2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-10902The wp-customer-reviews plugin before 3.0.9 for WordPress has CSRF in the admin tools.
CVE-2016-10901The wp-customer-reviews plugin before 3.0.9 for WordPress has XSS in the admin tools.
CVE-2016-10900The uji-countdown plugin before 2.0.7 for WordPress has XSS.
CVE-2016-10899The total-security plugin before 3.4.1 for WordPress has a settings-change vulnerability.
CVE-2016-10898The total-security plugin before 3.4.1 for WordPress has XSS.
CVE-2016-10897The sermon-browser plugin before 0.45.16 for WordPress has multiple XSS issues.
CVE-2016-10896The seo-redirection plugin before 4.3 for WordPress has stored XSS.
CVE-2016-10895The option-tree plugin before 2.6.0 for WordPress has XSS via an add_list_item or add_social_links AJAX request.
CVE-2016-10892The chained-quiz plugin before 1.0 for WordPress has multiple XSS issues.
CVE-2016-10915The popup-by-supsystic plugin before 1.7.9 for WordPress has CSRF.
CVE-2016-10914The add-from-server plugin before 3.3.2 for WordPress has CSRF for importing a large file.
CVE-2016-10913The wp-latest-posts plugin before 3.7.5 for WordPress has XSS.
CVE-2016-10893MEDIUM6.1The crayon-syntax-highlighter plugin before 2.8.4 for WordPress has multiple XSS issues via AJAX requests.
CVE-2016-10907An issue was discovered in drivers/iio/dac/ad5755.c in the Linux kernel before 4.8.6. There is an out of bounds write in...
CVE-2016-10906An issue was discovered in drivers/net/ethernet/arc/emac_main.c in the Linux kernel before 4.5. A use-after-free is caus...
CVE-2016-10905HIGH7.8An issue was discovered in fs/gfs2/rgrp.c in the Linux kernel before 4.8. A use-after-free is caused by the functions gf...
CVE-2016-10904The olimometer plugin before 2.57 for WordPress has SQL injection.
CVE-2016-10894MEDIUM4.6xtrlock through 2.10 does not block multitouch events. Consequently, an attacker at a locked screen can send input to (a...
CVE-2016-10888The all-in-one-wp-security-and-firewall plugin before 4.0.7 for WordPress has multiple SQL injection issues.
CVE-2016-10887The all-in-one-wp-security-and-firewall plugin before 4.0.9 for WordPress has multiple SQL injection issues.
CVE-2016-10886The wp-editor plugin before 1.2.6 for WordPress has incorrect permissions.
CVE-2016-10885The wp-editor plugin before 1.2.6 for WordPress has CSRF.
CVE-2016-10884HIGH8.8The simple-membership plugin before 3.3.3 for WordPress has multiple CSRF issues.
CVE-2016-10883The simple-add-pages-or-posts plugin before 1.7 for WordPress has CSRF for deleting users.
CVE-2016-10882The google-document-embedder plugin before 2.6.2 for WordPress has CSRF.

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now