2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-20048HIGH8.6iSelect 1.4.0-2+b1 contains a local buffer overflow vulnerability that allows local attackers to execute arbitrary code ...
CVE-2016-20047HIGH8.6EKG Gadu 1.9~pre+r2855-3+b1 contains a local buffer overflow vulnerability in the username handling that allows local at...
CVE-2016-20046HIGH8.6zFTP Client 20061220+dfsg3-4.1 contains a buffer overflow vulnerability in the NAME parameter handling of FTP connection...
CVE-2016-20045HIGH7.8HNB Organizer 1.9.18-10 contains a local buffer overflow vulnerability that allows local attackers to execute arbitrary ...
CVE-2016-20044HIGH7.8PInfo 0.6.9-5.1 contains a local buffer overflow vulnerability that allows local attackers to execute arbitrary code by ...
CVE-2016-20043HIGH7.8NRSS RSS Reader 0.3.9-1 contains a stack buffer overflow vulnerability that allows local attackers to execute arbitrary ...
CVE-2016-20042HIGH8.6TRN 3.6-23 contains a stack buffer overflow vulnerability that allows local attackers to execute arbitrary code by suppl...
CVE-2016-20041HIGH8.6Yasr 0.6.9-5 contains a buffer overflow vulnerability that allows local attackers to crash the application or execute ar...
CVE-2016-20040HIGH8.6TiEmu 3.03-nogdb+dfsg-3 contains a buffer overflow vulnerability in the ROM parameter handling that allows local attacke...
CVE-2016-20039HIGH8.6Multi Emulator Super System 0.154-3.1 contains a buffer overflow vulnerability in the gamma parameter handling that allo...
CVE-2016-20038HIGH8.6yTree 1.94-1.1 contains a stack-based buffer overflow vulnerability that allows local attackers to execute arbitrary cod...
CVE-2016-20037HIGH8.6xwpe 1.5.30a-2.1 and prior contains a stack-based buffer overflow vulnerability that allows local attackers to execute a...
CVE-2016-20036MEDIUM6.1Wowza Streaming Engine 4.5.0 contains multiple reflected cross-site scripting vulnerabilities in the enginemanager inter...
CVE-2016-20035MEDIUM4.3Wowza Streaming Engine 4.5.0 contains a cross-site request forgery vulnerability that allows attackers to perform admini...
CVE-2016-20034HIGH8Wowza Streaming Engine 4.5.0 contains a privilege escalation vulnerability that allows authenticated read-only users to ...
CVE-2016-20033HIGH8.5Wowza Streaming Engine 4.5.0 contains a local privilege escalation vulnerability that allows authenticated users to esca...
CVE-2016-20032HIGH7.2ZKTeco ZKAccess Security System 5.3.1 contains a stored cross-site scripting vulnerability that allows attackers to exec...
CVE-2016-20031MEDIUM6.8ZKTeco ZKBioSecurity 3.0 contains a local authorization bypass vulnerability in visLogin.jsp that allows attackers to au...
CVE-2016-20030CRITICAL9.8ZKTeco ZKBioSecurity 3.0 contains a user enumeration vulnerability that allows unauthenticated attackers to discover val...
CVE-2016-20029MEDIUM6.9ZKTeco ZKBioSecurity 3.0 contains a file path manipulation vulnerability that allows attackers to access arbitrary files...
CVE-2016-20028MEDIUM5.3ZKTeco ZKBioSecurity 3.0 contains a cross-site request forgery vulnerability that allows attackers to perform administra...
CVE-2016-20027MEDIUM6.1ZKTeco ZKBioSecurity 3.0 contains multiple reflected cross-site scripting vulnerabilities that allow attackers to execut...
CVE-2016-20026CRITICAL9.8ZKTeco ZKBioSecurity 3.0 contains hardcoded credentials in the bundled Apache Tomcat server that allow unauthenticated a...
CVE-2016-20025HIGH8.8ZKTeco ZKAccess Professional 3.5.3 contains an insecure file permissions vulnerability that allows authenticated users t...
CVE-2016-20024CRITICAL9.8ZKTeco ZKTime.Net 3.0.1.6 contains an insecure file permissions vulnerability that allows unprivileged users to escalate...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now