2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-10841 | — | — | 0.9% | Aug 1, 2019 | The bin/mkvhostspasswd script in cPanel before 11.54.0.4 discloses password hashes (SEC-73). |
| CVE-2016-10840 | — | — | 2.1% | Aug 1, 2019 | cPanel before 11.54.0.4 allows arbitrary code execution during locale duplication (SEC-72). |
| CVE-2016-10839 | — | — | 1.1% | Aug 1, 2019 | cPanel before 11.54.0.4 allows SQL injection in bin/horde_update_usernames (SEC-71). |
| CVE-2016-10838 | — | — | 1.1% | Aug 1, 2019 | cPanel before 11.54.0.4 allows arbitrary file-read operations via the bin/fmq script (SEC-70). |
| CVE-2016-10837 | — | — | 1.5% | Aug 1, 2019 | cPanel before 11.54.0.4 allows arbitrary code execution because of an unsafe @INC path (SEC-46). |
| CVE-2016-10836 | — | — | 1.1% | Aug 1, 2019 | cPanel before 55.9999.141 allows arbitrary file-read operations during authentication with caldav (SEC-108). |
| CVE-2016-10860 | — | — | 1.0% | Aug 1, 2019 | cPanel before 11.54.0.0 allows unauthorized zone modification via the WHM API (SEC-66). |
| CVE-2016-10859 | — | — | 1.0% | Aug 1, 2019 | cPanel before 11.54.0.0 allows unauthorized password changes via Webmail API commands (SEC-65). |
| CVE-2016-10858 | — | — | 2.5% | Aug 1, 2019 | cPanel before 11.54.0.0 allows unauthenticated arbitrary code execution via DNS NS entry poisoning (SEC-64). |
| CVE-2016-10857 | — | — | 1.0% | Aug 1, 2019 | cPanel before 11.54.0.0 allows a bypass of the e-mail sending limit (SEC-60). |
| CVE-2016-10856 | — | — | 1.0% | Aug 1, 2019 | cPanel before 11.54.0.0 allows subaccounts to discover sensitive data through comet feeds (SEC-29). |
| CVE-2016-10855 | — | — | 2.6% | Aug 1, 2019 | cPanel before 11.54.0.4 allows unauthenticated arbitrary code execution via cpsrvd (SEC-91). |
| CVE-2016-10854 | — | — | 0.6% | Aug 1, 2019 | cPanel before 11.54.0.4 allows self XSS in the X3 Entropy Banner interface (SEC-87). |
| CVE-2016-10853 | — | — | 0.6% | Aug 1, 2019 | cPanel before 11.54.0.4 allows stored XSS in the WHM Feature Manager interface (SEC-86). |
| CVE-2016-10852 | — | — | 1.0% | Aug 1, 2019 | cPanel before 11.54.0.4 lacks ACL enforcement in the AppConfig subsystem (SEC-85). |
| CVE-2016-10851 | — | — | 0.6% | Aug 1, 2019 | cPanel before 11.54.0.4 allows self XSS in the WHM PHP Configuration editor interface (SEC-84). |
| CVE-2016-10850 | — | — | 2.1% | Aug 1, 2019 | cPanel before 11.54.0.4 allows arbitrary code execution via scripts/synccpaddonswithsqlhost (SEC-83). |
| CVE-2016-10766 | HIGH | 8.8 | 0.6% | Jul 29, 2019 | edx-platform before 2016-06-06 allows CSRF. |
| CVE-2016-10765 | MEDIUM | 5.3 | 0.8% | Jul 29, 2019 | edx-platform before 2016-06-10 allows account activation with a spoofed e-mail address. |
| CVE-2016-10764 | CRITICAL | 9.8 | 3.1% | Jul 27, 2019 | In the Linux kernel before 4.9.6, there is an off by one in the drivers/mtd/spi-nor/cadence-quadspi.c cqspi_setup_flash(... |
| CVE-2016-10763 | — | — | 0.9% | Jul 18, 2019 | The CampTix Event Ticketing plugin before 1.5 for WordPress allows XSS in the admin section via a ticket title or body. |
| CVE-2016-10762 | — | — | 1.8% | Jul 18, 2019 | The CampTix Event Ticketing plugin before 1.5 for WordPress allows CSV injection when the export tool is used. |
| CVE-2016-5236 | — | — | 0.6% | Jul 1, 2019 | Cross-Site-Scripting (XSS) vulnerabilities in F5 WebSafe Dashboard 3.9.5 and earlier, aka F5 WebSafe Alert Server, allow... |
| CVE-2016-5235 | — | — | 0.9% | Jul 1, 2019 | A Cross Site Scripting (XSS) vulnerability in versions of F5 WebSafe Dashboard 3.9.x and earlier, aka F5 WebSafe Alert S... |
| CVE-2016-10761 | — | — | 0.7% | Jun 29, 2019 | Logitech Unifying devices before 2016-02-26 allow keystroke injection, bypassing encryption, aka MouseJack. |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now