2016 CVE Vulnerabilities

10,648 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-10903——The GoDaddy godaddy-email-marketing-sign-up-forms plugin before 1.1.3 for WordPress has CSRF.
CVE-2016-10902——The wp-customer-reviews plugin before 3.0.9 for WordPress has CSRF in the admin tools.
CVE-2016-10901——The wp-customer-reviews plugin before 3.0.9 for WordPress has XSS in the admin tools.
CVE-2016-10900——The uji-countdown plugin before 2.0.7 for WordPress has XSS.
CVE-2016-10899——The total-security plugin before 3.4.1 for WordPress has a settings-change vulnerability.
CVE-2016-10898——The total-security plugin before 3.4.1 for WordPress has XSS.
CVE-2016-10897——The sermon-browser plugin before 0.45.16 for WordPress has multiple XSS issues.
CVE-2016-10896——The seo-redirection plugin before 4.3 for WordPress has stored XSS.
CVE-2016-10895——The option-tree plugin before 2.6.0 for WordPress has XSS via an add_list_item or add_social_links AJAX request.
CVE-2016-10892——The chained-quiz plugin before 1.0 for WordPress has multiple XSS issues.
CVE-2016-10915——The popup-by-supsystic plugin before 1.7.9 for WordPress has CSRF.
CVE-2016-10914——The add-from-server plugin before 3.3.2 for WordPress has CSRF for importing a large file.
CVE-2016-10913——The wp-latest-posts plugin before 3.7.5 for WordPress has XSS.
CVE-2016-10893MEDIUM6.1The crayon-syntax-highlighter plugin before 2.8.4 for WordPress has multiple XSS issues via AJAX requests.
CVE-2016-10907——An issue was discovered in drivers/iio/dac/ad5755.c in the Linux kernel before 4.8.6. There is an out of bounds write in...
CVE-2016-10906——An issue was discovered in drivers/net/ethernet/arc/emac_main.c in the Linux kernel before 4.5. A use-after-free is caus...
CVE-2016-10905HIGH7.8An issue was discovered in fs/gfs2/rgrp.c in the Linux kernel before 4.8. A use-after-free is caused by the functions gf...
CVE-2016-10904——The olimometer plugin before 2.57 for WordPress has SQL injection.
CVE-2016-10894MEDIUM4.6xtrlock through 2.10 does not block multitouch events. Consequently, an attacker at a locked screen can send input to (a...
CVE-2016-10888——The all-in-one-wp-security-and-firewall plugin before 4.0.7 for WordPress has multiple SQL injection issues.
CVE-2016-10887——The all-in-one-wp-security-and-firewall plugin before 4.0.9 for WordPress has multiple SQL injection issues.
CVE-2016-10886——The wp-editor plugin before 1.2.6 for WordPress has incorrect permissions.
CVE-2016-10885——The wp-editor plugin before 1.2.6 for WordPress has CSRF.
CVE-2016-10884HIGH8.8The simple-membership plugin before 3.3.3 for WordPress has multiple CSRF issues.
CVE-2016-10883——The simple-add-pages-or-posts plugin before 1.7 for WordPress has CSRF for deleting users.

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now