2016 CVE Vulnerabilities

10,648 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-10932——An issue was discovered in the hyper crate before 0.9.4 for Rust on Windows. There is an HTTPS man-in-the-middle vulnera...
CVE-2016-10931——An issue was discovered in the openssl crate before 0.9.0 for Rust. There is an SSL/TLS man-in-the-middle vulnerability ...
CVE-2016-6154——The authentication applet in Watchguard Fireware 11.11 Operating System has reflected XSS (this can also cause an open r...
CVE-2016-10929——The advanced-ajax-page-loader plugin before 2.7.7 for WordPress has no protection against the reading of uploaded files ...
CVE-2016-10928——The onelogin-saml-sso plugin before 2.2.0 for WordPress has a hardcoded @@@nopass@@@ password for just-in-time provision...
CVE-2016-10930——The wp-support-plus-responsive-ticket-system plugin before 7.1.0 for WordPress has insecure direct object reference via ...
CVE-2016-10927——The nelio-ab-testing plugin before 4.5.11 for WordPress has SSRF in ajax/iesupport.php.
CVE-2016-10926——The nelio-ab-testing plugin before 4.5.9 for WordPress has SSRF in ajax/iesupport.php.
CVE-2016-10925——The peters-login-redirect plugin before 2.9.1 for WordPress has XSS during the editing of redirect URLs.
CVE-2016-10924——The ebook-download plugin before 1.2 for WordPress has directory traversal.
CVE-2016-10923——The woocommerce-store-toolkit plugin before 1.5.8 for WordPress has privilege escalation.
CVE-2016-10922——The woocommerce-store-toolkit plugin before 1.5.7 for WordPress has privilege escalation.
CVE-2016-10921——The gallery-photo-gallery plugin before 1.0.1 for WordPress has SQL injection.
CVE-2016-10920——The gnucommerce plugin before 0.5.7-BETA for WordPress has XSS.
CVE-2016-10919——The wassup plugin before 1.9.1 for WordPress has XSS via the Top stats widget or the wassupURI::add_siteurl method, a di...
CVE-2016-10918——The gallery-by-supsystic plugin before 1.8.6 for WordPress has CSRF.
CVE-2016-10917——The search-everything plugin before 8.1.6 for WordPress has SQL injection related to empty search strings, a different v...
CVE-2016-10916——The appointment-booking-calendar plugin before 1.1.24 for WordPress has SQL injection, a different vulnerability than CV...
CVE-2016-10891——The aryo-activity-log plugin before 2.3.3 for WordPress has XSS.
CVE-2016-10890——The aryo-activity-log plugin before 2.3.2 for WordPress has XSS.
CVE-2016-10912——The universal-analytics plugin before 1.3.1 for WordPress has XSS.
CVE-2016-10911——The profile-builder plugin before 2.4.2 for WordPress has multiple XSS issues.
CVE-2016-10910——The formbuilder plugin before 1.06 for WordPress has multiple XSS issues.
CVE-2016-10909——The booking-calendar-contact-form plugin before 1.0.24 for WordPress has SQL injection.
CVE-2016-10908——The booking-calendar-contact-form plugin before 1.0.24 for WordPress has XSS.

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now