2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-10972 | CRITICAL | 9.8 | 9.3% | Sep 16, 2019 | The newspaper theme before 6.7.2 for WordPress has a lack of options access control via td_ajax_update_panel. |
| CVE-2016-10971 | CRITICAL | 9.8 | 1.9% | Sep 16, 2019 | The MemberSonic Lite plugin before 1.302 for WordPress has incorrect login access control because only knowlewdge of an ... |
| CVE-2016-10970 | MEDIUM | 6.1 | 1.1% | Sep 16, 2019 | The supportflow plugin before 0.7 for WordPress has XSS via a ticket excerpt. |
| CVE-2016-10969 | MEDIUM | 6.1 | 1.0% | Sep 16, 2019 | The supportflow plugin before 0.7 for WordPress has XSS via a discussion ticket title. |
| CVE-2016-10968 | HIGH | 8.8 | 1.6% | Sep 16, 2019 | The peepso-core plugin before 1.6.1 for WordPress has PeepSoProfilePreferencesAjax->save() privilege escalation. |
| CVE-2016-10967 | MEDIUM | 6.1 | 1.0% | Sep 16, 2019 | The real3d-flipbook-lite plugin 1.0 for WordPress has XSS via the wp-content/plugins/real3d-flipbook/includes/flipbooks.... |
| CVE-2016-10966 | HIGH | 7.5 | 2.6% | Sep 16, 2019 | The real3d-flipbook-lite plugin 1.0 for WordPress has bookName=../ directory traversal for file upload. |
| CVE-2016-10965 | HIGH | 7.5 | 2.2% | Sep 16, 2019 | The real3d-flipbook-lite plugin 1.0 for WordPress has deleteBook=../ directory traversal for file deletion. |
| CVE-2016-10964 | MEDIUM | 6.1 | 1.0% | Sep 16, 2019 | The dwnldr plugin before 1.01 for WordPress has XSS via the User-Agent HTTP header. |
| CVE-2016-10963 | MEDIUM | 6.1 | 0.9% | Sep 16, 2019 | The icegram plugin before 1.9.19 for WordPress has XSS. |
| CVE-2016-10962 | MEDIUM | 6.5 | 0.6% | Sep 16, 2019 | The icegram plugin before 1.9.19 for WordPress has CSRF via the wp-admin/edit.php option_name parameter. |
| CVE-2016-10961 | MEDIUM | 6.1 | 1.0% | Sep 16, 2019 | The colorway theme before 3.4.2 for WordPress has XSS via the contactName parameter. |
| CVE-2016-10960 | HIGH | 8.8 | 9.0% | Sep 16, 2019 | The wsecure plugin before 2.4 for WordPress has remote code execution via shell metacharacters in the wsecure-config.php... |
| CVE-2016-10959 | MEDIUM | 6.5 | 1.1% | Sep 16, 2019 | The estatik plugin before 2.3.1 for WordPress has authenticated arbitrary file upload (exploitable with CSRF) via es_med... |
| CVE-2016-10958 | HIGH | 7.5 | 1.9% | Sep 16, 2019 | The estatik plugin before 2.3.0 for WordPress has unauthenticated arbitrary file upload via es_media_images[] to wp-admi... |
| CVE-2016-10957 | MEDIUM | 6.1 | 1.0% | Sep 16, 2019 | The Akal theme through 2016-08-22 for WordPress has XSS via the framework/brad-shortcodes/tinymce/preview.php sc paramet... |
| CVE-2016-10956 | HIGH | 7.5 | 10.6% | Sep 16, 2019 | The mail-masta plugin 1.0 for WordPress has local file inclusion in count_of_send.php and csvexport.php. |
| CVE-2016-10955 | CRITICAL | 9.8 | 2.4% | Sep 13, 2019 | The cysteme-finder plugin before 1.4 for WordPress has unrestricted file upload because of incorrect session tracking. |
| CVE-2016-10954 | CRITICAL | 9.8 | 2.2% | Sep 13, 2019 | The Neosense theme before 1.8 for WordPress has qquploader unrestricted file upload. |
| CVE-2016-10953 | MEDIUM | 5.4 | 0.8% | Sep 13, 2019 | The Headway theme before 3.8.9 for WordPress has XSS via the license key field. |
| CVE-2016-10952 | MEDIUM | 6.1 | 1.4% | Sep 13, 2019 | The quotes-collection plugin before 2.0.6 for WordPress has XSS via the wp-admin/admin.php?page=quotes-collection page p... |
| CVE-2016-10951 | HIGH | 7.2 | 1.9% | Sep 13, 2019 | The fs-shopping-cart plugin 2.07.02 for WordPress has SQL injection via the pid parameter. |
| CVE-2016-10950 | HIGH | 8.8 | 1.9% | Sep 13, 2019 | The sirv plugin before 1.3.2 for WordPress has SQL injection via the id parameter. |
| CVE-2016-10949 | HIGH | 8.8 | 1.6% | Sep 13, 2019 | The Relevanssi Premium plugin before 1.14.6.1 for WordPress has SQL injection with resultant unsafe unserialization. |
| CVE-2016-10948 | HIGH | 8.1 | 1.7% | Sep 13, 2019 | The Post Indexer plugin before 3.0.6.2 for WordPress has incorrect handling of data passed to the unserialize function. |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now