2016 CVE Vulnerabilities

10,645 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-20070MEDIUM5.1WordPress Booking Calendar Contact Form 1.0.23 contains privilege escalation and stored cross-site scripting vulnerabili...
CVE-2016-20069HIGH8.8WordPress Booking Calendar Contact Form 1.0.23 contains an unauthenticated blind SQL injection vulnerability in the shor...
CVE-2016-20068HIGH8.8WordPress Booking Calendar Contact Form version 1.0.23 contains an unauthenticated blind SQL injection vulnerability tha...
CVE-2016-20067MEDIUM5.3WordPress CP Polls 1.0.8 contains a cross-site request forgery vulnerability that allows attackers to perform unauthoriz...
CVE-2016-20066MEDIUM5.1WordPress CP Polls 1.0.8 contains a persistent cross-site scripting vulnerability that allows attackers to inject malici...
CVE-2016-20065HIGH8.8Product Catalog 8 1.2 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers...
CVE-2016-20064MEDIUM6.9WP Vault 0.8.6.6 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary f...
CVE-2016-20063HIGH7.1Single Personal Message 1.0.3 contains an SQL injection vulnerability that allows authenticated users to execute arbitra...
CVE-2016-20062HIGH8.8Simply Poll 1.4.1 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers to ...
CVE-2016-20054MEDIUM5.3Nodcms contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized administrative ...
CVE-2016-20061HIGH8.5sheed AntiVirus 2.3 contains an unquoted service path vulnerability in the ShavProt service that allows local attackers ...
CVE-2016-20060HIGH8.5Hotspot Shield 6.0.3 contains an unquoted service path vulnerability in the hshld service binary that allows local attac...
CVE-2016-20059HIGH8.5IObit Malware Fighter 4.3.1 contains an unquoted service path vulnerability in the IMFservice and LiveUpdateSvc services...
CVE-2016-20058HIGH8.5Netgate AMITI Antivirus build 23.0.305 contains an unquoted service path vulnerability in the AmitiAvSrv and AmitiAntivi...
CVE-2016-20057HIGH8.5NETGATE Registry Cleaner build 16.0.205 contains an unquoted service path vulnerability in the NGRegClnSrv service that ...
CVE-2016-20056HIGH8.5Spy Emergency build 23.0.205 contains an unquoted service path vulnerability in the SpyEmrgHealth and SpyEmrgSrv service...
CVE-2016-20055HIGH8.5IObit Advanced SystemCare 10.0.2 contains an unquoted service path vulnerability in the AdvancedSystemCareService10 serv...
CVE-2016-20053MEDIUM6.9Redaxo CMS 5.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create admin...
CVE-2016-20052CRITICAL9.3Snews CMS 1.7 contains an unrestricted file upload vulnerability that allows unauthenticated attackers to upload arbitra...
CVE-2016-20051MEDIUM6.9Snews CMS 1.7 contains a cross-site request forgery vulnerability that allows attackers to change administrator credenti...
CVE-2016-20050MEDIUM6.9NetSchedScan 1.0 contains a buffer overflow vulnerability in the scan Hostname/IP field that allows local attackers to c...
CVE-2016-15058HIGH8.6Hirschmann HiLCOS Classic Platform switches Classic L2E, L2P, L3E, L3P versions prior to 09.0.06 and Classic L2B prior t...
CVE-2016-20049CRITICAL9.3JAD 1.5.8e-1kali1 and prior contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitr...
CVE-2016-20048HIGH8.6iSelect 1.4.0-2+b1 contains a local buffer overflow vulnerability that allows local attackers to execute arbitrary code ...
CVE-2016-20047HIGH8.6EKG Gadu 1.9~pre+r2855-3+b1 contains a local buffer overflow vulnerability in the username handling that allows local at...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now