oauth-ruby gem through 0.5.4 for Ruby does not verify server X.509 certificates if a certif... |
| CVE-2016-6502 | — | — | — | Aug 17, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2016-6499 | — | — | — | Aug 17, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2016-6498 | — | — | — | Aug 17, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2016-11085 | MEDIUM | 6.5 | 1.0% | Aug 16, 2020 | php/qmn_options_questions_tab.php in the quiz-master-next plugin before 4.7.9 for WordPress allows CSRF, with resultant ... |
| CVE-2016-7064 | HIGH | 7.5 | 0.7% | Jul 21, 2020 | A flaw was found in pritunl-client before version 1.0.1116.6. A lack of signature verification leads to sensitive inform... |
| CVE-2016-7063 | CRITICAL | 9.8 | 2.4% | Jul 21, 2020 | A flaw was found in pritunl-client before version 1.0.1116.6. Arbitrary write to user specified path may lead to privile... |
| CVE-2016-11084 | MEDIUM | 6.1 | 0.3% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 2.1.0. It allows XSS via CSRF. |
| CVE-2016-11083 | MEDIUM | 6.1 | 0.7% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 2.2.0. It allows XSS because it configures files to be opened in a b... |
| CVE-2016-11082 | MEDIUM | 6.1 | 0.7% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 2.2.0. It allows XSS via a crafted link. |
| CVE-2016-11081 | MEDIUM | 4.3 | 0.7% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 2.2.0. It allows unintended access to information stored by a web br... |
| CVE-2016-11080 | MEDIUM | 4.3 | 0.7% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 3.0.0. It offers superfluous APIs for a Team Administrator to view a... |
| CVE-2016-11079 | MEDIUM | 6.1 | 0.7% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 3.0.0. It allows XSS via a redirect URL. |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now