2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-10947HIGH7.2The Post Indexer plugin before 3.0.6.2 for WordPress has SQL injection via the period parameter by a super admin.
CVE-2016-10946HIGH8.8The wp-d3 plugin before 2.4.1 for WordPress has CSRF.
CVE-2016-10945HIGH8.8The PageLines theme 1.1.4 for WordPress has wp-admin/admin-post.php?page=pagelines CSRF.
CVE-2016-10944HIGH8.8The multisite-post-duplicator plugin before 1.1.3 for WordPress has wp-admin/tools.php?page=mpd CSRF.
CVE-2016-10943HIGH7.2The zx-csv-upload plugin 1 for WordPress has SQL injection via the id parameter.
CVE-2016-10942CRITICAL9.8The podlove-podcasting-plugin-for-wordpress plugin before 2.3.16 for WordPress has SQL injection via the insert_id param...
CVE-2016-10941MEDIUM6.1The podlove-podcasting-plugin-for-wordpress plugin before 2.3.16 for WordPress has XSS exploitable via CSRF.
CVE-2016-10940HIGH7.2The zm-gallery plugin 1.0 for WordPress has SQL injection via the order parameter.
CVE-2016-10939HIGH7.2The xtremelocator plugin 1.5 for WordPress has SQL injection via the id parameter.
CVE-2016-10938MEDIUM6.5The copy-me plugin 1.0.0 for WordPress has CSRF for copying non-public posts to a public location.
CVE-2016-10937HIGH7.5IMAPFilter through 2.6.12 does not validate the hostname in an SSL certificate.
CVE-2016-7398CRITICAL9.8A type confusion vulnerability in the merge_param() function of php_http_params.c in PHP's pecl-http extension 3.1.0beta...
CVE-2016-10500Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2016-10488Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2016-10470Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2016-10468Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2016-10465Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2016-10463Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2016-10453Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2016-10413Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2016-10936The wp-polls plugin before 2.73.1 for WordPress has XSS via the Poll bar option.
CVE-2016-10935The woocommerce-exporter plugin before 1.8.4 for WordPress has privilege escalation.
CVE-2016-10934The check-email plugin before 0.5.2 for WordPress has XSS.
CVE-2016-10933An issue was discovered in the portaudio crate through 0.7.0 for Rust. There is a man-in-the-middle issue because the so...
CVE-2016-10932An issue was discovered in the hyper crate before 0.9.4 for Rust on Windows. There is an HTTPS man-in-the-middle vulnera...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now