2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-5202CRITICAL9.1browser/extensions/api/dial/dial_registry.cc in Google Chrome before 54.0.2840.98 on macOS, before 54.0.2840.99 on Windo...
CVE-2016-2360CRITICAL9.8Milesight IP security cameras through 2016-11-14 have a default root password in /etc/shadow that is the same across dif...
CVE-2016-2359CRITICAL9.8Milesight IP security cameras through 2016-11-14 allow remote attackers to bypass authentication and access a protected ...
CVE-2016-2358CRITICAL9.8Milesight IP security cameras through 2016-11-14 have a default set of 10 privileged accounts with hardcoded credentials...
CVE-2016-2357CRITICAL9.8Milesight IP security cameras through 2016-11-14 have a hardcoded SSL private key under the /etc/config directory.
CVE-2016-2356CRITICAL9.8Milesight IP security cameras through 2016-11-14 have a buffer overflow in a web application via a long username or pass...
CVE-2016-11016MEDIUM6.1NETGEAR JNR1010 devices before 1.0.0.32 allow webproc?getpage= XSS.
CVE-2016-11015MEDIUM6.5NETGEAR JNR1010 devices before 1.0.0.32 allow cgi-bin/webproc CSRF via the :InternetGatewayDevice.X_TWSZ-COM_URL_Filter....
CVE-2016-11014CRITICAL9.8NETGEAR JNR1010 devices before 1.0.0.32 have Incorrect Access Control because the ok value of the auth cookie is a speci...
CVE-2016-11013MEDIUM6.1The wp-listings plugin before 2.0.2 for WordPress has includes/views/single-listing.php XSS.
CVE-2016-11012MEDIUM5.4The sola-support-tickets plugin before 3.13 for WordPress has incorrect access control for /wp-admin with resultant XSS.
CVE-2016-11011MEDIUM6.5The wp-invoice plugin before 4.1.1 for WordPress has wpi_update_user_option privilege escalation.
CVE-2016-11010MEDIUM5.3The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_twocheckout payer metadata update...
CVE-2016-11009MEDIUM5.3The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_interkassa payer metadata updates...
CVE-2016-11008MEDIUM5.3The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_paypal payer metadata updates.
CVE-2016-11007MEDIUM5.3The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_user_id for invoice retrieval.
CVE-2016-11006MEDIUM5.3The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control for admin_init settings changes.
CVE-2016-11005MEDIUM6.1The instalinker plugin before 1.1.2 for WordPress has includes/instalinker-admin-preview.php?client_id= XSS.
CVE-2016-11004HIGH8.8The Elegant Themes Monarch plugin before 1.2.7 for WordPress has privilege escalation.
CVE-2016-11003HIGH8.8The Elegant Themes Bloom plugin before 1.1.1 for WordPress has privilege escalation.
CVE-2016-11002HIGH8.8The Elegant Themes Extra theme before 1.2.4 for WordPress has privilege escalation.
CVE-2016-11001MEDIUM6.1The user-submitted-posts plugin before 20160215 for WordPress has XSS via the user-submitted-content field.
CVE-2016-11000CRITICAL9.8The wp-ultimate-exporter plugin through 1.1 for WordPress has SQL injection via the export_type_name parameter.
CVE-2016-10999MEDIUM6.1The Goodnews theme through 2016-02-28 for WordPress has XSS via the s parameter.
CVE-2016-10998MEDIUM6.1The ocim-mp3 plugin through 2016-03-07 for WordPress has wp-content/plugins/ocim-mp3/source/pages.php?id= XSS.

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now