2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-10947 | HIGH | 7.2 | 1.5% | Sep 13, 2019 | The Post Indexer plugin before 3.0.6.2 for WordPress has SQL injection via the period parameter by a super admin. |
| CVE-2016-10946 | HIGH | 8.8 | 0.8% | Sep 13, 2019 | The wp-d3 plugin before 2.4.1 for WordPress has CSRF. |
| CVE-2016-10945 | HIGH | 8.8 | 0.8% | Sep 13, 2019 | The PageLines theme 1.1.4 for WordPress has wp-admin/admin-post.php?page=pagelines CSRF. |
| CVE-2016-10944 | HIGH | 8.8 | 0.7% | Sep 13, 2019 | The multisite-post-duplicator plugin before 1.1.3 for WordPress has wp-admin/tools.php?page=mpd CSRF. |
| CVE-2016-10943 | HIGH | 7.2 | 1.9% | Sep 13, 2019 | The zx-csv-upload plugin 1 for WordPress has SQL injection via the id parameter. |
| CVE-2016-10942 | CRITICAL | 9.8 | 2.0% | Sep 13, 2019 | The podlove-podcasting-plugin-for-wordpress plugin before 2.3.16 for WordPress has SQL injection via the insert_id param... |
| CVE-2016-10941 | MEDIUM | 6.1 | 1.2% | Sep 13, 2019 | The podlove-podcasting-plugin-for-wordpress plugin before 2.3.16 for WordPress has XSS exploitable via CSRF. |
| CVE-2016-10940 | HIGH | 7.2 | 5.5% | Sep 13, 2019 | The zm-gallery plugin 1.0 for WordPress has SQL injection via the order parameter. |
| CVE-2016-10939 | HIGH | 7.2 | 1.6% | Sep 13, 2019 | The xtremelocator plugin 1.5 for WordPress has SQL injection via the id parameter. |
| CVE-2016-10938 | MEDIUM | 6.5 | 0.9% | Sep 13, 2019 | The copy-me plugin 1.0.0 for WordPress has CSRF for copying non-public posts to a public location. |
| CVE-2016-10937 | HIGH | 7.5 | 0.9% | Sep 8, 2019 | IMAPFilter through 2.6.12 does not validate the hostname in an SSL certificate. |
| CVE-2016-7398 | CRITICAL | 9.8 | 6.8% | Sep 6, 2019 | A type confusion vulnerability in the merge_param() function of php_http_params.c in PHP's pecl-http extension 3.1.0beta... |
| CVE-2016-10500 | — | — | — | Aug 30, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2016-10488 | — | — | — | Aug 30, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2016-10470 | — | — | — | Aug 30, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2016-10468 | — | — | — | Aug 30, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2016-10465 | — | — | — | Aug 30, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2016-10463 | — | — | — | Aug 30, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2016-10453 | — | — | — | Aug 30, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2016-10413 | — | — | — | Aug 30, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2016-10936 | — | — | 0.9% | Aug 27, 2019 | The wp-polls plugin before 2.73.1 for WordPress has XSS via the Poll bar option. |
| CVE-2016-10935 | — | — | 2.1% | Aug 27, 2019 | The woocommerce-exporter plugin before 1.8.4 for WordPress has privilege escalation. |
| CVE-2016-10934 | — | — | 0.9% | Aug 27, 2019 | The check-email plugin before 0.5.2 for WordPress has XSS. |
| CVE-2016-10933 | — | — | 1.1% | Aug 26, 2019 | An issue was discovered in the portaudio crate through 0.7.0 for Rust. There is a man-in-the-middle issue because the so... |
| CVE-2016-10932 | — | — | 0.7% | Aug 26, 2019 | An issue was discovered in the hyper crate before 0.9.4 for Rust on Windows. There is an HTTPS man-in-the-middle vulnera... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now