2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-10931An issue was discovered in the openssl crate before 0.9.0 for Rust. There is an SSL/TLS man-in-the-middle vulnerability ...
CVE-2016-6154The authentication applet in Watchguard Fireware 11.11 Operating System has reflected XSS (this can also cause an open r...
CVE-2016-10929The advanced-ajax-page-loader plugin before 2.7.7 for WordPress has no protection against the reading of uploaded files ...
CVE-2016-10928The onelogin-saml-sso plugin before 2.2.0 for WordPress has a hardcoded @@@nopass@@@ password for just-in-time provision...
CVE-2016-10930The wp-support-plus-responsive-ticket-system plugin before 7.1.0 for WordPress has insecure direct object reference via ...
CVE-2016-10927The nelio-ab-testing plugin before 4.5.11 for WordPress has SSRF in ajax/iesupport.php.
CVE-2016-10926The nelio-ab-testing plugin before 4.5.9 for WordPress has SSRF in ajax/iesupport.php.
CVE-2016-10925The peters-login-redirect plugin before 2.9.1 for WordPress has XSS during the editing of redirect URLs.
CVE-2016-10924The ebook-download plugin before 1.2 for WordPress has directory traversal.
CVE-2016-10923The woocommerce-store-toolkit plugin before 1.5.8 for WordPress has privilege escalation.
CVE-2016-10922The woocommerce-store-toolkit plugin before 1.5.7 for WordPress has privilege escalation.
CVE-2016-10921The gallery-photo-gallery plugin before 1.0.1 for WordPress has SQL injection.
CVE-2016-10920The gnucommerce plugin before 0.5.7-BETA for WordPress has XSS.
CVE-2016-10919The wassup plugin before 1.9.1 for WordPress has XSS via the Top stats widget or the wassupURI::add_siteurl method, a di...
CVE-2016-10918The gallery-by-supsystic plugin before 1.8.6 for WordPress has CSRF.
CVE-2016-10917The search-everything plugin before 8.1.6 for WordPress has SQL injection related to empty search strings, a different v...
CVE-2016-10916The appointment-booking-calendar plugin before 1.1.24 for WordPress has SQL injection, a different vulnerability than CV...
CVE-2016-10891The aryo-activity-log plugin before 2.3.3 for WordPress has XSS.
CVE-2016-10890The aryo-activity-log plugin before 2.3.2 for WordPress has XSS.
CVE-2016-10912The universal-analytics plugin before 1.3.1 for WordPress has XSS.
CVE-2016-10911The profile-builder plugin before 2.4.2 for WordPress has multiple XSS issues.
CVE-2016-10910The formbuilder plugin before 1.06 for WordPress has multiple XSS issues.
CVE-2016-10909The booking-calendar-contact-form plugin before 1.0.24 for WordPress has SQL injection.
CVE-2016-10908The booking-calendar-contact-form plugin before 1.0.24 for WordPress has XSS.
CVE-2016-10903The GoDaddy godaddy-email-marketing-sign-up-forms plugin before 1.1.3 for WordPress has CSRF.

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now