2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2016-10738Zenbership v107 has CSRF via admin/cp-functions/event-add.php.
CVE-2016-10737Serendipity 2.0.4 has XSS via the serendipity_admin.php serendipity[body] parameter.
CVE-2016-7576In iOS before 9.3.3, a memory corruption issue existed in the kernel. This issue was addressed through improved memory h...
CVE-2016-4644In iOS before 9.3.3, tvOS before 9.2.2, and OS X El Capitan before v10.11.6 and Security Update 2016-004, a downgrade is...
CVE-2016-4643In iOS before 9.3.3, tvOS before 9.2.2, and OS X El Capitan before v10.11.6 and Security Update 2016-004, a validation i...
CVE-2016-4642In iOS before 9.3.3, tvOS before 9.2.2, and OS X El Capitan before v10.11.6 and Security Update 2016-004, proxy authenti...
CVE-2016-10736The "Social Pug - Easy Social Share Buttons" plugin before 1.2.6 for WordPress allows XSS via the wp-admin/admin.php?pag...
CVE-2016-9651A missing check for whether a property of a JS object is private in V8 in Google Chrome prior to 55.0.2883.75 allowed a ...
CVE-2016-10403Insufficient data validation on image data in PDFium in Google Chrome prior to 51.0.2704.63 allowed a remote attacker to...
CVE-2016-10735In Bootstrap 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute, a differen...
CVE-2016-10502While generating trusted application id, An integer overflow can occur giving the trusted application an invalid identit...
CVE-2016-8489Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-10242. Reason: This candidate is a reservation...
CVE-2016-10734ProjectSend (formerly cFTP) r582 allows Insecure Direct Object Reference via includes/actions.log.export.php.
CVE-2016-10733ProjectSend (formerly cFTP) r582 allows directory traversal via file=../ in the process-zip-download.php query string.
CVE-2016-10732ProjectSend (formerly cFTP) r582 allows authentication bypass via a direct request for users.php, home.php, edit-file.ph...
CVE-2016-10731ProjectSend (formerly cFTP) r582 allows SQL injection via manage-files.php with the request parameter status, manage-fil...
CVE-2016-10730An issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. A...
CVE-2016-10729An issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. T...
CVE-2016-9069A use-after-free in nsINode::ReplaceOrInsertBefore during DOM operations resulting in potentially exploitable crashes. T...
CVE-2016-7475Under some circumstances on BIG-IP 12.0.0-12.1.0, 11.6.0-11.6.1, or 11.4.0-11.5.4 HF1, the Traffic Management Microkerne...
CVE-2016-0715Pivotal Cloud Foundry Elastic Runtime version 1.4.0 through 1.4.5, 1.5.0 through 1.5.11 and 1.6.0 through 1.6.11 is vuln...
CVE-2016-7066It was found that the improper default permissions on /tmp/auth directory in JBoss Enterprise Application Platform befor...
CVE-2016-1000232NodeJS Tough-Cookie version 2.2.2 contains a Regular Expression Parsing vulnerability in HTTP request Cookie Header pars...
CVE-2016-1000030Pidgin version <2.11.0 contains a vulnerability in X.509 Certificates imports specifically due to improper check of retu...
CVE-2016-9140Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now