2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2016-15055HIGH8.7JVC VN-T IP-camera models firmware versions up to 2016-08-22 (confirmed on the VN-T216VPRU model) contain a directory tr...
CVE-2016-15050HIGH8.8Nagios XI versions prior to 5.2.4 contain a SQL injection vulnerability in the notification search functionality. User-s...
CVE-2016-15047HIGH8.7AVTECH devices that include the CloudSetup.cgi management endpoint are vulnerable to authenticated OS command injection....
CVE-2016-15046HIGH8.6A client-side remote code execution vulnerability exists in Hanwha Techwin Smart Security Manager (SSM) versions 1.32 an...
CVE-2016-15045HIGH8.5A local privilege escalation vulnerability exists in lastore-daemon, the system package manager daemon used in Deepin Li...
CVE-2016-10408HIGH7.8QSEE will randomly experience a fatal error during execution due to speculative instruction fetches from device memory. ...
CVE-2016-10394HIGH7.8Initial xbl_sec revision does not have all the debug policy features and critical checks.
CVE-2016-20022HIGH8.4In the Linux kernel before 4.8, usb_parse_endpoint in drivers/usb/core/config.c does not validate the wMaxPacketSize fie...
CVE-2016-15036HIGH7.5** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Deis Workflow Manager up to 2.3.2. It has been classified a...
CVE-2016-1203HIGH8.1Improper file verification vulnerability in SaAT Netizen installer ver.1.2.0.424 and earlier, and SaAT Netizen ver.1.2.0...
CVE-2016-15026HIGH7.8A vulnerability was found in 3breadt dd-plist 1.17 and classified as problematic. Affected by this issue is some unknown...
CVE-2016-15019HIGH7.5A vulnerability was found in tombh jekbox. It has been rated as problematic. This issue affects some unknown processing ...
CVE-2016-15009HIGH8.8A vulnerability classified as problematic has been found in OpenACS bug-tracker. Affected is an unknown function of the ...
CVE-2016-15005HIGH8.8CSRF tokens are generated using math/rand, which is not a cryptographically secure random number generator, allowing an ...
CVE-2016-20018HIGH7.5Knex Knex.js through 2.3.0 has a limited SQL injection vulnerability that can be exploited to ignore the WHERE clause of...
CVE-2016-20015HIGH7.5In the ebuild package through smokeping-2.7.3-r1 for SmokePing on Gentoo, the initscript allows the smokeping user to ga...
CVE-2016-4427HIGH7.5In zulip before 1.3.12, deactivated users could access messages if SSO was enabled.
CVE-2016-0796HIGH7.5WordPress Plugin mb.miniAudioPlayer-an HTML5 audio player for your mp3 files is prone to multiple vulnerabilities, inclu...
CVE-2016-15003HIGH7.8A vulnerability has been found in FileZilla Client 3.17.0.0 and classified as problematic. This vulnerability affects un...
CVE-2016-15002HIGH8.8A vulnerability, which was classified as critical, was found in MONyog Ultimate 6.63. This affects an unknown part of th...
CVE-2016-20013HIGH7.5sha256crypt and sha512crypt through 0.6 allow attackers to cause a denial of service (CPU consumption) because the algor...
CVE-2016-3735HIGH8.1Piwigo is image gallery software written in PHP. When a criteria is not met on a host, piwigo defaults to usingmt_rand i...
CVE-2016-20011HIGH7.5libgrss through 0.7.0 fails to perform TLS certificate verification when downloading feeds, allowing remote attackers to...
CVE-2016-20003HIGH7.5The REST/JSON project 7.x-1.x for Drupal allows user enumeration, aka SA-CONTRIB-2016-033. NOTE: This project is not cov...
CVE-2016-20008HIGH7.5The REST/JSON project 7.x-1.x for Drupal allows session enumeration, aka SA-CONTRIB-2016-033. NOTE: This project is not ...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now