2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-5235 | — | — | 0.9% | Jul 1, 2019 | A Cross Site Scripting (XSS) vulnerability in versions of F5 WebSafe Dashboard 3.9.x and earlier, aka F5 WebSafe Alert S... |
| CVE-2016-10761 | — | — | 0.7% | Jun 29, 2019 | Logitech Unifying devices before 2016-02-26 allow keystroke injection, bypassing encryption, aka MouseJack. |
| CVE-2016-7404 | — | — | 1.9% | Jun 21, 2019 | OpenStack Magnum passes OpenStack credentials into the Heat templates creating its instances. While these should just be... |
| CVE-2016-10760 | — | — | 3.2% | Jun 11, 2019 | On Seowon Intech routers, there is a Command Injection vulnerability in diagnostic.cgi via shell metacharacters in the p... |
| CVE-2016-10759 | — | — | 3.7% | May 24, 2019 | The Xinha plugin in Precurio 2.1 allows Directory Traversal, with resultant arbitrary code execution, via ExtendedFileMa... |
| CVE-2016-10758 | — | — | 1.7% | May 24, 2019 | PHPKIT 1.6.6 allows arbitrary File Upload, as demonstrated by a .php file to pkinc/admin/mediaarchive.php and pkinc/func... |
| CVE-2016-10757 | — | — | 1.3% | May 24, 2019 | In Redaxo 5.2.0, the cron management of the admin panel suffers from CSRF that leads to arbitrary Remote Code Execution ... |
| CVE-2016-10756 | — | — | 0.7% | May 24, 2019 | Kliqqi 3.0.0.5 allows CSRF with resultant Arbitrary File Upload because module.php?module=upload can be used to configur... |
| CVE-2016-10755 | — | — | 1.3% | May 24, 2019 | AbanteCart 1.2.8 allows SQL Injection via the source_language parameter to admin/controller/pages/localisation/language.... |
| CVE-2016-10754 | — | — | 1.5% | May 24, 2019 | modules/Calendar/Activity.php in Vtiger CRM 6.5.0 allows SQL injection via the contactidlist parameter. |
| CVE-2016-10753 | — | — | 1.7% | May 24, 2019 | e107 2.1.2 allows PHP Object Injection with resultant SQL injection, because usersettings.php uses unserialize without a... |
| CVE-2016-10752 | — | — | 2.3% | May 24, 2019 | serendipity_moveMediaDirectory in Serendipity 2.0.3 allows remote attackers to upload and execute arbitrary PHP code bec... |
| CVE-2016-10751 | — | — | 2.9% | May 24, 2019 | osClass 3.6.1 allows oc-admin/plugins.php Directory Traversal via the plugin parameter. This is exploitable for remote P... |
| CVE-2016-8900 | — | — | 2.1% | May 24, 2019 | Exponent CMS version 2.3.9 suffers from a Object Injection vulnerability in framework/modules/core/controllers/expTagCon... |
| CVE-2016-8898 | — | — | 1.8% | May 24, 2019 | Exponent CMS version 2.3.9 suffers from a sql injection vulnerability in framework/modules/ecommerce/controllers/cartCon... |
| CVE-2016-10245 | — | — | 1.8% | May 24, 2019 | Insufficient sanitization of the query parameter in templates/html/search_opensearch.php could lead to reflected cross-s... |
| CVE-2016-8899 | — | — | 2.1% | May 23, 2019 | Exponent CMS version 2.3.9 suffers from a Object Injection vulnerability in framework/modules/core/controllers/expCatCon... |
| CVE-2016-8897 | — | — | 1.8% | May 23, 2019 | Exponent CMS version 2.3.9 suffers from a sql injection vulnerability in framework/modules/help/controllers/helpControll... |
| CVE-2016-7550 | — | — | 2.4% | May 23, 2019 | asterisk 13.10.0 is affected by: denial of service issues in asterisk. The impact is: cause a denial of service (remote)... |
| CVE-2016-9969 | — | — | 1.2% | May 23, 2019 | In libwebp 0.5.1, there is a double free bug in libwebpmux. |
| CVE-2016-8901 | — | — | 2.7% | May 23, 2019 | b2evolution 6.7.6 suffer from an Object Injection vulnerability in /htsrv/call_plugin.php. |
| CVE-2016-10750 | — | — | 3.7% | May 22, 2019 | In Hazelcast before 3.11, the cluster join procedure is vulnerable to remote code execution via Java deserialization. If... |
| CVE-2016-7151 | — | — | 1.0% | May 15, 2019 | Capstone 3.0.4 has an out-of-bounds vulnerability (SEGV caused by a read memory access) in X86_insn_reg_intel in arch/X8... |
| CVE-2016-10719 | — | — | 1.0% | May 15, 2019 | TP-Link Archer CR-700 1.0.6 devices have an XSS vulnerability that can be introduced into the admin account through a DH... |
| CVE-2016-1600 | — | — | 1.1% | May 9, 2019 | The ServiceNow driver in NetIQ Identity Manager versions prior to 4.6 are susceptible to an information disclosure vulne... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now