2016 CVE Vulnerabilities
10,645 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-20016 | CRITICAL | 9.8 | 86.3% | Oct 19, 2022 | MVPower CCTV DVR models, including TV-7104HE 1.8.4 115215B9 and TV7108HE, contain a web shell that is accessible via a /... |
| CVE-2016-2338 | CRITICAL | 9.8 | 4.6% | Sep 29, 2022 | An exploitable heap overflow vulnerability exists in the Psych::Emitter start_document function of Ruby. In Psych::Emitt... |
| CVE-2016-4991 | CRITICAL | 9.8 | 1.4% | Jul 28, 2022 | Input passed to the Pdf() function is shell escaped and passed to child_process.exec() during PDF rendering. However, th... |
| CVE-2016-15004 | CRITICAL | 9.8 | 1.3% | Jul 23, 2022 | A vulnerability was found in InfiniteWP Client Plugin 1.5.1.3/1.6.0. It has been declared as critical. Affected by this ... |
| CVE-2016-20014 | CRITICAL | 9.8 | 1.2% | Apr 21, 2022 | In pam_tacplus.c in pam_tacplus before 1.4.1, pam_sm_acct_mgmt does not zero out the arep data structure. |
| CVE-2016-1239 | CRITICAL | 9.8 | 1.2% | Feb 19, 2022 | duck before 0.10 did not properly handle loading of untrusted code from the current directory. |
| CVE-2016-20010 | CRITICAL | 10 | 3.7% | May 5, 2021 | EWWW Image Optimizer before 2.8.5 allows remote command execution because it relies on a protection mechanism involving ... |
| CVE-2016-20009 | CRITICAL | 9.8 | 1.9% | Mar 11, 2021 | A DNS client stack-based buffer overflow in ipdnsc_decode_name() affects Wind River VxWorks 6.5 through 7. NOTE: This vu... |
| CVE-2016-20005 | CRITICAL | 9.8 | 1.2% | Jan 1, 2021 | The REST/JSON project 7.x-1.x for Drupal allows user registration bypass, aka SA-CONTRIB-2016-033. NOTE: This project is... |
| CVE-2016-20004 | CRITICAL | 9.8 | 1.2% | Jan 1, 2021 | The REST/JSON project 7.x-1.x for Drupal allows field access bypass, aka SA-CONTRIB-2016-033. NOTE: This project is not ... |
| CVE-2016-20002 | CRITICAL | 9.8 | 1.2% | Jan 1, 2021 | The REST/JSON project 7.x-1.x for Drupal allows comment access bypass, aka SA-CONTRIB-2016-033. NOTE: This project is no... |
| CVE-2016-20001 | CRITICAL | 9.8 | 1.2% | Jan 1, 2021 | The REST/JSON project 7.x-1.x for Drupal allows node access bypass, aka SA-CONTRIB-2016-033. NOTE: This project is not c... |
| CVE-2016-9026 | CRITICAL | 9.8 | 1.3% | Dec 31, 2020 | Exponent CMS before 2.6.0 has improper input validation in fileController.php. |
| CVE-2016-9025 | CRITICAL | 9.8 | 1.2% | Dec 31, 2020 | Exponent CMS before 2.6.0 has improper input validation in purchaseOrderController.php. |
| CVE-2016-9023 | CRITICAL | 9.8 | 1.2% | Dec 31, 2020 | Exponent CMS before 2.6.0 has improper input validation in cron/find_help.php. |
| CVE-2016-9022 | CRITICAL | 9.8 | 1.3% | Dec 31, 2020 | Exponent CMS before 2.6.0 has improper input validation in usersController.php. |
| CVE-2016-9021 | CRITICAL | 9.8 | 1.3% | Dec 31, 2020 | Exponent CMS before 2.6.0 has improper input validation in storeController.php. |
| CVE-2016-7063 | CRITICAL | 9.8 | 2.4% | Jul 21, 2020 | A flaw was found in pritunl-client before version 1.0.1116.6. Arbitrary write to user specified path may lead to privile... |
| CVE-2016-11074 | CRITICAL | 9.8 | 1.2% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 3.0.0. A password-reset link could be reused. |
| CVE-2016-11064 | CRITICAL | 9.8 | 1.3% | Jun 19, 2020 | An issue was discovered in Mattermost Desktop App before 3.4.0. Strings could be executed as code via injection. |
| CVE-2016-11061 | CRITICAL | 9.8 | 2.0% | Apr 29, 2020 | Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, and 7970i devices b... |
| CVE-2016-11038 | CRITICAL | 9.8 | 0.9% | Apr 7, 2020 | An issue was discovered on Samsung mobile devices with software through 2016-04-05 (incorporating the Samsung Profession... |
| CVE-2016-11036 | CRITICAL | 9.8 | 0.4% | Apr 7, 2020 | An issue was discovered on Samsung mobile devices with M(6.0) software. There is a Factory Reset Protection (FRP) bypass... |
| CVE-2016-11033 | CRITICAL | 9.8 | 0.4% | Apr 7, 2020 | An issue was discovered on Samsung mobile devices with M(6.0) software. There is a heap-based buffer overflow in tlc_ser... |
| CVE-2016-11028 | CRITICAL | 9.8 | 0.4% | Apr 7, 2020 | An issue was discovered on Samsung mobile devices with software through 2016-09-13 (Exynos AP chipsets). There is a stac... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now