2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-10881The google-document-embedder plugin before 2.6.2 for WordPress has XSS.
CVE-2016-10880The google-document-embedder plugin before 2.6.1 for WordPress has XSS.
CVE-2016-10889The nextgen-gallery plugin before 2.1.57 for WordPress has SQL injection via a gallery name.
CVE-2016-10867MEDIUM6.1The all-in-one-wp-security-and-firewall plugin before 4.0.6 for WordPress has XSS in settings pages.
CVE-2016-10866The all-in-one-wp-security-and-firewall plugin before 4.2.0 for WordPress has multiple XSS issues.
CVE-2016-10871The mailchimp-for-wp plugin before 4.0.11 for WordPress has XSS on the integration settings page.
CVE-2016-10870The google-language-translator plugin before 5.0.06 for WordPress has XSS.
CVE-2016-10869The contact-form-plugin plugin before 4.0.2 for WordPress has XSS.
CVE-2016-10868The all-in-one-wp-security-and-firewall plugin before 4.0.5 for WordPress has XSS in the blacklist, file system, and fil...
CVE-2016-10872MEDIUM6.1The ultimate-member plugin before 1.3.40 for WordPress has XSS on the login form.
CVE-2016-10879The wp-live-chat-support plugin before 6.2.02 for WordPress has XSS.
CVE-2016-10878MEDIUM6.1The wp-google-map-plugin plugin before 3.1.2 for WordPress has XSS.
CVE-2016-10877The wp-editor plugin before 1.2.6.3 for WordPress has multiple XSS issues.
CVE-2016-10876The wp-database-backup plugin before 4.3.1 for WordPress has CSRF.
CVE-2016-10875MEDIUM6.1The wp-database-backup plugin before 4.3.1 for WordPress has XSS.
CVE-2016-10874HIGH8.8The wp-database-backup plugin before 4.3.3 for WordPress has CSRF.
CVE-2016-10873MEDIUM6.1The wp-database-backup plugin before 4.3.3 for WordPress has XSS.
CVE-2016-10865The Lightbox Plus Colorbox plugin through 2.7.2 for WordPress has cross-site request forgery (CSRF) via wp-admin/admin.p...
CVE-2016-10863Edimax Wi-Fi Extender devices allow goform/formwlencryptvxd CSRF with resultant PSK key disclosure.
CVE-2016-10862Neet AirStream NAS1.1 devices have a password of ifconfig for the root account. This cannot be changed via the configura...
CVE-2016-10864NETGEAR EX7000 V1.0.0.42_1.0.94 devices allow XSS via the SSID.
CVE-2016-5431HIGH7.5The PHP JOSE Library by Gree Inc. before version 2.2.1 is vulnerable to key confusion/algorithm substitution in the JWS ...
CVE-2016-10861Neet AirStream NAS1.1 devices allow CSRF attacks that cause the settings binary to change the AP name and password.
CVE-2016-10812In cPanel before 57.9999.54, /scripts/enablefileprotect exposed TTYs (SEC-117).
CVE-2016-10811In cPanel before 57.9999.54, /scripts/unsuspendacct exposed TTYs (SEC-116).

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now