2016 CVE Vulnerabilities

10,648 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-9854——An issue was discovered in phpMyAdmin. By calling some scripts that are part of phpMyAdmin in an unexpected way, it is p...
CVE-2016-9853——An issue was discovered in phpMyAdmin. By calling some scripts that are part of phpMyAdmin in an unexpected way, it is p...
CVE-2016-9852——An issue was discovered in phpMyAdmin. By calling some scripts that are part of phpMyAdmin in an unexpected way, it is p...
CVE-2016-9851——An issue was discovered in phpMyAdmin. With a crafted request parameter value it is possible to bypass the logout timeou...
CVE-2016-9850——An issue was discovered in phpMyAdmin. Username matching for the allow/deny rules may result in wrong matches and detect...
CVE-2016-9849——An issue was discovered in phpMyAdmin. It is possible to bypass AllowRoot restriction ($cfg['Servers'][$i]['AllowRoot'])...
CVE-2016-9848——An issue was discovered in phpMyAdmin. phpinfo (phpinfo.php) shows PHP information including values of HttpOnly cookies....
CVE-2016-9847——An issue was discovered in phpMyAdmin. When the user does not specify a blowfish_secret key for encrypting cookies, phpM...
CVE-2016-6633——An issue was discovered in phpMyAdmin. phpMyAdmin can be used to trigger a remote code execution attack against certain ...
CVE-2016-6632——An issue was discovered in phpMyAdmin where, under certain conditions, phpMyAdmin may not delete temporary files during ...
CVE-2016-6631——An issue was discovered in phpMyAdmin. A user can execute a remote code execution attack against a server when phpMyAdmi...
CVE-2016-6630——An issue was discovered in phpMyAdmin. An authenticated user can trigger a denial-of-service (DoS) attack by entering a ...
CVE-2016-6629——An issue was discovered in phpMyAdmin involving the $cfg['ArbitraryServerRegexp'] configuration directive. An attacker c...
CVE-2016-6628——An issue was discovered in phpMyAdmin. An attacker may be able to trigger a user to download a specially crafted malicio...
CVE-2016-6627——An issue was discovered in phpMyAdmin. An attacker can determine the phpMyAdmin host location through the file url.php. ...
CVE-2016-6626——An issue was discovered in phpMyAdmin. An attacker could redirect a user to a malicious web page. All 4.6.x versions (pr...
CVE-2016-6625——An issue was discovered in phpMyAdmin. An attacker can determine whether a user is logged in to phpMyAdmin. The user's s...
CVE-2016-6624——An issue was discovered in phpMyAdmin involving improper enforcement of the IP-based authentication rules. When phpMyAdm...
CVE-2016-6623——An issue was discovered in phpMyAdmin. An authorized user can cause a denial-of-service (DoS) attack on a server by pass...
CVE-2016-6622——An issue was discovered in phpMyAdmin. An unauthenticated user is able to execute a denial-of-service (DoS) attack by fo...
CVE-2016-6620——An issue was discovered in phpMyAdmin. Some data is passed to the PHP unserialize() function without verification that i...
CVE-2016-6619——An issue was discovered in phpMyAdmin. In the user interface preference feature, a user can execute an SQL injection att...
CVE-2016-6618——An issue was discovered in phpMyAdmin. The transformation feature allows a user to trigger a denial-of-service (DoS) att...
CVE-2016-6617——An issue was discovered in phpMyAdmin. A specially crafted database and/or table name can be used to trigger an SQL inje...
CVE-2016-6616——An issue was discovered in phpMyAdmin. In the "User group" and "Designer" features, a user can execute an SQL injection ...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now