2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-7404OpenStack Magnum passes OpenStack credentials into the Heat templates creating its instances. While these should just be...
CVE-2016-10760On Seowon Intech routers, there is a Command Injection vulnerability in diagnostic.cgi via shell metacharacters in the p...
CVE-2016-10759The Xinha plugin in Precurio 2.1 allows Directory Traversal, with resultant arbitrary code execution, via ExtendedFileMa...
CVE-2016-10758PHPKIT 1.6.6 allows arbitrary File Upload, as demonstrated by a .php file to pkinc/admin/mediaarchive.php and pkinc/func...
CVE-2016-10757In Redaxo 5.2.0, the cron management of the admin panel suffers from CSRF that leads to arbitrary Remote Code Execution ...
CVE-2016-10756Kliqqi 3.0.0.5 allows CSRF with resultant Arbitrary File Upload because module.php?module=upload can be used to configur...
CVE-2016-10755AbanteCart 1.2.8 allows SQL Injection via the source_language parameter to admin/controller/pages/localisation/language....
CVE-2016-10754modules/Calendar/Activity.php in Vtiger CRM 6.5.0 allows SQL injection via the contactidlist parameter.
CVE-2016-10753e107 2.1.2 allows PHP Object Injection with resultant SQL injection, because usersettings.php uses unserialize without a...
CVE-2016-10752serendipity_moveMediaDirectory in Serendipity 2.0.3 allows remote attackers to upload and execute arbitrary PHP code bec...
CVE-2016-10751osClass 3.6.1 allows oc-admin/plugins.php Directory Traversal via the plugin parameter. This is exploitable for remote P...
CVE-2016-8900Exponent CMS version 2.3.9 suffers from a Object Injection vulnerability in framework/modules/core/controllers/expTagCon...
CVE-2016-8898Exponent CMS version 2.3.9 suffers from a sql injection vulnerability in framework/modules/ecommerce/controllers/cartCon...
CVE-2016-10245Insufficient sanitization of the query parameter in templates/html/search_opensearch.php could lead to reflected cross-s...
CVE-2016-8899Exponent CMS version 2.3.9 suffers from a Object Injection vulnerability in framework/modules/core/controllers/expCatCon...
CVE-2016-8897Exponent CMS version 2.3.9 suffers from a sql injection vulnerability in framework/modules/help/controllers/helpControll...
CVE-2016-7550asterisk 13.10.0 is affected by: denial of service issues in asterisk. The impact is: cause a denial of service (remote)...
CVE-2016-9969In libwebp 0.5.1, there is a double free bug in libwebpmux.
CVE-2016-8901b2evolution 6.7.6 suffer from an Object Injection vulnerability in /htsrv/call_plugin.php.
CVE-2016-10750In Hazelcast before 3.11, the cluster join procedure is vulnerable to remote code execution via Java deserialization. If...
CVE-2016-7043MEDIUM5.9It has been reported that KIE server and Busitess Central before version 7.21.0.Final contain username and password as p...
CVE-2016-7151Capstone 3.0.4 has an out-of-bounds vulnerability (SEGV caused by a read memory access) in X86_insn_reg_intel in arch/X8...
CVE-2016-10719TP-Link Archer CR-700 1.0.6 devices have an XSS vulnerability that can be introduced into the admin account through a DH...
CVE-2016-1600The ServiceNow driver in NetIQ Identity Manager versions prior to 4.6 are susceptible to an information disclosure vulne...
CVE-2016-10749CRITICAL9.8parse_string in cJSON.c in cJSON before 2016-10-02 has a buffer over-read, as demonstrated by a string that begins with ...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now