2016 CVE Vulnerabilities

10,645 CVEs published in 2016.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2016-11025CRITICAL9.8An issue was discovered on Samsung mobile devices with software through 2016-09-13 (Exynos AP chipsets). There is a memc...
CVE-2016-11049CRITICAL9.1An issue was discovered on Samsung mobile devices with software through 2016-01-16 (Shannon333/308/310 chipsets). The IM...
CVE-2016-11024CRITICAL9.8odata4j 0.7.0 allows ExecuteJPQLQueryCommand.java SQL injection. NOTE: this product is apparently discontinued.
CVE-2016-11023CRITICAL9.8odata4j 0.7.0 allows ExecuteCountQueryCommand.java SQL injection. NOTE: this product is apparently discontinued.
CVE-2016-6918CRITICAL9.8Lexmark Markvision Enterprise (MVE) before 2.4.1 allows remote attackers to execute arbitrary commands by uploading file...
CVE-2016-11020CRITICAL9.8Kunena before 5.0.4 does not restrict avatar file extensions to gif, jpeg, jpg, and png. This can lead to XSS and remote...
CVE-2016-4606CRITICAL9.8Curl before 7.49.1 in Apple OS X before macOS Sierra prior to 10.12 allows remote or local attackers to execute arbitrar...
CVE-2016-1000005CRITICAL9.8mcrypt_get_block_size did not enforce that the provided "module" parameter was a string, leading to type confusion if ot...
CVE-2016-1000004CRITICAL9.8Insufficient type checks were employed prior to casting input data in SimpleXMLElement_exportNode and simplexml_import_d...
CVE-2016-2031CRITICAL9.8Multiple vulnerabilities exists in Aruba Instate before 4.1.3.0 and 4.2.3.1 due to insufficient validation of user-suppl...
CVE-2016-11018CRITICAL9.8An issue was discovered in the Huge-IT gallery-images plugin before 1.9.0 for WordPress. The headers Client-Ip and X-For...
CVE-2016-11017CRITICAL9.8The application login page in AKIPS Network Monitor 15.37 through 16.5 allows a remote unauthenticated attacker to execu...
CVE-2016-1000027CRITICAL9.8Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue if used for Java dese...
CVE-2016-9652CRITICAL9.8Multiple unspecified vulnerabilities in Google Chrome before 55.0.2883.75.
CVE-2016-5194CRITICAL9.8Unspecified vulnerabilities in Google Chrome before 54.0.2840.59.
CVE-2016-1000006CRITICAL9.8hhvm before 3.12.11 has a use-after-free in the serialize_memoize_param() and ResourceBundle::__construct() functions.
CVE-2016-4401CRITICAL9.8Aruba ClearPass Policy Manager before 6.5.7 and 6.6.x before 6.6.2 allows attackers to obtain database credentials.
CVE-2016-5202CRITICAL9.1browser/extensions/api/dial/dial_registry.cc in Google Chrome before 54.0.2840.98 on macOS, before 54.0.2840.99 on Windo...
CVE-2016-2360CRITICAL9.8Milesight IP security cameras through 2016-11-14 have a default root password in /etc/shadow that is the same across dif...
CVE-2016-2359CRITICAL9.8Milesight IP security cameras through 2016-11-14 allow remote attackers to bypass authentication and access a protected ...
CVE-2016-2358CRITICAL9.8Milesight IP security cameras through 2016-11-14 have a default set of 10 privileged accounts with hardcoded credentials...
CVE-2016-2357CRITICAL9.8Milesight IP security cameras through 2016-11-14 have a hardcoded SSL private key under the /etc/config directory.
CVE-2016-2356CRITICAL9.8Milesight IP security cameras through 2016-11-14 have a buffer overflow in a web application via a long username or pass...
CVE-2016-11014CRITICAL9.8NETGEAR JNR1010 devices before 1.0.0.32 have Incorrect Access Control because the ok value of the auth cookie is a speci...
CVE-2016-11000CRITICAL9.8The wp-ultimate-exporter plugin through 1.1 for WordPress has SQL injection via the export_type_name parameter.

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now