2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-10846 | — | — | 1.3% | Aug 1, 2019 | cPanel before 11.54.0.4 allows arbitrary file-chown and file-chmod operations during Roundcube database conversions (SEC... |
| CVE-2016-10845 | — | — | 1.1% | Aug 1, 2019 | cPanel before 11.54.0.4 allows arbitrary file-overwrite operations in scripts/check_system_storable (SEC-78). |
| CVE-2016-10844 | — | — | 1.1% | Aug 1, 2019 | The chcpass script in cPanel before 11.54.0.4 reveals a password hash (SEC-77). |
| CVE-2016-10843 | — | — | 1.4% | Aug 1, 2019 | cPanel before 11.54.0.4 allows code execution in the context of shared users via JSON-API (SEC-76). |
| CVE-2016-10842 | — | — | 1.1% | Aug 1, 2019 | cPanel before 11.54.0.4 allows certain file-read operations in bin/setup_global_spam_filter.pl (SEC-74). |
| CVE-2016-10841 | — | — | 0.9% | Aug 1, 2019 | The bin/mkvhostspasswd script in cPanel before 11.54.0.4 discloses password hashes (SEC-73). |
| CVE-2016-10840 | — | — | 2.1% | Aug 1, 2019 | cPanel before 11.54.0.4 allows arbitrary code execution during locale duplication (SEC-72). |
| CVE-2016-10839 | — | — | 1.1% | Aug 1, 2019 | cPanel before 11.54.0.4 allows SQL injection in bin/horde_update_usernames (SEC-71). |
| CVE-2016-10838 | — | — | 1.1% | Aug 1, 2019 | cPanel before 11.54.0.4 allows arbitrary file-read operations via the bin/fmq script (SEC-70). |
| CVE-2016-10837 | — | — | 1.5% | Aug 1, 2019 | cPanel before 11.54.0.4 allows arbitrary code execution because of an unsafe @INC path (SEC-46). |
| CVE-2016-10836 | — | — | 1.1% | Aug 1, 2019 | cPanel before 55.9999.141 allows arbitrary file-read operations during authentication with caldav (SEC-108). |
| CVE-2016-10860 | — | — | 1.0% | Aug 1, 2019 | cPanel before 11.54.0.0 allows unauthorized zone modification via the WHM API (SEC-66). |
| CVE-2016-10859 | — | — | 1.0% | Aug 1, 2019 | cPanel before 11.54.0.0 allows unauthorized password changes via Webmail API commands (SEC-65). |
| CVE-2016-10858 | — | — | 2.5% | Aug 1, 2019 | cPanel before 11.54.0.0 allows unauthenticated arbitrary code execution via DNS NS entry poisoning (SEC-64). |
| CVE-2016-10857 | — | — | 1.0% | Aug 1, 2019 | cPanel before 11.54.0.0 allows a bypass of the e-mail sending limit (SEC-60). |
| CVE-2016-10856 | — | — | 1.0% | Aug 1, 2019 | cPanel before 11.54.0.0 allows subaccounts to discover sensitive data through comet feeds (SEC-29). |
| CVE-2016-10855 | — | — | 2.6% | Aug 1, 2019 | cPanel before 11.54.0.4 allows unauthenticated arbitrary code execution via cpsrvd (SEC-91). |
| CVE-2016-10854 | — | — | 0.6% | Aug 1, 2019 | cPanel before 11.54.0.4 allows self XSS in the X3 Entropy Banner interface (SEC-87). |
| CVE-2016-10853 | — | — | 0.6% | Aug 1, 2019 | cPanel before 11.54.0.4 allows stored XSS in the WHM Feature Manager interface (SEC-86). |
| CVE-2016-10852 | — | — | 1.0% | Aug 1, 2019 | cPanel before 11.54.0.4 lacks ACL enforcement in the AppConfig subsystem (SEC-85). |
| CVE-2016-10851 | — | — | 0.6% | Aug 1, 2019 | cPanel before 11.54.0.4 allows self XSS in the WHM PHP Configuration editor interface (SEC-84). |
| CVE-2016-10850 | — | — | 2.1% | Aug 1, 2019 | cPanel before 11.54.0.4 allows arbitrary code execution via scripts/synccpaddonswithsqlhost (SEC-83). |
| CVE-2016-10763 | — | — | 0.9% | Jul 18, 2019 | The CampTix Event Ticketing plugin before 1.5 for WordPress allows XSS in the admin section via a ticket title or body. |
| CVE-2016-10762 | — | — | 1.8% | Jul 18, 2019 | The CampTix Event Ticketing plugin before 1.5 for WordPress allows CSV injection when the export tool is used. |
| CVE-2016-5236 | — | — | 0.6% | Jul 1, 2019 | Cross-Site-Scripting (XSS) vulnerabilities in F5 WebSafe Dashboard 3.9.5 and earlier, aka F5 WebSafe Alert Server, allow... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now